Here are a few attacks against which we have tested our watermarking scheme:  
Fandisk (12,946 faces)  Watermarked  Smoothed  +noise, smoothed, simplified, cropped, 2nd watermark 
Head (13,408 faces)    0.45% noise  Second watermark
Dragon (30,000 faces)   1/2 #faces Similarity transform
Bunny (69,473 faces)   1/8 #faces Cropped