Given rendering tasks each contains basically a watermarked scene G^G^ and some range of frames required to be rendered, the goal of an attacker, namely a malicious worker (or in general a group of maliciously colluding workers), is to generate rendered frames that pass the noise verification, with computational costs significantly lower than doing render this range by some conventional rendering software.