Watermarks offer no defense against deepfakes
Waterloo researchers create “UnMarker” tool that can remove any AI image watermark, highlighting continuing dangers of deepfakes
2025-07-23
(Press-News.org)
New research from the University of Waterloo’s Cybersecurity and Privacy Institute demonstrates that any artificial intelligence (AI) image watermark can be removed, without the attacker needing to know the design of the watermark, or even whether an image is watermarked to begin with.
As AI-generated images and videos became more realistic, citizens and legislators are increasingly concerned about the potential impact of “deepfakes” across politics, the legal system and everyday life.
“People want a way to verify what’s real and what’s not because the damages will be huge if we can’t,” said Andre Kassis, a PhD candidate in computer science and the lead author on the research. “From political smear campaigns to non-consensual pornography, this technology could have terrible and wide-reaching consequences.”
AI companies, including OpenAI, Meta, and Google, have offered invisible encoded “watermarks” as a solution, suggesting these secret signatures can allow them to create publicly available tools that consistently and accurately distinguish between AI-generated content and real photos or videos, without revealing the nature of the watermarks.
The Waterloo team, however, has created a tool, UnMarker, which successfully destroys watermarks without needing to know the specifics of how they’ve been encoded. UnMarker is the first practical and universal tool that can remove watermarking in real-world settings. What sets UnMarker apart is that it requires no knowledge of the watermarking algorithm, no access to internal parameters, and no interaction with the detector at all. It works universally, stripping both traditional and semantic watermarks without any customization.
“While watermarking schemes are typically kept secret by AI companies, they must satisfy two essential properties: they need to be invisible to human users to preserve image quality, and they must be robust, that is, resistant to manipulation of an image like cropping or reducing resolution,” said Dr. Urs Hengartner, associate professor of the David R. Cheriton School of Computer Science at the University of Waterloo.
“These requirements constrain the possible designs for watermarks significantly. Our key insight is that to meet both criteria, watermarks must operate in the image’s spectral domain, meaning they subtly manipulate how pixel intensities vary across the image.”
Using a statistical attack, UnMarker looks for places in the image where the pixel frequency is unusual, and then distorts that frequency, making the image unrecognizable to the watermark-recognizing tool but undetectably different to the naked eye. In tests, the method worked more than 50 per cent of the time on different AI models – including Google’s SynthID and Meta’s Stable Signature – without existing knowledge of the images’ origins or watermarking methods.
“If we can figure this out, so can malicious actors,” Kassis said. “Watermarking is being promoted as this perfect solution, but we’ve shown that this technology is breakable. Deepfakes are still a huge threat. We live in an era where you can’t really trust what you see anymore.”
The research, “UnMarker: A Universal Attack on Defensive Image Watermarking,” appears in the proceedings of the 46th IEEE Symposium on Security and Privacy.
END
ELSE PRESS RELEASES FROM THIS DATE:
2025-07-23
Air pollution is a global health concern, with over 90% of the world’s population breathing air that exceeds World Health Organization safety standards. Fine and coarse particulate matter are especially dangerous, as they can penetrate deep into the lungs and bloodstream. While the link between air pollution and respiratory diseases is well established, how these pollutants disrupt immune responses in the lungs has remained unclear.
In a recent study, a team of researchers led by Professor Changwan Hong from Pusan National University ...
2025-07-23
WINSTON-SALEM, N.C., July 23, 2025 — A groundbreaking brain imaging study from Wake Forest University School of Medicine confirms a vital step toward new Alzheimer’s disease treatments: Intranasal insulin, delivered via a simple nasal spray, safely and effectively reaches key memory regions of the brain in older adults. The study also revealed that people with early cognitive decline absorb it differently.
This research, published in Alzheimer’s & Dementia: Translational Research & Clinical Interventions, describes the ...
2025-07-23
In a twist worthy of a detective novel, a long-misidentified fossil at Harvard’s Museum of Comparative Zoology (MCZ) has emerged as a key discovery in early animal evolution. Originally described in 1865 as a caterpillar, Palaeocampa anthrax shuffled between classifications—worm, millipede, and eventually a marine polychaete—until 130 years later, when researchers realized its true identity: the first-known nonmarine lobopodian and the earliest one ever discovered.
Lobopodians are extinct, soft-bodied creatures that bridge the evolutionary gap between a primitive worm-like ancestor and modern ...
2025-07-23
People with any type of substance use disorder (SUD) stand a 24% higher risk of having an unplanned hospital readmission within 30 days of a previous discharge compared with those without the disorder, new UCLA-led research finds.
People with opioid use disorder had the highest 30-day readmission rates, at nearly 40%, the researchers found. Overall, people with SUDs comprise a disproportionate share of patients with multiple unplanned readmissions.
The higher risk was true only for people with substance use disorders who were discharged to homes without having been provided with post-acute care, said study co-author Steven Shoptaw, director of the Center for ...
2025-07-23
Scientists at The Pirbright Institute have taken a major step forward in tackling one of the world’s most dangerous viruses, the Nipah virus, by evaluating vaccine candidates for pigs.
The Nipah virus is zoonotic, meaning it can be transmitted from animals to humans. Originating in Old World fruit bats, the virus primarily affects pigs and humans.
The virus was first identified during a major outbreak in 1998-99 in Malaysia which led to the culling of nearly half the country's pig population and resulted in significant economic losses.
Since then, the virus has continued to cause outbreaks in South and Southeast ...
2025-07-23
Promoting pyroptosis—an inflammatory form of programmed cell death—has become a promising treatment strategy for cancer. In research published in The FASEB Journal, investigators purified a long-chain sugar molecule, or exopolysaccharide, from deep-sea bacteria and demonstrated that it triggers pyroptosis to inhibit tumor growth.
The compound, called EPS3.9, consists of mannose and glucose and is produced by the Spongiibacter nanhainus CSC3.9 bacterial strain and other members of the genus ...
2025-07-23
Respiratory syncytial virus (RSV) is a well-known cause of infections in children, but it’s understudied in older individuals. In a retrospective study published in the Journal of the American Geriatrics Society, adults aged 65 and older hospitalized for RSV in Ontario, Canada experienced significantly higher rates of adverse outcomes such as longer length of hospital stay, transfer to intensive care, and 30-day mortality, compared with patients hospitalized with influenza, urinary tract infection, or fracture.
Interestingly, RSV hospitalization was also associated with higher rates of heart failure and atrial fibrillation up to 1-year post-discharge, regardless ...
2025-07-23
A review published in Advanced Science highlights the evolution of research related to implantable brain-computer interfaces (iBCIs), which decode brain signals that are then translated into commands for external devices to potentially benefit individuals with impairments such as loss of limb function or speech.
A comprehensive systematic review identified 112 studies, nearly half of which have been published since 2020. Eighty iBCI participants were identified, mostly participating in studies concentrated in the United States, but with growing numbers of studies from Europe, China, and Australia.
The ...
2025-07-23
New research in Plants, People, Planet indicates that bread wheat’s micronutrient content can be increased by cultivating it with a specific type of fungus.
When investigators grew different types of wheat with and without the arbuscular mycorrhizal fungus Rhizophagus irregularis, they observed that crops grown with fungi developed larger grains with greater amounts of phosphorus and zinc. The higher amount of phosphorus in the grain did not result in an increase in phytate (a compound that can hinder digestion of zinc and iron). As a result, bread wheat grown with fungi had higher bioavailability of zinc and iron overall compared ...
2025-07-23
Bethesda, MD (July 18, 2025) — Researchers employed a machine learning technique known as random forest analysis and found that it significantly outperformed traditional methods in predicting which hospitalized patients with cirrhosis are at risk of death, according to a new paper published in Gastroenterology.
“This gives us a crystal ball — it helps hospital teams, transplant centers, GI and ICU services to triage and prioritize patients more effectively,” said Dr. Jasmohan S. ...
LAST 30 PRESS RELEASES:
[Press-News.org] Watermarks offer no defense against deepfakes
Waterloo researchers create “UnMarker” tool that can remove any AI image watermark, highlighting continuing dangers of deepfakes