arXiv ScienceSearch

arXiv · 2605.09203

Removing the Watermark Is Not Enough: Forensic Stealth in Generative-AI Watermark Removal

Abstract

The literature on watermark removal has largely asked whether an attacker can make the watermark verifier fail while preserving the appearance of the image. This is a useful test, but it does not capture the purpose of removal in applications where watermarks support provenance. In such settings, the attacker wants the image to pass as ordinary content. If the removal process leaves a recognizable statistical trace, the watermark may have disappeared, but deniability has not been restored. We call this missing requirement forensic stealth. We evaluate six recent attacks spanning four different removal strategies and find that all leave strong forensic traces. At a 1% false-positive target, attack-specific detectors identify at least 99% of the removal outputs. In a separate image-by-image assessment of five attacks, only one of 750 outputs removes the watermark, remains within the fidelity budget, and evades forensic detection. The consistency of this result across different mechanisms shows that current evaluation practice overlooks a central part of the security problem. We also ask whether forensic stealth is possible in principle. Under explicit idealized assumptions, we show that exact forensic stealth is possible when a remover preserves source content and resamples the remaining detail from the corresponding clean distribution. In this model, the resulting outputs exactly match the clean-image distribution while remaining within the distortion budget. This shows that removal traces are not inevitable and places the practical difficulty in generating source-appropriate clean variation without damaging the image. We argue that forensic stealth should become part of the standard by which watermark removal is judged.

Explore related subjects

Keep this discovery

BibTeXRIS

Yevin Nikhel Goonatilake, Giuseppe Ateniese. 2026-08-28. Removing the Watermark Is Not Enough: Forensic Stealth in Generative-AI Watermark Removal. https://arxiv.org/abs/2605.09203

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

The Security Feature Location Problem

Software security must be realized through security features such as authentication and encryption, but which features does a system implement, and where? We present security feature location: the task of relating code locations to security features, enabling developers to understand security implementations and assess whether intended security properties are enforced.

cs.CR

The Impact of Magma: A Ground-Truth Fuzzing Benchmark

Magma is an open-source and ground-truth fuzzing benchmark that enables uniform fuzzer evaluation and comparison. Magma was originally released with a research paper published at ACM SIGMETRICS 2021. This short paper explains the motivation, the design, and the impact of Magma, with a description of extensions to the original benchmark.

cs.CR

Security Science (SecSci), Basic Concepts and Mathematical Foundations

This textbook compiles the lecture notes from security courses taught at Oxford in the 2000s, at Royal Holloway in the 2010s, and currently in Hawaii. The early chapters are suitable for a first course in security. The middle chapters have been used in advanced courses. Towards the end there are also some research problems.

cs.CR