upvote
Is it possible to implement a very good mechanism?
reply
Not that I can think of, but you could have two watermarks, one detectable with an open-source classifier and the other proprietary.

Most AI images are either extremely low-effort or not actively trying to be deceptive, so defenders can still catch the majority. If someone is actively circumventing they'll probably circumvent both, anyway.

reply