{"id":"https://openalex.org/W7131415972","doi":"https://doi.org/10.48550/arxiv.2602.20680","title":"Vanishing Watermarks: Diffusion-Based Image Editing Undermines Robust Invisible Watermarking","display_name":"Vanishing Watermarks: Diffusion-Based Image Editing Undermines Robust Invisible Watermarking","publication_year":2026,"publication_date":"2026-02-24","ids":{"openalex":"https://openalex.org/W7131415972","doi":"https://doi.org/10.48550/arxiv.2602.20680"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2602.20680","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5126814801","display_name":"Fan Guo","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Guo, Fan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085370925","display_name":"Jiyu Kang","orcid":"https://orcid.org/0000-0002-6993-2047"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kang, Jiyu","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126807537","display_name":"Qi Ming","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ming, Qi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126809518","display_name":"Emily Davis","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Davis, Emily","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5126804886","display_name":"Finn Carter","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Carter, Finn","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5126814801"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.8629999756813049,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.8629999756813049,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.06790000200271606,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.019600000232458115,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.9222000241279602},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.8919000029563904},{"id":"https://openalex.org/keywords/payload","display_name":"Payload (computing)","score":0.6111000180244446},{"id":"https://openalex.org/keywords/image-editing","display_name":"Image editing","score":0.5088000297546387},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.48969998955726624},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.4702000021934509},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4699999988079071},{"id":"https://openalex.org/keywords/generative-model","display_name":"Generative model","score":0.400299996137619},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.39800000190734863}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.9222000241279602},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.8919000029563904},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7110999822616577},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6237999796867371},{"id":"https://openalex.org/C134066672","wikidata":"https://www.wikidata.org/wiki/Q1424639","display_name":"Payload (computing)","level":3,"score":0.6111000180244446},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.5720999836921692},{"id":"https://openalex.org/C2776674983","wikidata":"https://www.wikidata.org/wiki/Q545981","display_name":"Image editing","level":3,"score":0.5088000297546387},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.48969998955726624},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.4702000021934509},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4699999988079071},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.400299996137619},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.39800000190734863},{"id":"https://openalex.org/C36464697","wikidata":"https://www.wikidata.org/wiki/Q451553","display_name":"Visualization","level":2,"score":0.3709000051021576},{"id":"https://openalex.org/C106430172","wikidata":"https://www.wikidata.org/wiki/Q6002272","display_name":"Image restoration","level":4,"score":0.36090001463890076},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.33320000767707825},{"id":"https://openalex.org/C2780581891","wikidata":"https://www.wikidata.org/wiki/Q15738686","display_name":"Copy protection","level":4,"score":0.33059999346733093},{"id":"https://openalex.org/C3073032","wikidata":"https://www.wikidata.org/wiki/Q15912075","display_name":"Information hiding","level":3,"score":0.33009999990463257},{"id":"https://openalex.org/C2779843651","wikidata":"https://www.wikidata.org/wiki/Q7390335","display_name":"SIGNAL (programming language)","level":2,"score":0.32269999384880066},{"id":"https://openalex.org/C160086991","wikidata":"https://www.wikidata.org/wiki/Q5939193","display_name":"Human visual system model","level":3,"score":0.32190001010894775},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.3174000084400177},{"id":"https://openalex.org/C2776459999","wikidata":"https://www.wikidata.org/wiki/Q2119376","display_name":"Fidelity","level":2,"score":0.31690001487731934},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.28850001096725464},{"id":"https://openalex.org/C126042441","wikidata":"https://www.wikidata.org/wiki/Q1324888","display_name":"Frame (networking)","level":2,"score":0.2721000015735626},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.27129998803138733},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.25360000133514404},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.25040000677108765}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2602.20680","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2602.20680","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.20680","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2602.20680","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Robust":[0],"invisible":[1],"watermarking":[2,144,185],"schemes":[3,149],"aim":[4],"to":[5,31,60,76,135,197],"embed":[6],"hidden":[7,130],"information":[8,123],"into":[9],"images":[10],"such":[11],"that":[12,46,66,97,113,157],"the":[13,86,100,121,125,129,173,192,202],"watermark":[14,102,108,162,199],"survives":[15],"common":[16],"manipulations.":[17],"However,":[18],"powerful":[19,205],"diffusion-based":[20,95],"image":[21,69,116,127],"generation":[22],"and":[23,42,128,153,155],"editing":[24],"techniques":[25,186],"now":[26],"pose":[27],"a":[28,39,67,93,179],"new":[29,195],"threat":[30],"these":[32],"watermarks.":[33],"In":[34],"this":[35],"paper,":[36],"we":[37,91,111,140],"present":[38],"comprehensive":[40],"theoretical":[41],"empirical":[43],"analysis":[44],"demonstrating":[45],"diffusion":[47,119,158,206],"models":[48,75],"can":[49,80],"effectively":[50],"erase":[51],"robust":[52,184],"watermarks":[53,57,83],"even":[54],"when":[55],"those":[56],"were":[58],"designed":[59],"withstand":[61],"conventional":[62],"distortions.":[63],"We":[64],"show":[65],"diffusion-driven":[68],"regeneration":[70],"process,":[71],"which":[72],"leverages":[73],"generative":[74,188],"recreate":[77],"an":[78,115],"image,":[79],"remove":[81],"embedded":[82,101],"while":[84,167],"preserving":[85],"image's":[87],"perceptual":[88],"content.":[89],"Furthermore,":[90],"introduce":[92],"guided":[94],"attack":[96],"explicitly":[98],"targets":[99],"signal":[103],"during":[104],"generation,":[105],"significantly":[106],"degrading":[107],"detectability.":[109],"Theoretically,":[110],"prove":[112],"as":[114],"undergoes":[117],"sufficient":[118],"transformations,":[120],"mutual":[122],"between":[124],"watermarked":[126],"payload":[131],"approaches":[132],"zero,":[133],"leading":[134],"inevitable":[136],"decoding":[137],"failure.":[138],"Experimentally,":[139],"evaluate":[141],"multiple":[142],"state-of-the-art":[143],"methods":[145],"(including":[146],"deep":[147],"learning-based":[148],"like":[150],"StegaStamp,":[151],"TrustMark,":[152],"VINE)":[154],"demonstrate":[156],"edits":[159],"yield":[160],"near-zero":[161],"recovery":[163],"rates":[164],"after":[165],"attack,":[166],"maintaining":[168],"high":[169],"visual":[170],"fidelity":[171],"of":[172,204],"regenerated":[174],"images.":[175],"Our":[176],"findings":[177],"reveal":[178],"fundamental":[180],"vulnerability":[181],"in":[182,201],"current":[183],"against":[187],"model-based":[189],"edits,":[190],"underscoring":[191],"need":[193],"for":[194],"strategies":[196],"ensure":[198],"resilience":[200],"era":[203],"models.":[207]},"counts_by_year":[],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2026-02-26T00:00:00"}
