Pith. sign in

REVIEW 3 cited by

Invisible Image Watermarks Are Provably Removable Using Generative AI

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.01953 v3 pith:JEOUGZIK submitted 2023-06-02 cs.CR cs.AIcs.CV

classification cs.CRcs.AIcs.CV
keywords watermarksimageinvisibleattackmodelsattacksexistinggenerative
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Invisible watermarks safeguard images' copyrights by embedding hidden messages only detectable by owners. They also prevent people from misusing images, especially those generated by AI models. We propose a family of regeneration attacks to remove these invisible watermarks. The proposed attack method first adds random noise to an image to destroy the watermark and then reconstructs the image. This approach is flexible and can be instantiated with many existing image-denoising algorithms and pre-trained generative models such as diffusion models. Through formal proofs and extensive empirical evaluations, we demonstrate that pixel-level invisible watermarks are vulnerable to this regeneration attack. Our results reveal that, across four different pixel-level watermarking schemes, the proposed method consistently achieves superior performance compared to existing attack techniques, with lower detection rates and higher image quality. However, watermarks that keep the image semantically similar can be an alternative defense against our attacks. Our finding underscores the need for a shift in research/industry emphasis from invisible watermarks to semantic-preserving watermarks. Code is available at https://github.com/XuandongZhao/WatermarkAttacker

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Robust Watermarks Leak: Channel-Aware Feature Extraction Enables Adversarial Watermark Manipulation

    cs.CV 2025-02 conditional novelty 7.0 of 10

    Robust watermarks leak detectable patterns into neural network feature channels, enabling single-image, no-box watermark removal and forgery.

  2. Peccavi: Visual Paraphrase Attack Safe and Distortion Free Image Watermarking Technique for AI-Generated Images

    cs.CV 2025-06 reject novelty 5.0 of 10

    PECCAVI embeds watermarks in paraphrase-stable image regions and reports improved watermark retention after visual paraphrase attacks, but overclaims distortion-free performance and ships no code.

  3. KGMark: A Diffusion Watermark for Knowledge Graphs

    cs.CR 2025-05 reject novelty 5.0 of 10

    KGMark embeds a detectable watermark into knowledge graph embeddings via diffusion inversion, with graph alignment and a learned mask, and reports high AUC under editing attacks.

Pith tools