Chun-peng Wang, Feng Zhang, Shanshan Zhang, Yunan Liu, Yuli Wang, Qi Li, Zhi-qiu Xia
Abstract
Digital image watermarking is a critical technology for image copyright protection. The concurrent evolution of watermarking attacks and defenses has spurred rapid advancements in the field. However, watermarking attack methods have lagged behind, often facing two primary challenges: limited watermark removal ability and quality degradation of the attacked image. In this paper, we introduce a Watermarking Attack method based on the Residual Diffusion Model, termed WARDM. Our WARDM treats watermark information as noise and leverages the powerful image reconstruction capabilities of the diffusion model to effectively remove the watermark. Specifically, we construct a Markov chain based on the residuals between the host and watermarked images, and employ reverse propagation to reconstruct the original host image. To optimally balance watermark removal ability and image quality, we incorporate a noise schedule into WARDM that controls both the velocity and intensity of noise at each stage of the Markov chain. Extensive experiments demonstrate the superior performance of WARDM in both watermark removal capability and visual quality preservation, achieving an improvement of 5.39% in PSNR over state-of-the-art methods. Moreover, our method demonstrates strong generalization, effectively executing attacks across a variety of watermarking techniques.
Citation format
WANG, Chun-peng, et al. Can watermarks be removed like noise? A watermarking attack network using residual diffusion model. IEEE Transactions on Dependable and Secure Computing, 2026.