SearcharxivSearch

arXiv · 2605.09203

Removing the Watermark Is Not Enough: Forensic Stealth in Generative-AI Watermark Removal

Abstract

The literature on watermark removal has largely asked whether an attacker can make the watermark verifier fail while preserving the appearance of the image. This is a useful test, but it does not capture the purpose of removal in applications where watermarks support provenance. In such settings, the attacker wants the image to pass as ordinary content. If the removal process leaves a recognizable statistical trace, the watermark may have disappeared, but deniability has not been restored. We call this missing requirement forensic stealth. We evaluate six recent attacks spanning four different removal strategies and find that all leave strong forensic traces. At a 1% false-positive target, attack-specific detectors identify at least 99% of the removal outputs. In a separate image-by-image assessment of five attacks, only one of 750 outputs removes the watermark, remains within the fidelity budget, and evades forensic detection. The consistency of this result across different mechanisms shows that current evaluation practice overlooks a central part of the security problem. We also ask whether forensic stealth is possible in principle. Under explicit idealized assumptions, we show that exact forensic stealth is possible when a remover preserves source content and resamples the remaining detail from the corresponding clean distribution. In this model, the resulting outputs exactly match the clean-image distribution while remaining within the distortion budget. This shows that removal traces are not inevitable and places the practical difficulty in generating source-appropriate clean variation without damaging the image. We argue that forensic stealth should become part of the standard by which watermark removal is judged.

Explore related subjects

Keep this discovery

BibTeXRIS

Yevin Nikhel Goonatilake, Giuseppe Ateniese. 2026-08-28. Removing the Watermark Is Not Enough: Forensic Stealth in Generative-AI Watermark Removal. https://arxiv.org/abs/2605.09203

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related discoveries

The Impact of Magma: A Ground-Truth Fuzzing Benchmark

Magma is an open-source and ground-truth fuzzing benchmark that enables uniform fuzzer evaluation and comparison. Magma was originally released with a research paper published at ACM SIGMETRICS 2021. This short paper explains the motivation, the design, and the impact of Magma, with a description of extensions to the original benchmark.

cs.CR

Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox

We present how Hyper-V sockets can be used as a real-time communication channel for a malware analysis sandbox. We show that, compared to WinSock TCP sockets, Hyper-V sockets are not subject to TCP/IP-layer blocking and are not enumerated by common TCP connection listing tools. We compare the throughput of the two communication channels as a function of buffer size.

cs.CR

High-Dimensional Deterministic Secure Quantum Communication with Reed-Solomon Erasure Coding

Deterministic Secure Quantum Communication (DSQC) is a quantum cryptographic technique engineered to transfer a message through a quantum channel, requiring an auxiliary classical channel for eavesdropping verification and decoding, but without prior key distribution. This article presents a theoretical high-dimensional prepare and measure DSQC protocol using the Reed-Solomon erasure coding to ensure data resilience to noise. This protocol offers the following benefits: it eliminates the need for quantum memory or entanglement, it can be built with commercially available technology, and its higher capacity improves the overall transmission rate.

quant-ph