Removing the Watermark Is Not Enough: Forensic Stealth in Generative-AI Watermark Removal
cs.CR
Submitted: 2026-05-09
Updated: 2026-08-28
Comments: 22 pages, including appendices. v2: substantially revised and expanded, with updated empirical evaluation and theoretical analysis
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- SEAL: Semantic Aware Image Watermarking
- The Coding Limits of Robust Watermarking for Generative Models
- SynthID-Image: Image watermarking at internet scale
- An Undetectable Watermark for Generative Image Models
- ROBIN: Robust and Invisible Watermarks for Diffusion Models with Adversarial Optimization
- UnMarker: A Universal Attack on Defensive Image Watermarking
- Removal Attack and Defense on AI-generated Content Latent-based Watermarking
- Image Watermarks are Removable Using Controllable Regeneration from Clean Noise
- Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances
- Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models
- Denoising Diffusion Implicit Models
- Human Preference Score v2: A Solid Benchmark for Evaluating Human Preferences of Text-to-Image Synthesis
- RAW: A Robust and Agile Plug-and-Play Watermark Framework for AI-Generated Images with Provable Guarantees
- InvisMark: Invisible and Robust Watermarking for AI-generated Image Provenance
- Attack-Resilient Image Watermarking Using Stable Diffusion
- Invisible Image Watermarks Are Provably Removable Using Generative AI
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs