{"id":"https://openalex.org/W7130417776","doi":"https://doi.org/10.48550/arxiv.2602.15364","title":"MarkSweep: A No-box Removal Attack on AI-Generated Image Watermarking via Noise Intensification and Frequency-aware Denoising","display_name":"MarkSweep: A No-box Removal Attack on AI-Generated Image Watermarking via Noise Intensification and Frequency-aware Denoising","publication_year":2026,"publication_date":"2026-02-17","ids":{"openalex":"https://openalex.org/W7130417776","doi":"https://doi.org/10.48550/arxiv.2602.15364"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2602.15364","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.15364","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2602.15364","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5126335275","display_name":"Jie Cao","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Cao, Jie","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126296836","display_name":"Zelin Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Zelin","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126294184","display_name":"Qi Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Qi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5120318443","display_name":"Jianbing Ni","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ni, Jianbing","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5126335275"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.3474999964237213,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.3474999964237213,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.2639999985694885,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.12200000137090683,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.9205999970436096},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.845300018787384},{"id":"https://openalex.org/keywords/noise-reduction","display_name":"Noise reduction","score":0.607699990272522},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.6025000214576721},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.513700008392334},{"id":"https://openalex.org/keywords/gaussian-noise","display_name":"Gaussian noise","score":0.4388999938964844},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.4104999899864197},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.37070000171661377},{"id":"https://openalex.org/keywords/image-quality","display_name":"Image quality","score":0.3264000117778778}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.9205999970436096},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.845300018787384},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.7149999737739563},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.6733999848365784},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6177999973297119},{"id":"https://openalex.org/C163294075","wikidata":"https://www.wikidata.org/wiki/Q581861","display_name":"Noise reduction","level":2,"score":0.607699990272522},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.6025000214576721},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.513700008392334},{"id":"https://openalex.org/C4199805","wikidata":"https://www.wikidata.org/wiki/Q2725903","display_name":"Gaussian noise","level":2,"score":0.4388999938964844},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.4104999899864197},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.37070000171661377},{"id":"https://openalex.org/C55020928","wikidata":"https://www.wikidata.org/wiki/Q3813865","display_name":"Image quality","level":3,"score":0.3264000117778778},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.32190001010894775},{"id":"https://openalex.org/C160086991","wikidata":"https://www.wikidata.org/wiki/Q5939193","display_name":"Human visual system model","level":3,"score":0.3190000057220459},{"id":"https://openalex.org/C111335779","wikidata":"https://www.wikidata.org/wiki/Q3454686","display_name":"Reduction (mathematics)","level":2,"score":0.3174000084400177},{"id":"https://openalex.org/C169334058","wikidata":"https://www.wikidata.org/wiki/Q353292","display_name":"Additive white Gaussian noise","level":3,"score":0.2976999878883362},{"id":"https://openalex.org/C106430172","wikidata":"https://www.wikidata.org/wiki/Q6002272","display_name":"Image restoration","level":4,"score":0.28130000829696655},{"id":"https://openalex.org/C55352655","wikidata":"https://www.wikidata.org/wiki/Q304247","display_name":"Median filter","level":4,"score":0.275299996137619},{"id":"https://openalex.org/C2778328480","wikidata":"https://www.wikidata.org/wiki/Q1639904","display_name":"Hybrid image","level":3,"score":0.2700999975204468},{"id":"https://openalex.org/C9417928","wikidata":"https://www.wikidata.org/wiki/Q1070689","display_name":"Image processing","level":3,"score":0.26649999618530273},{"id":"https://openalex.org/C36464697","wikidata":"https://www.wikidata.org/wiki/Q451553","display_name":"Visualization","level":2,"score":0.2635999917984009},{"id":"https://openalex.org/C163716315","wikidata":"https://www.wikidata.org/wiki/Q901177","display_name":"Gaussian","level":2,"score":0.2628999948501587},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.259799987077713},{"id":"https://openalex.org/C2779530757","wikidata":"https://www.wikidata.org/wiki/Q1207505","display_name":"Quality (philosophy)","level":2,"score":0.25780001282691956},{"id":"https://openalex.org/C69744172","wikidata":"https://www.wikidata.org/wiki/Q860822","display_name":"Image fusion","level":3,"score":0.25600001215934753},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.25369998812675476}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2602.15364","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.15364","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2602.15364","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.15364","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"AI":[0],"watermarking":[1,115],"embeds":[2],"invisible":[3,94],"signals":[4],"within":[5],"images":[6,35,57],"to":[7,79,99,117],"provide":[8],"provenance":[9],"information":[10],"and":[11,52,74,83,89,112],"identify":[12],"content":[13],"as":[14],"AI-generated.":[15],"In":[16],"this":[17],"paper,":[18],"we":[19],"introduce":[20],"MarkSweep,":[21,100],"a":[22,60],"novel":[23],"watermark":[24,43,85],"removal":[25],"attack":[26],"that":[27,93],"effectively":[28,102],"erases":[29],"the":[30,69,75,107],"embedded":[31,104],"watermarks":[32,95],"from":[33],"AI-generated":[34,125],"without":[36],"degrading":[37],"visual":[38],"quality.":[39],"MarkSweep":[40],"first":[41],"amplifies":[42],"noise":[44,82],"in":[45],"high-frequency":[46],"regions":[47],"via":[48],"edge-aware":[49],"Gaussian":[50],"perturbations":[51],"injects":[53],"it":[54],"into":[55],"clean":[56],"for":[58],"training":[59],"denoising":[61],"network.":[62],"This":[63],"network":[64],"then":[65],"integrates":[66],"two":[67],"modules,":[68],"learnable":[70],"frequency":[71],"decomposition":[72],"module":[73],"frequency-aware":[76],"fusion":[77],"module,":[78],"suppress":[80],"amplified":[81],"eliminate":[84],"traces.":[86],"Theoretical":[87],"analysis":[88],"extensive":[90],"experiments":[91],"demonstrate":[92],"are":[96],"highly":[97],"vulnerable":[98],"which":[101],"removes":[103],"watermarks,":[105],"reducing":[106],"bit":[108],"accuracy":[109],"of":[110,124],"HiDDeN":[111],"Stable":[113],"Signature":[114],"schemes":[116],"below":[118],"67%,":[119],"while":[120],"preserving":[121],"perceptual":[122],"quality":[123],"images.":[126]},"counts_by_year":[],"updated_date":"2026-02-19T06:31:58.851227","created_date":"2026-02-19T00:00:00"}
