Backfire: watermark that strengthens under diffusion purifier attacks, 99.5% survival
ckn · reddit · 2026-09-02
Zhao et al. (arXiv:2306.01953) showed regeneration attacks strip ordinary invisible watermarks. Backfire is a keyed mark optimized as a fixed point of the purifier — running the attack makes the identifier more readable (2.5x confidence in the demo).
Provcheck.ai v1.4.0 results on a 200-image corpus at 30 dB:
- 99.5% survival vs diffusion regeneration; 94–97.5% vs learned VAE re-encode (86.5% on the hardest iterated pass)
- 99.0% JPEG q90, 98.5% q50, 98.0% resize, 97.0% blur
- Zero false positives across 200 marked + 1,000 unmarked images; wrong key reads 0.08, so the mark lives in the key, not the pixels
- Known limit: doesn't survive controllable regeneration from clean noise (see LIMITS.md)
Also released: a free Apache-2.0 ComfyUI node that watermarks (TrustMark/silentcipher) and C2PA-signs outputs in-graph. Backfire itself is a separate opt-in add-on. Repo: github.com/CreativeMayhemLtd/provcheck
More from Apps
- Video generation has matured: you can now direct models instead of prompting and hoping — MilitantAI · 2026-09-03
- Matt Shumer's Browser Game Fable 5.1 Keeps Improving Itself, Multiplayer Live — mattshumer_ · 2026-09-03
- 3-year-old Reddit threads get cited in Gemini answers with zero optimization — gaganghotra_ · 2026-09-03
- Replit CEO: Designers' Time in Figma Down, Prototyping in Replit/ChatGPT Up — amasad · 2026-09-03
- Launch Videos for Under $10 With Replit Animation, vs $200K Agency Spend — amasad · 2026-09-03
- Unity researcher voxelized his living room into billions of millimeter-scale voxels, stunned Stanford VR audience — Scobleizer · 2026-09-03