English

Stable Signature is Unstable: Removing Image Watermark from Diffusion Models

Cryptography and Security 2024-05-14 v1 Computer Vision and Pattern Recognition

Abstract

Watermark has been widely deployed by industry to detect AI-generated images. A recent watermarking framework called \emph{Stable Signature} (proposed by Meta) roots watermark into the parameters of a diffusion model's decoder such that its generated images are inherently watermarked. Stable Signature makes it possible to watermark images generated by \emph{open-source} diffusion models and was claimed to be robust against removal attacks. In this work, we propose a new attack to remove the watermark from a diffusion model by fine-tuning it. Our results show that our attack can effectively remove the watermark from a diffusion model such that its generated images are non-watermarked, while maintaining the visual quality of the generated images. Our results highlight that Stable Signature is not as stable as previously thought.

Keywords

Cite

@article{arxiv.2405.07145,
  title  = {Stable Signature is Unstable: Removing Image Watermark from Diffusion Models},
  author = {Yuepeng Hu and Zhengyuan Jiang and Moyang Guo and Neil Gong},
  journal= {arXiv preprint arXiv:2405.07145},
  year   = {2024}
}
R2 v1 2026-06-28T16:24:22.527Z