{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:27:34Z","timestamp":1766442454443,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":28,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765175","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:37:25Z","timestamp":1763854645000},"page":"2174-2188","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Removal Attack and Defense on AI-generated Content Latent-based Watermarking"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-4311-9028","authenticated-orcid":false,"given":"De Zhang","family":"Lee","sequence":"first","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9635-9859","authenticated-orcid":false,"given":"Han","family":"Fang","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1899-6750","authenticated-orcid":false,"given":"Hanyi","family":"Wang","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4613-0866","authenticated-orcid":false,"given":"Ee-Chien","family":"Chang","sequence":"additional","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Pseudorandom Error-Correcting Codes. In CRYPTO","author":"Christ Miranda","year":"2024","unstructured":"Miranda Christ and Sam Gunn. 2024. Pseudorandom Error-Correcting Codes. In CRYPTO 2024."},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the Twenty-Ninth Annual ACM-SIAM Symposium on Discrete Algorithms","author":"Sa Christopher De","year":"2018","unstructured":"Christopher De Sa, Albert Gu, Rohan Puttagunta, Christopher R\u00e9, and Atri Rudra. 2018. A two-pronged progress in structured dense matrix vector multiplication. In Proceedings of the Twenty-Ninth Annual ACM-SIAM Symposium on Discrete Algorithms (New Orleans, Louisiana) (SODA '18). Society for Industrial and Applied Mathematics, USA, 1060\u20131079."},{"key":"e_1_3_2_1_3_1","volume-title":"CoSDA: Enhancing the Robustness of Inversion-based Generative Image Watermarking Framework. In AAAI","author":"Fang Han","year":"2025","unstructured":"Han Fang, Kejiang Chen, Zijin Yang, Bosen Cui, Weiming Zhang, and Ee-Chien Chang. 2025. CoSDA: Enhancing the Robustness of Inversion-based Generative Image Watermarking Framework. In AAAI 2025."},{"key":"e_1_3_2_1_4_1","volume-title":"The Stable Signature: Rooting Watermarks in Latent Diffusion Models. In ICCV","author":"Fernandez Pierre","year":"2023","unstructured":"Pierre Fernandez, Guillaume Couairon, Herv\u00e9 J\u00e9gou, Matthijs Douze, and Teddy Furon. 2023. The Stable Signature: Rooting Watermarks in Latent Diffusion Models. In ICCV 2023."},{"key":"e_1_3_2_1_5_1","volume-title":"An undetectable watermark for generative image models. arXiv preprint arXiv:2410.07369","author":"Gunn Sam","year":"2024","unstructured":"Sam Gunn, Xuandong Zhao, and Dawn Song. 2024. An undetectable watermark for generative image models. arXiv preprint arXiv:2410.07369 (2024)."},{"key":"e_1_3_2_1_6_1","unstructured":"Yuepeng Hu Zhengyuan Jiang Moyang Guo and Neil Gong. 2024. Stable Signature is Unstable: Removing Image Watermark from Diffusion Models. arXiv:2405.07145 [cs.CR] https:\/\/arxiv.org\/abs\/2405.07145"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i4.32420"},{"key":"e_1_3_2_1_8_1","volume-title":"Content Based Watermarking of Images. In ACM MM","author":"Kankanhalli Mohan S.","year":"1998","unstructured":"Mohan S. Kankanhalli, K. R. Ramakrishnan, and Rajmohan. 1998. Content Based Watermarking of Images. In ACM MM 1998."},{"key":"e_1_3_2_1_9_1","volume-title":"Auto-Encoding Variational Bayes. In ICLR","author":"Diederik","year":"2014","unstructured":"Diederik P. Kingma and Max Welling. 2014. Auto-Encoding Variational Bayes. In ICLR 2014."},{"key":"e_1_3_2_1_10_1","volume-title":"ICML","author":"Kirchenbauer John","year":"2023","unstructured":"John Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz, Ian Miers, and Tom Goldstein. 2023. A Watermark for Large Language Models. In ICML 2023."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1117\/12.263442"},{"key":"e_1_3_2_1_12_1","unstructured":"Liangqi Lei Keke Gai Jing Yu and Liehuang Zhu. 2024. DiffuseTrace: A Transparent and Flexible Watermarking Scheme for Latent Diffusion Model. (2024). arXiv:2405.02696 [cs.CR] https:\/\/arxiv.org\/abs\/2405.02696"},{"key":"e_1_3_2_1_13_1","unstructured":"Nils Lukas Edward Jiang Xinda Li and Florian Kerschbaum. 2021. SoK: How Robust is Image Classification Deep Neural Network Watermarking? (Extended Version). (2021). arXiv:2108.04974 [cs.CR] https:\/\/arxiv.org\/abs\/2108.04974"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3374201"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00585"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2412.03283"},{"key":"e_1_3_2_1_17_1","unstructured":"Qi Pang Shengyuan Hu Wenting Zheng and Virginia Smith. 2024. No Free Lunch in LLM Watermarking: Trade-offs in Watermarking Design Choices. (2024). arXiv:2402.16187 [cs.CR] https:\/\/arxiv.org\/abs\/2402.16187"},{"key":"e_1_3_2_1_18_1","volume-title":"SDXL: Improving Latent Diffusion Models for High-Resolution Image Synthesis. arXiv:2307.01952 [cs.CV] https:\/\/arxiv.org\/abs\/2307.01952","author":"Podell Dustin","year":"2023","unstructured":"Dustin Podell, Zion English, Kyle Lacey, Andreas Blattmann, Tim Dockhorn, Jonas M\u00fcller, Joe Penna, and Robin Rombach. 2023. SDXL: Improving Latent Diffusion Models for High-Resolution Image Synthesis. arXiv:2307.01952 [cs.CV] https:\/\/arxiv.org\/abs\/2307.01952"},{"key":"e_1_3_2_1_19_1","volume-title":"ICML","author":"Qiu Shikai","year":"2024","unstructured":"Shikai Qiu, Andres Potapczynski, Marc Finzi, Micah Goldblum, and Andrew Gordon Wilson. 2024. Compute better spent: replacing dense layers with structured matrices. In ICML 2024."},{"key":"e_1_3_2_1_20_1","volume-title":"Learning Transferable Visual Models From Natural Language Supervision. In ICML","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever. 2021. Learning Transferable Visual Models From Natural Language Supervision. In ICML 2021."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Robin Rombach Andreas Blattmann Dominik Lorenz Patrick Esser and Bj\u00f6rn Ommer. 2021. High-Resolution Image Synthesis with Latent Diffusion Models. arXiv:2112.10752 [cs.CV]","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_22_1","unstructured":"Atri Rudra. 2023. (Dense Structured) Matrix Vector Multiplication. https:\/\/web.archive.org\/web\/20240422090854\/https:\/\/cse.buffalo.edu\/faculty\/atri\/courses\/matrix\/matrix-vect-notes.pdf Date accessed: 2024-04-22."},{"key":"e_1_3_2_1_23_1","volume-title":"Analysis of Digital Image Watermark Attacks. In IEEE CCNC","author":"Song Chunlin","year":"2010","unstructured":"Chunlin Song, Sud Sudirman, Madjid Merabti, and David Llewellyn-Jones. 2010. Analysis of Digital Image Watermark Attacks. In IEEE CCNC 2010."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.1994.413536"},{"key":"e_1_3_2_1_25_1","unstructured":"Yuxin Wen John Kirchenbauer Jonas Geiping and Tom Goldstein. 2023. Tree-Ring Watermarks: Fingerprints for Diffusion Images that are Invisible and Robust. arXiv:2305.20030 [cs.LG] https:\/\/arxiv.org\/abs\/2305.20030"},{"key":"e_1_3_2_1_26_1","volume-title":"NeurIPS","author":"Yang Pei","year":"2024","unstructured":"Pei Yang, Hai Ci, Yiren Song, and Mike Zheng Shou. 2024a. Can Simple Averaging Defeat Modern Watermarks?. In NeurIPS 2024."},{"key":"e_1_3_2_1_27_1","volume-title":"Gaussian Shading: Provable Performance-Lossless Image Watermarking for Diffusion Models. In CVPR","author":"Yang Zijin","year":"2024","unstructured":"Zijin Yang, Kai Zeng, Kejiang Chen, Han Fang, Weiming Zhang, and Nenghai Yu. 2024b. Gaussian Shading: Provable Performance-Lossless Image Watermarking for Diffusion Models. In CVPR 2024."},{"key":"e_1_3_2_1_28_1","volume-title":"NeurIPS","author":"Zhao Xuandong","year":"2024","unstructured":"Xuandong Zhao, Kexun Zhang, Zihao Su, Saastha Vasan, Ilya Grishchenko, Christopher Kruegel, Giovanni Vigna, Yu-Xiang Wang, and Lei Li. 2024. Invisible Image Watermarks Are Provably Removable Using Generative AI. In NeurIPS 2024."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765175","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:25:37Z","timestamp":1766442337000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765175"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":28,"alternative-id":["10.1145\/3719027.3765175","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765175","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}