{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:EA7AEY4ORJHFBXYLT6JS4KA4LN","short_pith_number":"pith:EA7AEY4O","schema_version":"1.0","canonical_sha256":"203e02638e8a4e50df0b9f932e281c5b6edaf03bfd44e111b553447982fca25e","source":{"kind":"arxiv","id":"2407.04086","version":1},"attestation_state":"computed","paper":{"title":"Certifiably Robust Image Watermark","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Jinyuan Jia, Moyang Guo, Neil Zhenqiang Gong, Yuepeng Hu, Zhengyuan Jiang","submitted_at":"2024-07-04T17:56:04Z","abstract_excerpt":"Generative AI raises many societal concerns such as boosting disinformation and propaganda campaigns. Watermarking AI-generated content is a key technology to address these concerns and has been widely deployed in industry. However, watermarking is vulnerable to removal attacks and forgery attacks. In this work, we propose the first image watermarks with certified robustness guarantees against removal and forgery attacks. Our method leverages randomized smoothing, a popular technique to build certifiably robust classifiers and regression models. Our major technical contributions include extend"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.04086","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-07-04T17:56:04Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"017550a496f3fe638b00e33a9c2734ee0ad0d0a3644e4390531fb94a00c9f930","abstract_canon_sha256":"36afa558ef45f21435a2ff631cd59240422977d0239f897873fd7df1665189c8"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:40:28.460979Z","signature_b64":"91NMerToE14Nhy7y1E9pkUaQPDLU9A7OqloCfxm2mnqOqk0wPFmi25o4J1QQMbtrgr6DMxc7c4zqBZ+sKq2VCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"203e02638e8a4e50df0b9f932e281c5b6edaf03bfd44e111b553447982fca25e","last_reissued_at":"2026-07-05T08:40:28.460512Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:40:28.460512Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Certifiably Robust Image Watermark","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Jinyuan Jia, Moyang Guo, Neil Zhenqiang Gong, Yuepeng Hu, Zhengyuan Jiang","submitted_at":"2024-07-04T17:56:04Z","abstract_excerpt":"Generative AI raises many societal concerns such as boosting disinformation and propaganda campaigns. Watermarking AI-generated content is a key technology to address these concerns and has been widely deployed in industry. However, watermarking is vulnerable to removal attacks and forgery attacks. In this work, we propose the first image watermarks with certified robustness guarantees against removal and forgery attacks. Our method leverages randomized smoothing, a popular technique to build certifiably robust classifiers and regression models. Our major technical contributions include extend"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.04086","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.04086/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.04086","created_at":"2026-07-05T08:40:28.460569+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.04086v1","created_at":"2026-07-05T08:40:28.460569+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.04086","created_at":"2026-07-05T08:40:28.460569+00:00"},{"alias_kind":"pith_short_12","alias_value":"EA7AEY4ORJHF","created_at":"2026-07-05T08:40:28.460569+00:00"},{"alias_kind":"pith_short_16","alias_value":"EA7AEY4ORJHFBXYL","created_at":"2026-07-05T08:40:28.460569+00:00"},{"alias_kind":"pith_short_8","alias_value":"EA7AEY4O","created_at":"2026-07-05T08:40:28.460569+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2412.02576","citing_title":"The Efficacy of Transfer-based No-box Attacks on Image Watermarking: A Pragmatic Analysis","ref_index":26,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN","json":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN.json","graph_json":"https://pith.science/api/pith-number/EA7AEY4ORJHFBXYLT6JS4KA4LN/graph.json","events_json":"https://pith.science/api/pith-number/EA7AEY4ORJHFBXYLT6JS4KA4LN/events.json","paper":"https://pith.science/paper/EA7AEY4O"},"agent_actions":{"view_html":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN","download_json":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN.json","view_paper":"https://pith.science/paper/EA7AEY4O","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.04086&json=true","fetch_graph":"https://pith.science/api/pith-number/EA7AEY4ORJHFBXYLT6JS4KA4LN/graph.json","fetch_events":"https://pith.science/api/pith-number/EA7AEY4ORJHFBXYLT6JS4KA4LN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN/action/storage_attestation","attest_author":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN/action/author_attestation","sign_citation":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN/action/citation_signature","submit_replication":"https://pith.science/pith/EA7AEY4ORJHFBXYLT6JS4KA4LN/action/replication_record"}},"created_at":"2026-07-05T08:40:28.460569+00:00","updated_at":"2026-07-05T08:40:28.460569+00:00"}