Residual Transferability in Neural Image Watermarking Researchers formalized a vulnerability in neural image watermarking whereby watermark-bearing residuals extracted from released images can be transferred to unrelated content to forge watermarks, though the source does not name the authors or institution. The work addresses why these residuals remain transferable, a question prior demonstrations of the attack left poorly understood. Neural image watermarks can be forged by extracting watermark-bearing residuals from released images and transferring them to unrelated content. While prior work has demonstrated this vulnerability, what makes these residuals transferable remains poorly understood. We formalize this vulnerability wi