[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-defense-cuts-ai-watermark-forgery-success-from-87-to-1":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},10094,"new-defense-cuts-ai-watermark-forgery-success-from-87-to-1","New Defense Cuts AI Watermark Forgery Success From 87% To 1%","A new technique randomizes which secret key signs each AI output, slashing watermark forgery rates without the usual utility tradeoffs of other defenses.","A new defense makes it much harder to fake a company's watermark on text or images it never generated.\n\nResearchers propose swapping the usual approach - stamping content with one fixed key, or multiple keys at once to resist forgery - for a randomized pick: each query gets a single key chosen at random, and content only counts as genuine if exactly one key's signal shows up. In testing against adaptive \"blind\" attackers who get to see several watermarked samples, that cut harmful-text forgery success from as high as 87% with one key to as low as 1% using four keys, and a preliminary image test with the Tree-Ring watermarking method saw forgery success drop from 100% to 2%. The added computing cost was negligible. Because the method treats the underlying watermark as a black box, it can bolt onto any existing watermarking scheme instead of requiring a new one built from cryptographic-hardness assumptions.\n\nThat matters because watermarking is the mechanism AI providers are counting on to let platforms, researchers, and regulators tell AI output apart from everything else online. A forgery attack - planting a provider's watermark on content the provider never made - breaks that trust model and can be used to frame a company for content it didn't produce. The standard fix until now was piling on more simultaneous keys, which degrades the underlying model's quality. This approach claims the same forgery resistance without that cost, which is the harder problem to solve.\n\nOne caveat: \"blind attacker\" is a specific, bounded threat model, and a few lab benchmarks are a long way from proving watermark forgery is a solved problem in the wild.","[\"watermarking\",\"ai safety\",\"generative ai\",\"content provenance\"]","2026-10-05T04:00:00.000Z","2026-10-05T22:44:27.190Z","2026-10-05T22:44:33.500Z","published",null,[],"ai",[26,27,28,29],"watermarking","ai safety","generative ai","content provenance",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2507.07871",0,{"sections":36},[37,41,45,50,55,60,64,69,74,79,84,89,94,99],{"name":38,"slug":24,"count":39,"latest_published_at":40},"AI",6317,"2026-10-05T09:51:57.000Z",{"name":42,"slug":43,"count":44,"latest_published_at":18},"Security","security",871,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",446,"2026-10-05T10:25:00.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",340,"2026-10-05T09:18:03.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",205,"2026-10-05T10:58:22.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":18},"Science","science",179,{"name":65,"slug":66,"count":67,"latest_published_at":68},"Consumer Tech","consumer-tech",160,"2026-10-05T10:23:15.000Z",{"name":70,"slug":71,"count":72,"latest_published_at":73},"Dev Tools","dev-tools",99,"2026-10-05T10:47:06.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Software","software",97,"2026-10-04T10:00:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",93,"2026-10-05T11:13:51.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",51,"2026-10-05T02:35:01.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",32,"2026-10-02T18:00:00.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",8,"2026-10-05T09:00:00.000Z"]