RC RANDOM CHAOS

Your watermark is a spymark

Watermark detection recovers a signal, not an author, so any party with write access can embed a hidden tracking mark defender tooling reads as clean.

· 9 min read
Your watermark is a spymark

A watermark and a spymark occupy the same physical space inside an asset. Both embed a signal that survives compression, cropping, format conversion, and re-encoding. Both are built to be invisible to the person holding the file. The only difference is intent and control. A watermark is embedded by the party that owns or distributes the asset, and it answers one question: where did this copy come from. A spymark is embedded to answer a different question: where is this copy now, and who is touching it. Same mechanism. Opposite direction of trust.

The security-relevant point is that watermarking technology does not verify who embedded the mark. State it plainly. A robust, imperceptible mark is a capability, not an owner. Any party that can write to the asset before, during, or after distribution can embed one. The detector recovers a signal. It does not authenticate the author of that signal. The same robustness engineered to stop a leaker from stripping a mark also protects an attacker’s mark from removal. Resilience is neutral. It serves whoever embedded last.

This matters because watermarking is being deployed as a control across content provenance, model-output attribution, DRM traitor tracing, and asset leak detection. The claim being sold is trace and prove. The capability being shipped is embed a resilient covert channel into every asset that leaves your environment. Those are not the same claim. The gap between them is where a spymark lives, and nothing in the current deployment model closes it.

Watermarking was designed under a single-owner trust model. One party embeds, one party detects, and the asset in between is treated as passive data. The threat modeled was a leaker or a thief who wants the mark gone. Every design goal followed from that. Imperceptibility, so the adversary cannot locate the mark to target it. Robustness, so the adversary cannot destroy it with normal processing. Capacity, so the mark can carry a unique per-recipient identifier. The adversary in that model is downstream and hostile to the mark.

That model assumes the embedding party is trusted and singular. It assumes the mark is inert: it labels, it does not act, it does not communicate on its own. It assumes detection is a privilege held by the owner. It assumes the asset is the object of protection, not the delivery vehicle. Under those assumptions watermarking is coherent. Traitor tracing works because each recipient’s copy carries a distinct, hard-to-remove identifier, and a recovered leak points back to a recipient. The logic is clean as long as the world matches the diagram.

None of those assumptions are enforced by the technology. State that as a control finding, not a caveat. Nothing in a watermarking scheme authenticates the embedder. Nothing prevents a second mark from a second party occupying the same asset. Nothing makes the mark inert. Inertness is a property of how the mark is used, not of the mark itself. The trust was placed in the operating assumption, not in an enforced boundary. A control that depends on the adversary occupying only the position you imagined is not a control. It is an arrangement, and arrangements do not survive contact with an attacker who declines to stand where you put them.

Invert the trust model and the same technology becomes a tracking system. A spymark keeps every engineered property of a watermark and changes only two things: the party doing the embedding and the purpose of the mark. The attacker is no longer downstream trying to remove a mark. The attacker is upstream or lateral, writing a mark of their own into assets that pass through a surface they control. A shared template. A compromised export pipeline. A generation model. A document that gets forwarded. A media file seeded into a distribution channel. Robustness now works for the attacker. The mark they embed survives exactly the transformations a defender’s watermark was built to survive.

Bypassing watermark detection is a property of the same design, not a separate exploit. Watermark detectors look for a specific, known signal keyed to the owner. A spymark is not that signal. It is tuned outside the detector’s key space, so a provenance or leak scan looking for the owner’s mark returns clean while the attacker’s mark rides underneath it. Two independent marks can coexist in one asset because the channel has capacity and the detectors are not looking for each other. The defender’s tooling confirms the asset is authentic and never registers that it is also tagged. Clean is not the same as unmarked. The scan only reports on the signal it was told to find.

Tracking in the wild is what the mark enables once it survives and stays hidden. A unique per-target spymark turns any later recovery of the asset into a location and identity signal: this specific copy, tied to this specific recipient or environment, has surfaced here. Pair the mark with any point where the asset is later observed, a re-upload, a scan, a submission, a callback, and the attacker holds the same traitor-tracing capability the technology was built to give owners, aimed at targets who never consented and cannot see it. The capability did not change. The party holding it did. That is the entire shift, and it is enough.

The failure is that detection is keyed to a signal, not to an author. A watermark detector recovers the specific mark it was configured to find and confirms whether that mark is present. It does not enumerate every signal carried in the asset. The perceptual space that survives compression, cropping, and re-encoding has capacity for more than one mark, and the detector reads only the key it holds. Everything written outside that key is outside its report. The mark was not bypassed by defeating the detector. The mark was bypassed because “clean” was defined as absence of the owner’s signal and then read as absence of any signal. Those are two different measurements. The tooling only ever performed the first.

Robustness compounds the gap. Robustness is the property that a mark survives transformation, and it is applied to whatever occupies the channel. It carries no field for the identity of the party that wrote the mark. The same property that stops a leaker from stripping the owner’s signal stops a defender from stripping an attacker’s signal, on the condition the defender knew to look, which the keyed detector does not prompt them to do. This is enforcement without authentication. The scheme enforces persistence of a signal. It does not enforce ownership of that signal. Enforcement without authentication protects whoever wrote last and whoever wrote in a key the defender is not scanning.

The trust relationship is inverted at the point of write access. In the designed model, embedding and detecting are one party’s privilege. The break is that embedding is not a privilege enforced by the technology. It is a capability available to any party with write access to the asset at any point along its path. Write access is the boundary that decides the outcome, and the watermarking scheme does not treat it as a boundary. It treats singular, trusted write access as a given. Once the asset crosses a surface the attacker controls, the attacker holds the same embed capability the owner holds, and the detector on the far end cannot separate the two marks by origin, because origin is not a field the detector reads.

A control that reports on one known signal and nothing else converts every negative result into false assurance the moment a second party can write to the same channel. The scan is accurate about what it measured. The reading of the scan is where the failure lives. “No owner mark found” becomes “asset is untagged” becomes “asset is safe to forward.” Each step discards information the scan never claimed to provide. At the end the defender is treating a channel they do not fully read as a channel they fully control. The mechanism is a keyed scanner returning clean and clean being promoted to safe.

This exposes what watermarking becomes when it is shipped as an outbound control. It writes a resilient covert channel into every asset that leaves the environment. The same infrastructure that gives the owner a durable channel gives any party with pipeline write access a channel of equal durability. The defender’s own distribution path becomes the delivery mechanism for a second mark, because the asset was built to carry marks and to carry them through exactly the transformations that would otherwise remove them. The capability is symmetric. The deployment assumed it was exclusive. Same channel, same robustness, different holder.

The tracking outcome runs on the same mechanism, not a separate one. A per-target mark paired with any later point where the asset is observed is traitor tracing. The technology’s intended use and its abuse are one operation executed by different parties. Every property engineered to make the owner’s tracing reliable makes an attacker’s tracking reliable to the same degree. The pattern holds wherever a capability’s security depends on who holds it while the technology does not enforce who holds it: the capability is then available to both sides at full strength. Automation scales both directions. A pipeline step that marks every asset marks every asset for whoever controls that step.

A watermark and a spymark are the same object, and the threat model must treat them as the same object. The presence of watermarking in a pipeline is not a defensive control by default. It is a covert channel that the defender may or may not exclusively hold. Whether it functions as a control or as an exposure depends on a boundary the technology does not enforce: who can write to the asset, and whether detection authenticates the writer. Neither is confirmed by the scheme itself. On the mechanism described, embedder authentication, exclusive write access, and full-channel detection are not confirmed. Their absence is the operating condition.

What must now be true is narrow and non-negotiable. Detection must authenticate the embedder, not only recover a signal. A negative result must be scoped to the key that was scanned and must never be read as absence of all marks. Write access to the asset across its full path must be treated as the boundary it already is. Absent those three, watermarking is an unauthenticated covert channel carrying defender-grade robustness, open to any party in the asset’s path, and the defender’s confidence in a clean scan is confidence in a measurement that was never designed to answer the question being asked of it.

If a system allows a second mark, a second mark will be written. That is not a forecast. It is the operating property of a boundary that is assumed and not enforced. The question the owner asks their watermark, where did this copy come from, and the question an attacker asks theirs, where is this copy now and who is touching it, execute on identical infrastructure. Shipping that infrastructure without authenticating the embedder ships both questions. The defender selects only which one they intend to ask. They do not select which one the technology is capable of answering. Resilience serves whoever embedded. Decide whether that party is you before deployment, because the mark will not decide it on your behalf.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.