{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:54:21Z","timestamp":1781600061427,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":33,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T00:00:00Z","timestamp":1781568000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Adam Dziedzic was supported by the German Research Foundation (DFG) within the framework of the Weave Programme under the project titled \\\"Protecting Creativity: On the Way to Safe Generative Models\\\"","award":["545047250"],"award-info":[{"award-number":["545047250"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,17]]},"DOI":"10.1145\/3785353.3815071","type":"proceedings-article","created":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:11:30Z","timestamp":1781597490000},"page":"177-182","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Watermark Degradation Across Model Iterations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-6945-343X","authenticated-orcid":false,"given":"Michel","family":"Meintz","sequence":"first","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5805-9424","authenticated-orcid":false,"given":"Maitri Vignesh","family":"Shah","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8349-4533","authenticated-orcid":false,"given":"Bihe","family":"Zhao","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2681-6714","authenticated-orcid":false,"given":"Louis","family":"Kerner","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarb\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2111-2234","authenticated-orcid":false,"given":"Franziska","family":"Boenisch","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9786-2296","authenticated-orcid":false,"given":"Adam","family":"Dziedzic","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,16]]},"reference":[{"key":"e_1_3_3_1_2_2","volume-title":"The Twelfth International Conference on Learning Representations","author":"Alemohammad Sina","year":"2024","unstructured":"Sina Alemohammad, Josue Casco-Rodriguez, Lorenzo Luzi, Ahmed\u00a0Imtiaz Humayun, Hossein Babaei, Daniel LeJeune, Ali Siahkoohi, and Richard Baraniuk. 2024. Self-Consuming Generative Models Go MAD. In The Twelfth International Conference on Learning Representations."},{"key":"e_1_3_3_1_3_2","volume-title":"Thirty-seventh Conference on Neural Information Processing Systems Datasets and Benchmarks Track","author":"Andrews Jerone","year":"2023","unstructured":"Jerone Andrews, Dora Zhao, William Thong, Apostolos Modas, Orestis Papakyriakopoulos, and Alice Xiang. 2023. Ethical Considerations for Responsible Data Curation. In Thirty-seventh Conference on Neural Information Processing Systems Datasets and Benchmarks Track. https:\/\/openreview.net\/forum?id=Qf8uzIT1OK"},{"key":"e_1_3_3_1_4_2","volume-title":"IEEE International Conference on Computer Vision (ICCV)","author":"Bui Tu","year":"2025","unstructured":"Tu Bui, Shruti Agarwal, and John Collomosse. 2025. TrustMark: Robust Watermarking and Watermark Removal for Arbitrary Resolution Images. In IEEE International Conference on Computer Vision (ICCV)."},{"key":"e_1_3_3_1_5_2","first-page":"18674","volume-title":"Proceedings of the Computer Vision and Pattern Recognition Conference (CVPR)","author":"Dubi\u0144ski Jan","year":"2025","unstructured":"Jan Dubi\u0144ski, Antoni Kowalczuk, Franziska Boenisch, and Adam Dziedzic. 2025. CDI: Copyrighted Data Identification in Diffusion Models. In Proceedings of the Computer Vision and Pattern Recognition Conference (CVPR). 18674\u201318684."},{"key":"e_1_3_3_1_6_2","volume-title":"Advances in Neural Information Processing Systems","author":"Dziedzic Adam","year":"2022","unstructured":"Adam Dziedzic, Haonan Duan, Muhammad\u00a0Ahmad Kaleem, Nikita Dhawan, Jonas Guan, Yannis Cattan, Franziska Boenisch, and Nicolas Papernot. 2022. Dataset Inference for Self-Supervised Models. In Advances in Neural Information Processing Systems, Alice\u00a0H. Oh, Alekh Agarwal, Danielle Belgrave, and Kyunghyun Cho (Eds.). https:\/\/openreview.net\/forum?id=CCBJf9xJo2X"},{"key":"e_1_3_3_1_7_2","volume-title":"Forty-first international conference on machine learning","author":"Esser Patrick","year":"2024","unstructured":"Patrick Esser, Sumith Kulal, Andreas Blattmann, Rahim Entezari, Jonas M\u00fcller, Harry Saini, Yam Levi, Dominik Lorenz, Axel Sauer, Frederic Boesel, et\u00a0al. 2024. Scaling rectified flow transformers for high-resolution image synthesis. In Forty-first international conference on machine learning."},{"key":"e_1_3_3_1_8_2","first-page":"22466","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV)","author":"Fernandez Pierre","year":"2023","unstructured":"Pierre Fernandez, Guillaume Couairon, Herv\u00e9 J\u00e9gou, Matthijs Douze, and Teddy Furon. 2023. The Stable Signature: Rooting Watermarks in Latent Diffusion Models. In Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV). 22466\u201322477."},{"key":"e_1_3_3_1_9_2","volume-title":"The Fourteenth International Conference on Learning Representations","author":"Gesny Enoal","year":"2026","unstructured":"Enoal Gesny, Eva Giboulot, Teddy Furon, and Vivien Chappelier. 2026. Guidance Watermarking for Diffusion Models. In The Fourteenth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=5ifzhjMCKq"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"crossref","unstructured":"Jian Han Jinlai Liu Yi Jiang Bin Yan Yuqi Zhang Zehuan Yuan Bingyue Peng and Xiaobing Liu. 2025. Infinity: Scaling bitwise autoregressive modeling for high-resolution image synthesis. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2025).","DOI":"10.1109\/CVPR52734.2025.01467"},{"key":"e_1_3_3_1_11_2","first-page":"6840","volume-title":"Advances in Neural Information Processing Systems","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising Diffusion Probabilistic Models. In Advances in Neural Information Processing Systems , H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.), Vol.\u00a033. Curran Associates, Inc., 6840\u20136851. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/4c5bcfec8584af0d967f1ab10179ca4b-Paper.pdf"},{"key":"e_1_3_3_1_12_2","first-page":"4904","volume-title":"International conference on machine learning","author":"Jia Chao","year":"2021","unstructured":"Chao Jia, Yinfei Yang, Ye Xia, Yi-Ting Chen, Zarana Parekh, Hieu Pham, Quoc Le, Yun-Hsuan Sung, Zhen Li, and Tom Duerig. 2021. Scaling up visual and vision-language representation learning with noisy text supervision. In International conference on machine learning. PMLR, 4904\u20134916."},{"key":"e_1_3_3_1_13_2","volume-title":"The Thirty-ninth Annual Conference on Neural Information Processing Systems","author":"Jovanovi\u0107 Nikola","year":"2025","unstructured":"Nikola Jovanovi\u0107, Ismail Labiad, Tomas Soucek, Martin Vechev, and Pierre Fernandez. 2025. Watermarking Autoregressive Image Generation. In The Thirty-ninth Annual Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=hVdD72iom4"},{"key":"e_1_3_3_1_14_2","first-page":"3128","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","author":"Karpathy Andrej","year":"2015","unstructured":"Andrej Karpathy and Li Fei-Fei. 2015. Deep visual-semantic alignments for generating image descriptions. In Proceedings of the IEEE conference on computer vision and pattern recognition. 3128\u20133137."},{"key":"e_1_3_3_1_15_2","volume-title":"The Thirty-ninth Annual Conference on Neural Information Processing Systems","author":"Kerner Louis","year":"2025","unstructured":"Louis Kerner, Michel Meintz, Bihe Zhao, Franziska Boenisch, and Adam Dziedzic. 2025. BitMark: Watermarking Bitwise Autoregressive Image Generative Models. In The Thirty-ninth Annual Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=VSir0FzFnP"},{"key":"e_1_3_3_1_16_2","volume-title":"Forty-Second International Conference on Machine Learning (ICML)","author":"Kowalczuk Antoni","year":"2025","unstructured":"Antoni Kowalczuk, Jan Dubi\u0144ski, Franziska Boenisch, and Adam Dziedzic. 2025. Privacy Attacks on Image AutoRegressive Models. In Forty-Second International Conference on Machine Learning (ICML)."},{"key":"e_1_3_3_1_17_2","first-page":"1207","volume-title":"Proceedings of the 17th International Conference on Machine Learning (ICML 2000)","author":"Langley P.","year":"2000","unstructured":"P. Langley. 2000. Crafting Papers on Machine Learning. In Proceedings of the 17th International Conference on Machine Learning (ICML 2000), Pat Langley (Ed.). Morgan Kaufmann, Stanford, CA, 1207\u20131216."},{"key":"e_1_3_3_1_18_2","volume-title":"The Thirteenth International Conference on Learning Representations","author":"Liu Yepeng","year":"2025","unstructured":"Yepeng Liu, Yiren Song, Hai Ci, Yu Zhang, Haofan Wang, Mike\u00a0Zheng Shou, and Yuheng Bu. 2025. Image Watermarks are Removable using Controllable Regeneration from Clean Noise. In The Thirteenth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=mDKxlfraAn"},{"key":"e_1_3_3_1_19_2","volume-title":"Thirty-Eighth Conference on Neural Information Processing Systems (NeurIPS)","author":"Maini Pratyush","year":"2024","unstructured":"Pratyush Maini, Hengrui Jia, Nicolas Papernot, and Adam Dziedzic. 2024. LLM Dataset Inference: Did you train on my dataset?. In Thirty-Eighth Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_3_1_20_2","volume-title":"International Conference on Learning Representations","author":"Maini Pratyush","year":"2021","unstructured":"Pratyush Maini, Mohammad Yaghini, and Nicolas Papernot. 2021. Dataset Inference: Ownership Resolution in Machine Learning. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=hvdKKV2yt7T"},{"key":"e_1_3_3_1_21_2","unstructured":"Michel Meintz Jan Dubi\u0144ski Franziska Boenisch and Adam Dziedzic. 2025. Radioactive Watermarks in Diffusion and Autoregressive Image Generative Models. arxiv:https:\/\/arXiv.org\/abs\/2506.23731\u00a0[cs.LG] https:\/\/arxiv.org\/abs\/2506.23731"},{"key":"e_1_3_3_1_22_2","volume-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Rombach Robin","year":"2022","unstructured":"Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Bj\u00f6rn Ommer. 2022. High-resolution image synthesis with latent diffusion models. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition."},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"crossref","unstructured":"Chitwan Saharia William Chan Saurabh Saxena Lala Li Jay Whang Emily\u00a0L Denton Kamyar Ghasemipour Raphael Gontijo\u00a0Lopes Burcu Karagol\u00a0Ayan Tim Salimans et\u00a0al. 2022. Photorealistic text-to-image diffusion models with deep language understanding. Advances in neural information processing systems 35 (2022) 36479\u201336494.","DOI":"10.52202\/068431-2643"},{"key":"e_1_3_3_1_24_2","volume-title":"The Thirty-eighth Annual Conference on Neural Information Processing Systems","author":"Sander Tom","year":"2024","unstructured":"Tom Sander, Pierre Fernandez, Alain\u00a0Oliviero Durmus, Matthijs Douze, and Teddy Furon. 2024. Watermarking Makes Language Models Radioactive. In The Thirty-eighth Annual Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=qGiZQb1Khm"},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"crossref","unstructured":"Christoph Schuhmann Romain Beaumont Richard Vencu Cade Gordon Ross Wightman Mehdi Cherti Theo Coombes Aarush Katta Clayton Mullis Mitchell Wortsman et\u00a0al. 2022. Laion-5b: An open large-scale dataset for training next generation image-text models. Advances in neural information processing systems 35 (2022) 25278\u201325294.","DOI":"10.52202\/068431-1833"},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"crossref","unstructured":"Ilia Shumailov Zakhar Shumaylov Yiren Zhao Nicolas Papernot Ross Anderson and Yarin Gal. 2024. AI models collapse when trained on recursively generated data. Nature 631 8022 (2024) 755\u2013759.","DOI":"10.1038\/s41586-024-07566-y"},{"key":"e_1_3_3_1_28_2","volume-title":"Advances in Neural Information Processing Systems","author":"Song Yang","year":"2020","unstructured":"Yang Song and Stefano Ermon. 2020. Improved Techniques for Training Score-Based Generative Models. In Advances in Neural Information Processing Systems. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/92c3b916311a5517d9290576e3ea37ad-Paper.pdf"},{"key":"e_1_3_3_1_29_2","first-page":"2117","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"Tancik Matthew","year":"2020","unstructured":"Matthew Tancik, Ben Mildenhall, and Ren Ng. 2020. Stegastamp: Invisible hyperlinks in physical photographs. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition. 2117\u20132126."},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"crossref","unstructured":"Keyu Tian Yi Jiang Zehuan Yuan Bingyue Peng and Liwei Wang. 2024. Visual autoregressive modeling: Scalable image generation via next-scale prediction. Advances in neural information processing systems 37 (2024) 84839\u201384865.","DOI":"10.52202\/079017-2694"},{"key":"e_1_3_3_1_31_2","first-page":"58047","volume-title":"Advances in Neural Information Processing Systems","author":"Wen Yuxin","year":"2023","unstructured":"Yuxin Wen, John Kirchenbauer, Jonas Geiping, and Tom Goldstein. 2023. Tree-Rings Watermarks: Invisible Fingerprints for Diffusion Images. In Advances in Neural Information Processing Systems , A.\u00a0Oh, T.\u00a0Naumann, A.\u00a0Globerson, K.\u00a0Saenko, M.\u00a0Hardt, and S.\u00a0Levine (Eds.), Vol.\u00a036. Curran Associates, Inc., 58047\u201358063."},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"crossref","first-page":"2113","DOI":"10.1145\/3630106.3659029","volume-title":"Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency","author":"Wyllie Sierra","year":"2024","unstructured":"Sierra Wyllie, Ilia Shumailov, and Nicolas Papernot. 2024. Fairness feedback loops: training on synthetic data amplifies bias. In Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency. 2113\u20132147."},{"key":"e_1_3_3_1_33_2","unstructured":"Qihang Yu Ju He Xueqing Deng Xiaohui Shen and Liang-Chieh Chen. 2024. Randomized Autoregressive Visual Generation. arxiv:https:\/\/arXiv.org\/abs\/2411.00776\u00a0[cs.CV] https:\/\/arxiv.org\/abs\/2411.00776"},{"key":"e_1_3_3_1_34_2","unstructured":"Kevin\u00a0Alex Zhang Lei Xu Alfredo Cuesta-Infante and Kalyan Veeramachaneni. 2019. Robust Invisible Video Watermarking with Attention. (2019)."}],"event":{"name":"IH&MMSec '26: ACM Workshop on Information Hiding and Multimedia Security","location":"Firenze Italy","acronym":"IH&MMSec '26","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2026 ACM Workshop on Information Hiding and Multimedia Security"],"original-title":[],"deposited":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:15:12Z","timestamp":1781597712000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3785353.3815071"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,16]]},"references-count":33,"alternative-id":["10.1145\/3785353.3815071","10.1145\/3785353"],"URL":"https:\/\/doi.org\/10.1145\/3785353.3815071","relation":{},"subject":[],"published":{"date-parts":[[2026,6,16]]},"assertion":[{"value":"2026-06-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}