Low-Compute Watermark Removal via Dual-Domain Natural Projection
Pragati Meshram, Varun Chandrasekaran
Abstract
Effective removal of semantic watermarks requires balancing three competing objectives: high removal success, low perceptual distortion, and low computational cost. However, existing single-image attacks typically optimize only for the first two, achieving strong watermark suppression but relying on expensive, multi-step optimization that limits practical deployment. In this work, we show that this trade-off is fundamental: no current approach achieves all three properties simultaneously. We introduce DAWN, a lightweight, training-free attack that explicitly targets the low-cost regime while maintaining competitive removal performance. DAWN works by projecting a watermarked image onto natural-image priors in complementary frequency and semantic spaces, suppressing watermark signals that deviate from natural statistics, and then applying a decoupled perceptual-alignment step to restore visual consistency with minimal artifact. Across diverse pixel-, frequency-, and latent-space watermarking schemes, DAWN consistently reduces detectability while preserving structural and semantic fidelity, demonstrating that efficient, low-resource watermark removal is feasible with only modest perceptual degradation. Our code is available at https://anonymous.4open.science/r/DAWN-567A/.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3421a27f-a753-4258-8291-eeb9addcf47dBuilds on14
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Pick-a-Pic: An Open Dataset of User Preferences for Text-to-Image GenerationYuval Kirstain, Adam Polyak, Uriel Singer, Shahbuland Matiana et al.NeurIPS 2023 · 1,192 citations
- Invisible Image Watermarks Are Provably Removable Using Generative AIXuandong Zhao, Kexun Zhang, Zihao Su, Saastha Vasan et al.NeurIPS 2024 · 209 citations
- Attack-Resilient Image Watermarking Using Stable DiffusionLijun Zhang, Xiao Liu, Antoni Viros Martin, Cindy Xiong Bearfield et al.NeurIPS 2024 · 62 citations
Related papers
- RAVEN: Erasing Invisible Watermarks via Novel View SynthesisFahad Shamshad, Nils Lukas, Karthik NandakumarCVPR 2026 · 3 citations
- UnMarker: A Universal Attack on Defensive Image WatermarkingAndre Kassis, Urs HengartnerS&P 2025
- MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent ManipulationJie Cao, Qi Li, Zelin Zhang, Xiaodong Wu et al.USENIX Security 2026 · 1 citation
- SERUM: Simple, Efficient, Robust, and Unifying Marking for Diffusion-based Image GenerationJan Kociszewski, Hubert Jastrzebski, Tymoteusz Stepkowski, Filip Manijak et al.ICLR 2026
- LampMark: Proactive Deepfake Detection via Training-Free Landmark Perceptual WatermarksTianyi Wang, Mengxiao Huang, Harry Cheng, Xiao Zhang et al.ACM MM 2024 · 27 citations
