{"id":"https://openalex.org/W7131429406","doi":"https://doi.org/10.48550/arxiv.2602.20618","title":"RecoverMark: Robust Watermarking for Localization and Recovery of Manipulated Faces","display_name":"RecoverMark: Robust Watermarking for Localization and Recovery of Manipulated Faces","publication_year":2026,"publication_date":"2026-02-24","ids":{"openalex":"https://openalex.org/W7131429406","doi":"https://doi.org/10.48550/arxiv.2602.20618"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2602.20618","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5104279460","display_name":"Haonan An","orcid":"https://orcid.org/0009-0005-6874-0229"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"An, Haonan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126826732","display_name":"Xiaohui Ye","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ye, Xiaohui","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126787190","display_name":"Guang Hua","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hua, Guang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126797768","display_name":"Yihang Tao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tao, Yihang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013699453","display_name":"Hangcheng Cao","orcid":"https://orcid.org/0000-0002-0957-8576"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cao, Hangcheng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021444482","display_name":"Xiangyu Yu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yu, Xiangyu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5016290340","display_name":"Yuguang Fang","orcid":"https://orcid.org/0000-0002-1079-3871"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fang, Yuguang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8414999842643738,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8414999842643738,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.07180000096559525,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.03370000049471855,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.9061999917030334},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8781999945640564},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6744999885559082},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.661300003528595},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4717000126838684},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.4715999960899353},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4578999876976013},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.38989999890327454}],"concepts":[{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.9061999917030334},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8781999945640564},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7208999991416931},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6744999885559082},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.661300003528595},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6017000079154968},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.5879999995231628},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5157999992370605},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4717000126838684},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.4715999960899353},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4578999876976013},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.38989999890327454},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.3871000111103058},{"id":"https://openalex.org/C2777402240","wikidata":"https://www.wikidata.org/wiki/Q6783436","display_name":"Masking (illustration)","level":2,"score":0.375},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.3273000121116638},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.325300008058548},{"id":"https://openalex.org/C80191262","wikidata":"https://www.wikidata.org/wiki/Q5477668","display_name":"Fragility","level":2,"score":0.3125},{"id":"https://openalex.org/C27158222","wikidata":"https://www.wikidata.org/wiki/Q5532422","display_name":"Generalizability theory","level":2,"score":0.30889999866485596},{"id":"https://openalex.org/C126780896","wikidata":"https://www.wikidata.org/wiki/Q899871","display_name":"Distortion (music)","level":4,"score":0.30379998683929443},{"id":"https://openalex.org/C160086991","wikidata":"https://www.wikidata.org/wiki/Q5939193","display_name":"Human visual system model","level":3,"score":0.2687999904155731},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.26350000500679016}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2602.20618","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2602.20618","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.20618","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2602.20618","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"proliferation":[1],"of":[2,46],"AI-generated":[3],"content":[4,105,149,169],"has":[5],"facilitated":[6],"sophisticated":[7],"face":[8,168],"manipulation,":[9],"severely":[10],"undermining":[11],"visual":[12,133],"integrity":[13],"and":[14,81,107,174,198,218,233,236,241],"posing":[15],"unprecedented":[16],"challenges":[17],"to":[18,30,54,131,239],"intellectual":[19],"property.":[20],"In":[21],"response,":[22],"a":[23,71,97,119,183,199,205],"common":[24],"proactive":[25],"defense":[26],"leverages":[27],"fragile":[28,87,211],"watermarks":[29],"detect,":[31],"localize,":[32],"or":[33],"even":[34,135],"recover":[35],"manipulated":[36],"regions.":[37],"However,":[38],"these":[39,162],"methods":[40],"always":[41],"assume":[42],"an":[43,123],"adversary":[44,124],"unaware":[45],"the":[47,64,86,92,127,146,155,166,172,178,226],"embedded":[48],"watermark,":[49],"overlooking":[50],"their":[51],"inherent":[52],"vulnerability":[53],"watermark":[55,73,141,156,173,207],"removal":[56,142],"attacks.":[57,143],"Furthermore,":[58],"this":[59,152],"fragility":[60],"is":[61,114],"exacerbated":[62],"in":[63,151,209],"commonly":[65],"used":[66],"dual-watermark":[67],"strategy":[68],"that":[69,100,193],"adds":[70],"robust":[72,102,184,206],"for":[74,213],"image":[75,214,219],"ownership":[76,108],"verification,":[77],"where":[78],"mutual":[79],"interference":[80],"limited":[82],"embedding":[83,208],"capacity":[84],"reduce":[85],"watermark's":[88],"effectiveness.":[89],"To":[90],"address":[91],"gap,":[93],"we":[94,117],"propose":[95],"RecoverMark,":[96],"watermarking":[98],"framework":[99],"achieves":[101,204],"manipulation":[103,215],"localization,":[104,216],"recovery,":[106,217],"verification":[109],"simultaneously.":[110,222],"Our":[111],"key":[112],"insight":[113],"twofold.":[115],"First,":[116],"exploit":[118],"critical":[120],"real-world":[121],"constraint:":[122],"must":[125],"preserve":[126],"background's":[128],"semantic":[129],"consistency":[130],"avoid":[132],"detection,":[134],"if":[136],"they":[137],"apply":[138],"global,":[139],"imperceptible":[140],"Second,":[144],"using":[145],"image's":[147],"own":[148],"(face,":[150],"paper)":[153],"as":[154,171],"enhances":[157],"extraction":[158],"robustness.":[159],"Based":[160],"on":[161],"insights,":[163],"RecoverMark":[164,203],"treats":[165],"protected":[167],"itself":[170],"embeds":[175],"it":[176],"into":[177],"surrounding":[179],"background.":[180],"By":[181],"designing":[182],"two-stage":[185],"training":[186,201],"paradigm":[187],"with":[188],"carefully":[189],"crafted":[190],"distortion":[191],"layers":[192],"simulate":[194],"comprehensive":[195],"potential":[196],"attacks":[197,235],"progressive":[200],"strategy,":[202],"no":[210],"manner":[212],"IP":[220],"protection":[221],"Extensive":[223],"experiments":[224],"demonstrate":[225],"proposed":[227],"RecoverMark's":[228],"robustness":[229],"against":[230],"both":[231],"seen":[232],"unseen":[234],"its":[237],"generalizability":[238],"in-distribution":[240],"out-of-distribution":[242],"data.":[243]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-02-26T00:00:00"}
