Hi, interesting work.. Thought it might be worth having an open discussion on this topic.
I presume there will be a scramble to fix this, so heres some theorycrafting.
- I initially thought maybe treating the watermark as a reseting auth key might be a solution, Broken by figuring out the pattern change via time series repetition prior to generation of the actual image you want.
- Forcing the model to never generate pure black / pure white images - Broken by then switching to a fixed simple image request (ie; generate green circle of specific values, specific dimensions on pure white background.
It would be interesting to know whether this embedding is done via a postprocessing step or if it is baked into the model itself, the latter may be more of an issue for them.
Also do we think generated audio could also be de-watermarked (if it is in fact watermarked) in this manner too, using blank audio generations?
Hi, interesting work.. Thought it might be worth having an open discussion on this topic.
I presume there will be a scramble to fix this, so heres some theorycrafting.
It would be interesting to know whether this embedding is done via a postprocessing step or if it is baked into the model itself, the latter may be more of an issue for them.
Also do we think generated audio could also be de-watermarked (if it is in fact watermarked) in this manner too, using blank audio generations?