{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:SSFUBVW4DYJYHQM6OPPAEMFD7G","short_pith_number":"pith:SSFUBVW4","schema_version":"1.0","canonical_sha256":"948b40d6dc1e1383c19e73de0230a3f9b02e63e0039c745dacf217d7b80a5b0d","source":{"kind":"arxiv","id":"2412.03283","version":3},"attestation_state":"computed","paper":{"title":"Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Andreas M\\\"uller, Asja Fischer, Denis Lukovnikov, Erwin Quiring, Jonas Thietke","submitted_at":"2024-12-04T12:57:17Z","abstract_excerpt":"Integrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. S"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2412.03283","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-12-04T12:57:17Z","cross_cats_sorted":["cs.AI","cs.CV"],"title_canon_sha256":"bced60c0ddc06ecf6f4b952154d70366b81856bd92d0c65dfe7f2dbf8498508d","abstract_canon_sha256":"534d5e1b7301ea70541e51974fc62c7661f50e11d673507a11ac7683b42e9b5c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:17:38.557394Z","signature_b64":"HIoGqeMvR/NMwQeypRE8PxEuQYl6TzxbTbqsFRkX8asGZ3kpHiT0+IJ2ppOGv8r8IycHboq92IPJKTgGFwcxAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"948b40d6dc1e1383c19e73de0230a3f9b02e63e0039c745dacf217d7b80a5b0d","last_reissued_at":"2026-07-05T11:17:38.556875Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:17:38.556875Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Andreas M\\\"uller, Asja Fischer, Denis Lukovnikov, Erwin Quiring, Jonas Thietke","submitted_at":"2024-12-04T12:57:17Z","abstract_excerpt":"Integrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. S"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2412.03283","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2412.03283/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2412.03283","created_at":"2026-07-05T11:17:38.556933+00:00"},{"alias_kind":"arxiv_version","alias_value":"2412.03283v3","created_at":"2026-07-05T11:17:38.556933+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2412.03283","created_at":"2026-07-05T11:17:38.556933+00:00"},{"alias_kind":"pith_short_12","alias_value":"SSFUBVW4DYJY","created_at":"2026-07-05T11:17:38.556933+00:00"},{"alias_kind":"pith_short_16","alias_value":"SSFUBVW4DYJYHQM6","created_at":"2026-07-05T11:17:38.556933+00:00"},{"alias_kind":"pith_short_8","alias_value":"SSFUBVW4","created_at":"2026-07-05T11:17:38.556933+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.09203","citing_title":"Removing the Watermark Is Not Enough: Forensic Stealth in Generative-AI Watermark Removal","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2604.06662","citing_title":"Towards Robust Content Watermarking Against Removal and Forgery Attacks","ref_index":41,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G","json":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G.json","graph_json":"https://pith.science/api/pith-number/SSFUBVW4DYJYHQM6OPPAEMFD7G/graph.json","events_json":"https://pith.science/api/pith-number/SSFUBVW4DYJYHQM6OPPAEMFD7G/events.json","paper":"https://pith.science/paper/SSFUBVW4"},"agent_actions":{"view_html":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G","download_json":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G.json","view_paper":"https://pith.science/paper/SSFUBVW4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2412.03283&json=true","fetch_graph":"https://pith.science/api/pith-number/SSFUBVW4DYJYHQM6OPPAEMFD7G/graph.json","fetch_events":"https://pith.science/api/pith-number/SSFUBVW4DYJYHQM6OPPAEMFD7G/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G/action/timestamp_anchor","attest_storage":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G/action/storage_attestation","attest_author":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G/action/author_attestation","sign_citation":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G/action/citation_signature","submit_replication":"https://pith.science/pith/SSFUBVW4DYJYHQM6OPPAEMFD7G/action/replication_record"}},"created_at":"2026-07-05T11:17:38.556933+00:00","updated_at":"2026-07-05T11:17:38.556933+00:00"}