A Technical Report on “Erasing the Invisible”: The 2024 NeurIPS Competition on Stress Testing Image Watermarks
Abstract
AI-generated images have become pervasive, raising critical concerns around content authenticity, intellectual property, and the spread of misinformation. Invisible watermarks offer a promising solution for identifying AI-generated images, preserving content provenance without degrading visual quality. However, their real-world robustness remains uncertain due to the lack of standardized evaluation protocols and large-scale stress testing. To bridge this gap, we organized “Erasing the Invisible,” a NeurIPS 2024 competition and newly established benchmark designed to systematically stress testing the resilience of watermarking techniques. The competition introduced two attack tracks—Black-box and Beige-box—that simulate practical scenarios with varying levels of attacker knowledge on watermarks, providing a comprehensive assessment of watermark robustness. The competition attracted significant global participation, with 2,722 submissions from 298 teams. Through a rigorous evaluation pipeline featuring real-time feedback and human-verified final rankings, participants developed and demonstrated new attack strategies that revealed critical vulnerabilities in state-of-the-art watermarking methods. On average, the top-5 teams in both tracks could remove watermarks from $\geq$ 89% of the images while preserving high visual quality, setting strong baselines for future research on watermark attacks and defenses. To support continued progress in this field, we summarize the insights and lessons learned from this competition in this paper, and release the benchmark dataset, evaluation toolkit, and competition results. “Erasing the Invisible” establishes a valuable open resource for advancing more robust watermarking techniques and strengthening content provenance in the era of generative AI.
Cite
Text
Ding et al. "A Technical Report on “Erasing the Invisible”: The 2024 NeurIPS Competition on Stress Testing Image Watermarks." Advances in Neural Information Processing Systems, 2025.Markdown
[Ding et al. "A Technical Report on “Erasing the Invisible”: The 2024 NeurIPS Competition on Stress Testing Image Watermarks." Advances in Neural Information Processing Systems, 2025.](https://mlanthology.org/neurips/2025/ding2025neurips-technical/)BibTeX
@inproceedings{ding2025neurips-technical,
title = {{A Technical Report on “Erasing the Invisible”: The 2024 NeurIPS Competition on Stress Testing Image Watermarks}},
author = {Ding, Mucong and An, Bang and Rabbani, Tahseen and Deng, Chenghao and Satheesh, Anirudh and Chakraborty, Souradip and Saberi, Mehrdad and Wen, Yuxin and Sang, Kyle Rui and Agrawal, Aakriti and Zhao, Xuandong and Zhou, Mo and Hartley, Mary-Anne and Li, Lei and Wang, Yu-Xiang and Patel, Vishal M. and Feizi, Soheil and Goldstein, Tom and Huang, Furong},
booktitle = {Advances in Neural Information Processing Systems},
year = {2025},
url = {https://mlanthology.org/neurips/2025/ding2025neurips-technical/}
}