This paper examines the role of attacker’s memory in Quantization Index Modulation (QIM) watermarking systems. First we derive the attacker’s noise distribution that maximizes probability of error of the detector. Next, we derive QIM code parameters that are minmax optimal. The minmax optimal embedding strategy involves randomized lattice rotations, and the corresponding worst noise distributions are isotropic.