This work investigates the theoretical boundaries of creating publicly-detectable schemes to enable the provenance of watermarked imagery. Metadata-based approaches like C2PA provide unforgeability and public-detectability. ML techniques offer robust retrieval and watermarking. However, no existing scheme combines robustness, unforgeability, and public-detectability. In this work, we formally define such a scheme and establish its existence. Although theoretically possible, we find that at present, it is intractable to build certain components of our scheme without a leap in deep learning capabilities. We analyze these limitations and propose research directions that need to be addressed before we can practically realize robust and publicly-verifiable provenance.
@article{arxiv.2502.04901,
title = {On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark},
author = {Jaiden Fairoze and Guillermo Ortiz-Jimenez and Mel Vecerik and Somesh Jha and Sven Gowal},
journal= {arXiv preprint arXiv:2502.04901},
year = {2025}
}