YuxinWenRick/tree-ring-watermark

The problem about cropping and rotation attacks

asdcaszc opened this issue · 1 comments

Hi,

I have read your paper and it is a very interesting paper to embed the watermark into the latent code. However, when I test your code, the TPR@1%FPR for rotation attacks is only 70%.

When I read other papers, I found another paper called aqualora. Their result showed the performance for crop attacks is not good in your method. In addition, a method improved from yours Robust Image Watermarking using Stable Diffusion also cannot get good performance. Finally, the hugging face unofficial demo based on your method demo cannot get satisfying results.

Do you know how to improve the bad performance in these cases? Is the different GPU or other hyperparameters influnce it? Thanks for your kind sharing and wait your reply.

Best regards

Hi, thanks for reaching out.

The TPR@1%FPR under rotation attacks is around 70% from my side too, and the AUC is around 0.94. You may also get almost perfect TPR@1%FPR with 90-degree attacks instead of 75-degree attacks, but overall, I don't think it's super bad, and it's what we reported in our paper in Table 2.

Let me know if you have further questions!