English

On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark

Cryptography and Security 2025-04-29 v2 Machine Learning

Abstract

This work investigates the theoretical boundaries of creating publicly-detectable schemes to enable the provenance of watermarked imagery. Metadata-based approaches like C2PA provide unforgeability and public-detectability. ML techniques offer robust retrieval and watermarking. However, no existing scheme combines robustness, unforgeability, and public-detectability. In this work, we formally define such a scheme and establish its existence. Although theoretically possible, we find that at present, it is intractable to build certain components of our scheme without a leap in deep learning capabilities. We analyze these limitations and propose research directions that need to be addressed before we can practically realize robust and publicly-verifiable provenance.

Keywords

Cite

@article{arxiv.2502.04901,
  title  = {On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark},
  author = {Jaiden Fairoze and Guillermo Ortiz-Jimenez and Mel Vecerik and Somesh Jha and Sven Gowal},
  journal= {arXiv preprint arXiv:2502.04901},
  year   = {2025}
}
R2 v1 2026-06-28T21:36:04.787Z