Appendices776
–Neural Information Processing Systems
ALimitations777 As described in Sections 4 and 6, users would tailor attacks to image clusters. In the case of beige778 box, we outright provided these clusters by disclosing which image indices corresponded to which779 general watermark type. For the black-box track, several winning teams clustered images into groups780 by artifact varieties and did so by hand. For the latter, this was made possible because (1) our data set781 was relatively small, enabling this type of manual data labeling, and (2) they were made aware that782 the dataset contained mixtures of several watermarks. A database owner who uses only one type of783 watermark will unlikely produce such variation in artifacts.784 Additionally, we use the watermark models and setting provided in the original papers and do not785 calibrate the strength of watermarks.
Neural Information Processing Systems
Jun-15-2026, 01:41:04 GMT