{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:JEOUGZIKF5MY47XJCG7AAP3PC6","short_pith_number":"pith:JEOUGZIK","schema_version":"1.0","canonical_sha256":"491d43650a2f598e7ee911be003f6f178684f1b609dadfa0dad1da40aa3ab9e6","source":{"kind":"arxiv","id":"2306.01953","version":3},"attestation_state":"computed","paper":{"title":"Invisible Image Watermarks Are Provably Removable Using Generative AI","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Christopher Kruegel, Giovanni Vigna, Ilya Grishchenko, Kexun Zhang, Lei Li, Saastha Vasan, Xuandong Zhao, Yu-Xiang Wang, Zihao Su","submitted_at":"2023-06-02T23:29:28Z","abstract_excerpt":"Invisible watermarks safeguard images' copyrights by embedding hidden messages only detectable by owners. They also prevent people from misusing images, especially those generated by AI models. We propose a family of regeneration attacks to remove these invisible watermarks. The proposed attack method first adds random noise to an image to destroy the watermark and then reconstructs the image. This approach is flexible and can be instantiated with many existing image-denoising algorithms and pre-trained generative models such as diffusion models. Through formal proofs and extensive empirical e"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2306.01953","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-06-02T23:29:28Z","cross_cats_sorted":["cs.AI","cs.CV"],"title_canon_sha256":"3d0f00ce768b36c57f9c7b14dccd8dc2678401b4fd0547632e27d82980ed6776","abstract_canon_sha256":"7234d9c7fdf001c05562fd4f2520290e2120867e8c00eb345396223c5a619781"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:29:13.097419Z","signature_b64":"qqH6/D4JCexUYXO1/N+HMU9i8Rw/DVg54a5EyYhwd587dwLVZl+ChmLGoV3c55rTxzysvjGlPVkiNGNqqsR/Ag==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"491d43650a2f598e7ee911be003f6f178684f1b609dadfa0dad1da40aa3ab9e6","last_reissued_at":"2026-07-05T09:29:13.096895Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:29:13.096895Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Invisible Image Watermarks Are Provably Removable Using Generative AI","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Christopher Kruegel, Giovanni Vigna, Ilya Grishchenko, Kexun Zhang, Lei Li, Saastha Vasan, Xuandong Zhao, Yu-Xiang Wang, Zihao Su","submitted_at":"2023-06-02T23:29:28Z","abstract_excerpt":"Invisible watermarks safeguard images' copyrights by embedding hidden messages only detectable by owners. They also prevent people from misusing images, especially those generated by AI models. We propose a family of regeneration attacks to remove these invisible watermarks. The proposed attack method first adds random noise to an image to destroy the watermark and then reconstructs the image. This approach is flexible and can be instantiated with many existing image-denoising algorithms and pre-trained generative models such as diffusion models. Through formal proofs and extensive empirical e"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2306.01953","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2306.01953/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2306.01953","created_at":"2026-07-05T09:29:13.096954+00:00"},{"alias_kind":"arxiv_version","alias_value":"2306.01953v3","created_at":"2026-07-05T09:29:13.096954+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2306.01953","created_at":"2026-07-05T09:29:13.096954+00:00"},{"alias_kind":"pith_short_12","alias_value":"JEOUGZIKF5MY","created_at":"2026-07-05T09:29:13.096954+00:00"},{"alias_kind":"pith_short_16","alias_value":"JEOUGZIKF5MY47XJ","created_at":"2026-07-05T09:29:13.096954+00:00"},{"alias_kind":"pith_short_8","alias_value":"JEOUGZIK","created_at":"2026-07-05T09:29:13.096954+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.22689","citing_title":"Is This AI? Longitudinal Analysis of Strategies Used for AI Detection on Two Subreddits","ref_index":63,"is_internal_anchor":false},{"citing_arxiv_id":"2606.22689","citing_title":"Is This AI? Longitudinal Analysis of Strategies Used for AI Detection on Two Subreddits","ref_index":63,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6","json":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6.json","graph_json":"https://pith.science/api/pith-number/JEOUGZIKF5MY47XJCG7AAP3PC6/graph.json","events_json":"https://pith.science/api/pith-number/JEOUGZIKF5MY47XJCG7AAP3PC6/events.json","paper":"https://pith.science/paper/JEOUGZIK"},"agent_actions":{"view_html":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6","download_json":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6.json","view_paper":"https://pith.science/paper/JEOUGZIK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2306.01953&json=true","fetch_graph":"https://pith.science/api/pith-number/JEOUGZIKF5MY47XJCG7AAP3PC6/graph.json","fetch_events":"https://pith.science/api/pith-number/JEOUGZIKF5MY47XJCG7AAP3PC6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6/action/storage_attestation","attest_author":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6/action/author_attestation","sign_citation":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6/action/citation_signature","submit_replication":"https://pith.science/pith/JEOUGZIKF5MY47XJCG7AAP3PC6/action/replication_record"}},"created_at":"2026-07-05T09:29:13.096954+00:00","updated_at":"2026-07-05T09:29:13.096954+00:00"}