NeurIPS 2024 Competition
Erasing the Invisible:
A Stress-Test Challenge for Image Watermarks

The Submission Phase has the following two tracks. You could participate in both tracks. Two tracks are hosted on Codabench. Please follow the guidelines and submit your results on Codabench.

Black Box Track (Codabench link)

The black-box attack track simulates a real-world scenario where attackers must operate without knowledge of the watermarking technique employed. In this track, participants are provided with watermarked images, yet the specific watermarking method remains undisclosed. This track reflects a common situation in industry where watermark methods are kept confidential to protect against unauthorized removal or tampering. The participants’ challenge is to develop techniques that can effectively disrupt the watermark, while preserving image quality, without any insights into the methods used to embed them. This will test the watermark’s resilience under conditions that mimic actual adversarial attacks.

Beige Box Track (Codabench link)

The beige-box attack track offers a more transparent approach by providing participants with images alongside labels indicating the watermarking methodology used. The disclosure of the watermark methodology enables participants to use different strategies for attacking different watermarks. The beige-box track is designed to encourage a deeper understanding of watermark robustness and the development of novel attack vectors that could potentially counteract watermarking when some information about the underlying process is known.