Search papers, labs, and topics across Lattice.
The paper introduces MarkSweep, a novel attack against AI-generated image watermarks that circumvents the need for a watermark detector ("no-box"). MarkSweep amplifies watermark noise in high-frequency regions using edge-aware Gaussian perturbations and trains a denoising network to suppress this noise. The denoising network incorporates learnable frequency decomposition and frequency-aware fusion modules, effectively removing watermarks while maintaining image quality.
AI-generated image watermarks are surprisingly brittle: a new attack, MarkSweep, wipes them out by strategically amplifying and denoising high-frequency noise.
AI watermarking embeds invisible signals within images to provide provenance information and identify content as AI-generated. In this paper, we introduce MarkSweep, a novel watermark removal attack that effectively erases the embedded watermarks from AI-generated images without degrading visual quality. MarkSweep first amplifies watermark noise in high-frequency regions via edge-aware Gaussian perturbations and injects it into clean images for training a denoising network. This network then integrates two modules, the learnable frequency decomposition module and the frequency-aware fusion module, to suppress amplified noise and eliminate watermark traces. Theoretical analysis and extensive experiments demonstrate that invisible watermarks are highly vulnerable to MarkSweep, which effectively removes embedded watermarks, reducing the bit accuracy of HiDDeN and Stable Signature watermarking schemes to below 67%, while preserving perceptual quality of AI-generated images.