Watermarks are increasingly being used to make AI-generated images recognizable and to ensure their origin can be traced. Previous research has focused on whether watermarks can withstand image manipulation. CISPA researcher Michel Meintz from the SprintML Lab has investigated whether watermarks can withstand the training of a new generative model.
The result: Not all watermarks are equally robust. Their ability to persist across multiple model generations depends heavily on their design and the model that is used. The paper “Watermark Degradation Across Model Iterations” was presented at the ACM Workshop on Information Hiding and Multimedia Security (IH&MMSec 26) in Florence.
AI-generated images are ubiquitous today and are widely distributed, especially via the internet. This increases the risk that AI-generated images will be used to train new image-generation models. “When companies train on their own synthetic data, it can lead to model collapse,” explains Michel Meintz. “The more you train on your own synthetic data, the more likely the model’s quality is to deteriorate.”
