← Latest papers
💻 computer science

SHIFT: Stochastic Hidden-Trajectory Deflection for Removing Diffusion-based Watermark

The paper introduces SHIFT, a training-free attack that exploits the fundamental vulnerability of trajectory reconstruction in diffusion-based watermarking by using stochastic resampling to deflect the generative path in latent space, thereby achieving near-perfect removal of diverse watermarks while preserving image quality without requiring specific knowledge of the watermarking method.

Original authors: Rui Bao, Zheng Gao, Xiaoyu Li, Xiaoyan Feng, Yang Song, Jiaojiao Jiang

Published 2026-04-01
📖 5 min read🧠 Deep dive

Original authors: Rui Bao, Zheng Gao, Xiaoyu Li, Xiaoyan Feng, Yang Song, Jiaojiao Jiang

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you have a magical art machine (a Diffusion Model) that can draw any picture you describe. To stop people from stealing these AI drawings or spreading fake news, scientists invented a digital watermark.

Think of this watermark not as a visible logo, but as a secret recipe baked into the very DNA of how the picture was made.

  • How it works: When the machine draws a picture, it starts with static noise (like TV snow) and slowly turns it into an image. The "watermark" is a tiny, specific pattern hidden in that initial noise or the specific path the machine took to turn noise into art.
  • How it's checked: To prove a picture is real, a detective (the verifier) tries to run the machine in reverse. They take the finished picture, feed it back into the machine, and see if it turns back into the exact same secret noise pattern. If the noise matches the secret recipe, the picture is "authentic."

The Problem: The "Perfect Reverse" Assumption

For years, experts thought this system was unbreakable. They assumed that if you took a picture and ran it backward, it would always lead back to the original secret noise, no matter what. It's like assuming that if you un-bake a cake, you will always get back the exact same bowl of flour and eggs you started with.

The Solution: SHIFT (The "Stochastic Hidden-Trajectory Deflection")

The authors of this paper discovered a flaw in that assumption. They realized that while the machine can run backward perfectly, it doesn't have to. It can also run backward in a random, wobbly way.

They created an attack called SHIFT (Stochastic Hidden-Trajectory Deflection). Here is how it works, using a simple analogy:

The Analogy: The Hiking Trail

Imagine the AI drawing a picture is like a hiker walking down a specific, narrow mountain trail (the Trajectory) to reach a beautiful lake (the Image).

  • The Watermark: The hiker leaves a specific set of footprints on the trail. To prove they were there, a ranger checks if the footprints match the hiker's unique boot pattern.
  • The Old Defense: The ranger assumes that if you walk backward from the lake, you will only be able to follow the exact same footprints back to the start.

SHIFT is like a magical wind that blows the hiker off the trail.

  1. Step 1: The "Fog" (Partial Forward Diffusion)
    The attacker takes the finished picture and "fogs it up" slightly. This is like covering the hiker's footprints with a light layer of snow. The picture still looks like the same beautiful lake, but the specific trail details are getting blurry.

  2. Step 2: The "Random Jump" (Stochastic Reverse Resampling)
    This is the magic part. Instead of carefully walking backward along the old, snowy trail, the attacker tells the machine to jump randomly.

    • The machine starts from the foggy picture and begins to "un-draw" it.
    • But instead of following the old path, it adds a little bit of random chaos (like a gust of wind) at every single step.
    • The machine still knows how to make a beautiful picture (the lake still looks like a lake), but it takes a completely different path to get there.

The Result: The "Ghost" Trail

When the detective tries to check the picture:

  • They run the machine backward.
  • Because the attacker used the "random jump" method, the machine traces a brand new, random path back to the start.
  • The starting point they find is completely different from the original secret noise.
  • The footprints don't match. The ranger says, "This isn't the original hiker!"
  • The watermark is gone.

Why is this a big deal?

  • It's Universal: It doesn't matter how the watermark was hidden (in the noise, in the colors, or in the shape). As long as the system relies on "running backward to check," SHIFT breaks it.
  • It's Invisible: The picture still looks amazing. The "random jump" is guided by the AI's brain, so it fixes the picture as it goes. The image quality remains high, but the secret code is destroyed.
  • It's Simple: You don't need to be a genius hacker or retrain the AI. You just need to know how to make the AI take a "random walk" backward.

The Takeaway

The paper reveals that the "unbreakable" lock on AI art was actually just a one-way street. The defenders assumed you could only go one way (forward) and then come back the exact same way. The authors showed that if you introduce a little bit of controlled randomness on the way back, you can erase the evidence of where you came from, leaving the picture looking perfect but the proof of its origin completely wiped out.

In short: SHIFT is a "reset button" that scrambles the secret history of an AI image while keeping the picture itself looking beautiful.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →