SwiftRegen: Efficient Image Watermark Evasion Beyond Output Imitation and Evidence Removal
Abstract
Robust invisible image watermarking relies on embedded evidence that remains detectable under post-processing and adversarial manipulation. Regeneration attacks can suppress this evidence, but iterative denoising incurs substantial computational cost. We present SwiftRegen, an efficient watermark evasion attack that replaces iterative regeneration with a single-pass operator learned offline from clean images and their regenerated counterparts, without watermark supervision, detector queries, or keys. Our study reveals two key insights. First, faithfully reproducing the regeneration output does not guarantee effective removal transfer: a full-image predictor achieves higher output fidelity yet weaker removal than a bounded residual predictor, so learning the regeneration-induced update transfers removal more effectively. Second, watermark evidence can survive while detection fails. For schemes that depend on correspondence between surviving evidence and the detector-side reference, disrupting this correspondence can defeat detection without removing the evidence. This motivates Watermark Carrier Desynchronization (WCD), which uses mild cropping and resizing to disrupt synchronization while largely preserving visual content. SwiftRegen combines the learned operator with WCD, and across eleven watermarking schemes achieves a mean TPR@1% FPR of 0.080 and a 72× speedup over CtrlRegen. Our results show that robust watermark detection depends on both evidence persistence and synchronization.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.