cs.CVSep 30, 2026

WARP: A Unified Benchmark for Invisible Image Watermarking -- Robustness and Protection Against Attacks

Authors: Khaled Abud, Aleksey Yakushev, Aleksandr Akimenkov, Irina Serzhenko, Kirill Aistov, Egor Kovalev, Dmitry Obydenkov, Sergey Lavrushkin, +4 more

Organizations: MSU Institute for Artificial Intelligence Moscow, Russia · Trusted AI Research Center RAS Moscow, Russia · Independent researcher Moscow, Russia

Abstract

Digital image watermarking is increasingly critical in media contexts, as emerging regulations and industry practices require marking AI-generated content and ensuring traceable sources to prevent manipulation or misuse. Recent advances in invisible watermarking methods highlight the need to update existing benchmarking practices to reflect current techniques and evaluation criteria. We address this by introducing WARP -- a unified framework and benchmark for evaluating the robustness of invisible watermarks. WARP incorporates 32 recent classical, deep, and generative watermarking methods, as well as 34 different erasing techniques, ranging from traditional distortions to more sophisticated adversarial, purification, and re-embedding attacks. It provides standardized, reproducible, and easily scalable protocols for evaluating perceptual quality, watermark readability, and attack resilience. Using WARP, we extensively evaluate current invisible watermarking techniques, collecting the largest robustness benchmark in the field. Results identify the most robust approaches under both distortion and adversarial conditions, and reveal consistent relationships between watermarking methods and the attack strategies most effective against them. Our experiments also highlight that some of the watermarking methods considered are highly vulnerable to reembedding, even if they are robust to standard distortions. The code is made available at https://github.com/ispras/wibe.

Figures & tables

Appendix figures & tables16 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. SpreadMark: Robust Image Watermarking via Spread-Spectrum Embedding

    Aug 4, 2026Wei Song, Yuxin Cao, Zhenchang Xing +4WatermarksDeepfake Detection

  2. What Breaks Local Watermarks? A Robustness Benchmark for Local Invisible Image Watermarking

    Sep 15, 2026Kai Yao, Bence Szilágyi, Sebestyén Kamp +4WatermarksLocalization

  3. MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent Manipulation

    Aug 10, 2026Jie Cao, Qi Li, Zelin Zhang +4WatermarksAi-Generated Image Detection