LiBRA: Detection-Aware Image Watermark Removal via Bidirectional Latent Optimization

πŸ“… 2026-10-02
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
Existing AI-based image watermark removal methods are prone to watermark inversion residuals or excessive degradation of visual quality. To address these limitations, this work proposes LiBRA, a method that performs bidirectional optimization guidance in the latent space to drive decoder confidence toward random guessing, thereby mitigating inversion risks. Additionally, frequency masking is introduced to constrain perturbation regions and preserve generated image quality. Built upon an autoencoder architecture, LiBRA employs binomial testing for rigorous statistical validation. Experimental results demonstrate that LiBRA achieves covert and undetectable watermark removal while maintaining high visual fidelity, offering a new paradigm for evaluating watermark robustness.
πŸ“ Abstract
Digital watermarking supports source attribution for AI-generated images, but its reliability depends on resistance to removal attacks. Some attacks attempt to remove watermarks by forcing the decoded watermark to differ from the original. However, this can produce an inverted watermark that remains detectable, causing removal to fail, while further attempts to alter the watermark may unnecessarily degrade image quality. To address these limitations, we present LiBRA (Latent In-band Bidirectional Removal Attack), which aims to make watermarks undetectable while preserving image quality. Instead of continually pushing the watermark toward inversion, LiBRA adjusts the image to conceal the watermark without encouraging further changes that could degrade image quality. Some attacks keep pushing decoded bits away from the original watermark, even when further changes preserve detectability and damage image quality. With access to the watermark key and decoder, LiBRA makes bounded changes in a public autoencoder's latent space. Unlike inversion-driven objectives that cannot correct excessive inversion, LiBRA guides average decoding confidence toward random guessing from either direction. This helps avoid an inverted but detectable watermark. Leaving individual bits flexible allows image-quality constraints to favor less damaging changes, while an optional frequency-guided mask limits their location. We verify removal using an exact two-sided binomial test rather than assuming the confidence target guarantees success.
Problem

Research questions and friction points this paper is trying to address.

watermark removal
digital watermarking
image quality
detection evasion
AI-generated images
Innovation

Methods, ideas, or system contributions that make the work stand out.

Watermark Removal
Bidirectional Latent Optimization
Detection-Aware Attack
Autoencoder Latent Space
Binomial Test
S
Saibo Ye
Faculty of Data Science, City University of Macau, Macao SAR, China
H
Huajie Chen
Faculty of Data Science, City University of Macau, Macao SAR, China
X
Xin Guo
Faculty of Data Science, City University of Macau, Macao SAR, China
L
Le Yang
School of Information and Communications Engineering, Xi’an Jiaotong University, Xi’an 710049, China
C
Chi Liu
Faculty of Data Science, City University of Macau, Macao SAR, China
X
Xiangyu Hu
School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu 610054, China
J
Jingjing Guo
School of Cyber Engineering, Xidian University, Xi’an 710071, China
Tianqing Zhu
Tianqing Zhu
City University of Macau
PrivacyCyber SecurityMachine LearningAI Security