pith. sign in
Pith Number

pith:E5AEMJFC

pith:2026:E5AEMJFC33MZI6E5M7LYBWMMLC
not attested not anchored not stored refs resolved

Watermarks Attack Watermarks: Re-Watermarking as a Generic Removal Strategy

Benjamin I. P. Rubinstein, Maria Bulychev, Neil G. Marchant

Re-watermarking an already watermarked image reliably suppresses the original signal.

arxiv:2605.16796 v1 · 2026-05-16 · cs.CR · cs.CV

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{E5AEMJFC33MZI6E5M7LYBWMMLC}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

simply re-watermarking an already watermarked image reliably suppresses the original signal, without requiring gradients, surrogate models, or detection keys

C2weakest assumption

The core analogy holds that any imperceptible change intended to trigger a detector (including a new watermark) will interfere with an existing watermark's detection, independent of the specific schemes used.

C3one line summary

Re-watermarking reliably removes existing watermarks across 96 dataset-victim-attack combinations and pairs with a classifier achieving 0.878-0.953 accuracy, cutting bit accuracy by 25-48%.

References

55 extracted · 55 resolved · 0 Pith anchors

[1] B. An, M. Ding, T. Rabbani, A. Agrawal, Y . Xu, C. Deng, S. Zhu, A. Mohamed, Y . Wen, T. Goldstein, and F. Huang. W A VES: Benchmarking the robustness of image watermarks. InForty-first International 2024
[2] J. Ballé, D. Minnen, S. Singh, S. J. Hwang, and N. Johnston. Variational image compression with a scale hyperprior. InInternational Conference on Learning Representations, 2018 2018
[3] Flux.2: Next generation image generation 2025
[4] T. Bui, S. Agarwal, and J. Collomosse. TrustMark: Robust watermarking and watermark removal for arbitrary resolution images. InProceedings of the IEEE/CVF International Conference on Computer Vision ( 2025
[5] T. Bui, S. Agarwal, N. Yu, and J. Collomosse. RoSteALS: Robust steganography using autoencoder latent space. In2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pa 2023

Formal links

2 machine-checked theorem links

Receipt and verification
First computed 2026-05-20T00:03:22.541875Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

27404624a2ded994789d67d780d98c58aaf2d326673a15b760734a44714d476b

Aliases

arxiv: 2605.16796 · arxiv_version: 2605.16796v1 · doi: 10.48550/arxiv.2605.16796 · pith_short_12: E5AEMJFC33MZ · pith_short_16: E5AEMJFC33MZI6E5 · pith_short_8: E5AEMJFC
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/E5AEMJFC33MZI6E5M7LYBWMMLC \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 27404624a2ded994789d67d780d98c58aaf2d326673a15b760734a44714d476b
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "84d3deab44523b9517a30db0b3de5414ff801bd540daf3769c7f2d7b7f92ae72",
    "cross_cats_sorted": [
      "cs.CV"
    ],
    "license": "http://creativecommons.org/licenses/by/4.0/",
    "primary_cat": "cs.CR",
    "submitted_at": "2026-05-16T03:57:37Z",
    "title_canon_sha256": "72bfd26f947136cc241a909ab3fa2610a49d33c7b13a7e542748fda8b9375693"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2605.16796",
    "kind": "arxiv",
    "version": 1
  }
}