Markpainting: Adversarial Machine Learning meets Inpainting
David Khachaturov, Ilia Shumailov, Yiren Zhao, Nicolas Papernot, Ross J. Anderson
Abstract
Inpainting is a learned interpolation technique that is based on generative modeling and used to populate masked or missing pieces in an image; it has wide applications in picture editing and retouching. Recently, inpainting started being used for watermark removal, raising concerns. In this paper we study how to manipulate it using our markpainting technique. First, we show how an image owner with access to an inpainting model can augment their image in such a way that any attempt to edit it using that model will add arbitrary visible information. We find that we can target multiple different models simultaneously with our technique. This can be designed to reconstitute a watermark if the editor had been trying to remove it. Second, we show that our markpainting technique is transferable to models that have different architectures or were trained on different datasets, so watermarks created using it are difficult for adversaries to remove. Markpainting is novel and can be used as a manipulation alarm that becomes visible in the event of inpainting. Source code is available at: https://github. com/iliaishacked/markpainting .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dab4ad8d-7cc9-47c3-96f1-4db31f86b839Cited by top-tier papers2
- Are Deepfakes Concerning? Analyzing Conversations of Deepfakes on Reddit and Exploring Societal ImplicationsDilrukshi Gamage, Piyush Ghasiya, Vamshi Krishna Bonagiri, Mark E. Whiting et al.CHI 2022 · 77 citations
- DRAW: Defending Camera-shooted RAW against Image ManipulationXiaoxiao Hu, Qichao Ying, Zhenxing Qian, Sheng Li et al.ICCV 2023 · 12 citations
Builds on2
Related papers
- EARG-Net: Edge-Aware Reconstruction-Guided Network for Image Manipulation Detection and LocalizationYanpu Yu, Zhaoxin Shi, Hanqing Zhao, Tianyi Wei et al.AAAI 2026 · 1 citation
- Invisible Image Watermarks Are Provably Removable Using Generative AIXuandong Zhao, Kexun Zhang, Zihao Su, Saastha Vasan et al.NeurIPS 2024 · 209 citations
- Localization of Deep Inpainting Using High-Pass Fully Convolutional NetworkHaodong Li, Jiwu HuangICCV 2019 · 157 citations
- BitMark: Watermarking Bitwise Autoregressive Image Generative ModelsLouis Kerner, Michel Meintz, Bihe Zhao, Franziska Boenisch et al.NeurIPS 2025 · 6 citations
- Transferable Black-Box One-Shot Forging of Watermarks via Image Preference ModelsTomás Soucek, Sylvestre-Alvise Rebuffi, Pierre Fernandez, Nikola Jovanovic et al.NeurIPS 2025 · 11 citations
