v1.2.0: Backfire
v1.2.0: Backfire
This release introduces Backfire, an imperceptible, keyed image watermark that AI provenance-stripping attacks amplify instead of remove, plus Mellin, its audio-side sibling for keyed per-copy serials and traitor tracing. The provcheck core stays Apache-2.0 and unchanged in its guarantees.
Backfire
Diffusion "regeneration" attacks provably remove ordinary invisible watermarks by snapping an image back onto the natural-image manifold (Zhao et al., NeurIPS 2024), and open tools like watermarks-remover make the attack practical. We are glad that work is in the open, and we read it as a technical challenge for our context: Backfire optimizes the mark to be a fixed point of that very process, so running the stripper makes the keyed identifier read back stronger. The attack backfires.
Measured at 512 px on 24 diverse COCO photos against a real 50-step diffusion purifier: the keyed id survives 24 of 24, reads stronger than before the attack on 21 of 24, and generalizes to a purifier it was never tuned on (24 of 24). Zero false positives across 1,000 unmarked images. 34 dB PSNR. The read side is numpy-only, and backfire/repro/ reproduces every claim, including the wrong-key control.
One attack does strip it: an aggressive band-notch. We could not make the mark survive that, and we say so. But the notch carves a spectral hole natural images lack, so read runs a tamper tripwire; across 300 clean images and 81 notch configurations, no notch both strips the mark and evades detection. Remove the mark or stay quiet, not both. Full limits and our own red-team dead ends: backfire/LIMITS.md.
Mellin
provcheck-mellin embeds and reads a keyed 64-bit per-copy serial in audio, transcode-tolerant and time-stretch-invariant, so a leaked file identifies which copy it came from. For leaks blended from several copies, a Tardos collusion-resistant code still identifies at least one source, with a bounded false-positive guarantee that refuses thin evidence rather than implicate an uninvolved copy. Honest survival table in crates/provcheck-mellin/ROBUSTNESS.md.
Integration
provcheck --backfire-readandprovcheck --mellin-readon the CLI; a Keyed marks tab in the desktop app.- Both tools are standalone processes the Apache-2.0 binary shells out to, never links.
- The Windows installer bundles both readers (no Python or setup needed) plus signed sample files to try immediately.
- The Watermark tab gains a per-family detector selector.
Licensing
Backfire and Mellin are source-available under BUSL-1.1: free for non-commercial use, paid commercial licensing via licensing@creativemayhem.com. Every released version automatically converts to AGPL-3.0-or-later four years after its first public distribution. The provcheck core remains Apache-2.0.
Verify your download
Every asset ships with a .sha256 sidecar. Windows binaries are Authenticode-signed by Creative Mayhem UG. Linux and macOS artifacts carry detached minisign signatures; the public key:
RWT7q3OTt9C1eiqU5PdBjTcfEio7kjQ9/GxBU44mforTQkjx85t3lHvc
Full change list in the README changelog row for v1.2.0.