Removal Attack and Defense on AI-generated Content Latent-based Watermarking
De Zhang Lee, Han Fang, Hanyi Wang, Ee-Chien Chang
Abstract
Digital watermarks can be embedded into AI-generated content (AIGC) by initializing the generation process with starting points sampled from a secret distribution. When combined with pseudorandom error-correcting codes, such watermarked outputs can remain indistinguishable from unwatermarked objects, while maintaining robustness under whitenoise. In this paper, we go beyond indistinguishability and investigate security under removal attacks. We demonstrate that indistinguishability alone does not necessarily guarantee resistance to adversarial removal. Specifically, we propose a novel attack that exploits boundary information leaked by the locations of watermarked objects. This attack significantly reduces the distortion required to remove watermarks—by up to a factor of 15 × compared to a baseline whitenoise attack under certain settings. To mitigate such attacks, we introduce a defense mechanism that applies a secret transformation to hide the boundary, and prove that the secret transformation effectively rendering any attacker's perturbations equivalent to those of a naïve whitenoise adversary. Our empirical evaluations, conducted on multiple versions of Stable Diffusion, validate the effectiveness of both the attack and the proposed defense, highlighting the importance of addressing boundary leakage in latent-based watermarking schemes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 02fb7d1b-fe52-46b6-83a8-10cb41a1ec39Cited by top-tier papers4
- MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent ManipulationJie Cao, Qi Li, Zelin Zhang, Xiaodong Wu et al.USENIX Security 2026 · 1 citation
- Proof-of-Authorship for Diffusion-based AI Generated ContentDe Zhang Lee, Han Fang, Ee-Chien ChangCCS 2026
- WRATH: Turning Watermark Robustness Against Itself via a Watermark-Agnostic Black-Box Invalidation AttackNan Jiang, Juan Hu, Bangjie Sun, Terence Sim et al.S&P 2026
- Rethinking Forgery Attacks on Semantic Watermarks in Black-Box Settings: A Geometric Distortion PerspectiveCHENG-YI LEE, Yichi Zhang, Yuchen Yang, Chun-Shien Lu et al.ICML 2026
Builds on16
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- SDXL: Improving Latent Diffusion Models for High-Resolution Image SynthesisDustin Podell, Zion English, Kyle Lacey, Andreas Blattmann et al.ICLR 2024 · 4,569 citations
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- The Stable Signature: Rooting Watermarks in Latent Diffusion ModelsPierre Fernandez, Guillaume Couairon, Hervé Jégou, Matthijs Douze et al.ICCV 2023 · 370 citations
Related papers
- Invisible Image Watermarks Are Provably Removable Using Generative AIXuandong Zhao, Kexun Zhang, Zihao Su, Saastha Vasan et al.NeurIPS 2024 · 209 citations
- An Undetectable Watermark for Generative Image ModelsSam Gunn, Xuandong Zhao, Dawn SongICLR 2025
- RAVEN: Erasing Invisible Watermarks via Novel View SynthesisFahad Shamshad, Nils Lukas, Karthik NandakumarCVPR 2026 · 3 citations
- Evading Watermark based Detection of AI-Generated ContentZhengyuan Jiang, Jinghuai Zhang, Neil Zhenqiang GongCCS 2023 · 46 citations
- Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic DeflectionQingyu Liu, Yitao Zhang, Zhongjie Ba, Chao Shuai et al.ICLR 2026 · 2 citations
