{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:JHERORN27XK5HCFQY3GR6S35OC","short_pith_number":"pith:JHERORN2","canonical_record":{"source":{"id":"2604.25491","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-04-28T10:47:21Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"5422d409991473b970cc1011830cf94d2cfcf203616c450e8f6f701daee3ae0d","abstract_canon_sha256":"01fb88f0d07868b00c0170ad54f8ae560e872ac8edf7a03850ccdc5b02108d5a"},"schema_version":"1.0"},"canonical_sha256":"49c91745bafdd5d388b0c6cd1f4b7d70ab625b937d85558c96affc8c3c5d9256","source":{"kind":"arxiv","id":"2604.25491","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.25491","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"arxiv_version","alias_value":"2604.25491v2","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.25491","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"pith_short_12","alias_value":"JHERORN27XK5","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"pith_short_16","alias_value":"JHERORN27XK5HCFQ","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"pith_short_8","alias_value":"JHERORN2","created_at":"2026-05-28T02:04:48Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:JHERORN27XK5HCFQY3GR6S35OC","target":"record","payload":{"canonical_record":{"source":{"id":"2604.25491","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-04-28T10:47:21Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"5422d409991473b970cc1011830cf94d2cfcf203616c450e8f6f701daee3ae0d","abstract_canon_sha256":"01fb88f0d07868b00c0170ad54f8ae560e872ac8edf7a03850ccdc5b02108d5a"},"schema_version":"1.0"},"canonical_sha256":"49c91745bafdd5d388b0c6cd1f4b7d70ab625b937d85558c96affc8c3c5d9256","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-28T02:04:48.259824Z","signature_b64":"GQvCwcfgmMXFHMP/2vGklZzCvMHFs8CDvERVedAxybYC+IC8fF9WRMZ9DUIjz/AEKxNW4yqKHJlv4P6f1yH0Cg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"49c91745bafdd5d388b0c6cd1f4b7d70ab625b937d85558c96affc8c3c5d9256","last_reissued_at":"2026-05-28T02:04:48.259377Z","signature_status":"signed_v1","first_computed_at":"2026-05-28T02:04:48.259377Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2604.25491","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-28T02:04:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2ay1B/2iABeWdFZb/EknzNigIDonNq3JQwyLORjFdfXqWbybNtWgwVB300XXTlIdajP1wJrvhaEVbrtkg+VODw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T09:13:53.686117Z"},"content_sha256":"f8309fe22ba358154292a704a76033b6d22541528e909ff2d5d3dcd9fb67baf2","schema_version":"1.0","event_id":"sha256:f8309fe22ba358154292a704a76033b6d22541528e909ff2d5d3dcd9fb67baf2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:JHERORN27XK5HCFQY3GR6S35OC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Forensic Cost of Watermark Removal: From Dedicated Attacks to Image Editing","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"Watermark removal methods leave statistical artifacts that a classifier can detect at a false positive rate of one in a thousand.","cross_cats":["cs.AI"],"primary_cat":"cs.CV","authors_text":"Ewa Kijak, Gautier Evennou","submitted_at":"2026-04-28T10:47:21Z","abstract_excerpt":"Current watermark removal methods are evaluated on two axes: attack success rate and perceptual quality. We show this is insufficient. While state-of-the-art attacks successfully degrade the watermark signal without visible distortion, they leave distinct statistical artifacts that betray the removal attempt. We name this overlooked axis Watermark Removal Detection (WRD) and demonstrate that a modern classifier trained on these artifacts achieves state-of-the-art detection rates at $10^{-3}$ FPR across every removal method tested. No existing attack accounts for this forensic leakage. We bench"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"a modern classifier trained on these artifacts achieves state-of-the-art detection rates at 10^{-3} FPR across every removal method tested","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The statistical artifacts are inherent to the removal process itself rather than specific to the particular implementations, datasets, or training procedures used in the experiments.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Watermark removal leaves statistical artifacts that allow classifiers to detect the attempt at 10^{-3} FPR across tested methods, establishing forensic stealthiness as a required property.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Watermark removal methods leave statistical artifacts that a classifier can detect at a false positive rate of one in a thousand.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"ce6661e1d9b9a3d19dd543ba7f8b78e40e9d843748ef3feb8ed18e18ef57f744"},"source":{"id":"2604.25491","kind":"arxiv","version":2},"verdict":{"id":"ece32ed6-d5b2-450a-a0bc-36392629c44a","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-07T17:00:26.613793Z","strongest_claim":"a modern classifier trained on these artifacts achieves state-of-the-art detection rates at 10^{-3} FPR across every removal method tested","one_line_summary":"Watermark removal leaves statistical artifacts that allow classifiers to detect the attempt at 10^{-3} FPR across tested methods, establishing forensic stealthiness as a required property.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The statistical artifacts are inherent to the removal process itself rather than specific to the particular implementations, datasets, or training procedures used in the experiments.","pith_extraction_headline":"Watermark removal methods leave statistical artifacts that a classifier can detect at a false positive rate of one in a thousand."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2604.25491/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"ai_meta_artifact","ran_at":"2026-05-21T04:39:35.217459Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_compliance","ran_at":"2026-05-19T21:06:48.923609Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"79b8ef476c9b2c4c36e529ba3e9d131269f9ce15c78279e855c36a1d2fb11dcb"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"ece32ed6-d5b2-450a-a0bc-36392629c44a"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-28T02:04:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"z6sLYJFjP3A3jmAUaHkUD1yT/PQV255F+fQfiVq5gknDmBkNbhIjRaAUZYPjKhDfSAiHwaoxChRtWjODpJZ4Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T09:13:53.686601Z"},"content_sha256":"9f26b584b9b7d67fedd9dd2157c44e29bcbd915fe0aec6a61656a61f0060ac92","schema_version":"1.0","event_id":"sha256:9f26b584b9b7d67fedd9dd2157c44e29bcbd915fe0aec6a61656a61f0060ac92"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JHERORN27XK5HCFQY3GR6S35OC/bundle.json","state_url":"https://pith.science/pith/JHERORN27XK5HCFQY3GR6S35OC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JHERORN27XK5HCFQY3GR6S35OC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T09:13:53Z","links":{"resolver":"https://pith.science/pith/JHERORN27XK5HCFQY3GR6S35OC","bundle":"https://pith.science/pith/JHERORN27XK5HCFQY3GR6S35OC/bundle.json","state":"https://pith.science/pith/JHERORN27XK5HCFQY3GR6S35OC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JHERORN27XK5HCFQY3GR6S35OC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:JHERORN27XK5HCFQY3GR6S35OC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"01fb88f0d07868b00c0170ad54f8ae560e872ac8edf7a03850ccdc5b02108d5a","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-04-28T10:47:21Z","title_canon_sha256":"5422d409991473b970cc1011830cf94d2cfcf203616c450e8f6f701daee3ae0d"},"schema_version":"1.0","source":{"id":"2604.25491","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.25491","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"arxiv_version","alias_value":"2604.25491v2","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.25491","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"pith_short_12","alias_value":"JHERORN27XK5","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"pith_short_16","alias_value":"JHERORN27XK5HCFQ","created_at":"2026-05-28T02:04:48Z"},{"alias_kind":"pith_short_8","alias_value":"JHERORN2","created_at":"2026-05-28T02:04:48Z"}],"graph_snapshots":[{"event_id":"sha256:9f26b584b9b7d67fedd9dd2157c44e29bcbd915fe0aec6a61656a61f0060ac92","target":"graph","created_at":"2026-05-28T02:04:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"a modern classifier trained on these artifacts achieves state-of-the-art detection rates at 10^{-3} FPR across every removal method tested"},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The statistical artifacts are inherent to the removal process itself rather than specific to the particular implementations, datasets, or training procedures used in the experiments."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Watermark removal leaves statistical artifacts that allow classifiers to detect the attempt at 10^{-3} FPR across tested methods, establishing forensic stealthiness as a required property."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Watermark removal methods leave statistical artifacts that a classifier can detect at a false positive rate of one in a thousand."}],"snapshot_sha256":"ce6661e1d9b9a3d19dd543ba7f8b78e40e9d843748ef3feb8ed18e18ef57f744"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-21T04:39:35.217459Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T21:06:48.923609Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2604.25491/integrity.json","findings":[],"snapshot_sha256":"79b8ef476c9b2c4c36e529ba3e9d131269f9ce15c78279e855c36a1d2fb11dcb","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Current watermark removal methods are evaluated on two axes: attack success rate and perceptual quality. We show this is insufficient. While state-of-the-art attacks successfully degrade the watermark signal without visible distortion, they leave distinct statistical artifacts that betray the removal attempt. We name this overlooked axis Watermark Removal Detection (WRD) and demonstrate that a modern classifier trained on these artifacts achieves state-of-the-art detection rates at $10^{-3}$ FPR across every removal method tested. No existing attack accounts for this forensic leakage. We bench","authors_text":"Ewa Kijak, Gautier Evennou","cross_cats":["cs.AI"],"headline":"Watermark removal methods leave statistical artifacts that a classifier can detect at a false positive rate of one in a thousand.","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-04-28T10:47:21Z","title":"The Forensic Cost of Watermark Removal: From Dedicated Attacks to Image Editing"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2604.25491","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-07T17:00:26.613793Z","id":"ece32ed6-d5b2-450a-a0bc-36392629c44a","model_set":{"reader":"grok-4.3"},"one_line_summary":"Watermark removal leaves statistical artifacts that allow classifiers to detect the attempt at 10^{-3} FPR across tested methods, establishing forensic stealthiness as a required property.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Watermark removal methods leave statistical artifacts that a classifier can detect at a false positive rate of one in a thousand.","strongest_claim":"a modern classifier trained on these artifacts achieves state-of-the-art detection rates at 10^{-3} FPR across every removal method tested","weakest_assumption":"The statistical artifacts are inherent to the removal process itself rather than specific to the particular implementations, datasets, or training procedures used in the experiments."}},"verdict_id":"ece32ed6-d5b2-450a-a0bc-36392629c44a"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f8309fe22ba358154292a704a76033b6d22541528e909ff2d5d3dcd9fb67baf2","target":"record","created_at":"2026-05-28T02:04:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"01fb88f0d07868b00c0170ad54f8ae560e872ac8edf7a03850ccdc5b02108d5a","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-04-28T10:47:21Z","title_canon_sha256":"5422d409991473b970cc1011830cf94d2cfcf203616c450e8f6f701daee3ae0d"},"schema_version":"1.0","source":{"id":"2604.25491","kind":"arxiv","version":2}},"canonical_sha256":"49c91745bafdd5d388b0c6cd1f4b7d70ab625b937d85558c96affc8c3c5d9256","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"49c91745bafdd5d388b0c6cd1f4b7d70ab625b937d85558c96affc8c3c5d9256","first_computed_at":"2026-05-28T02:04:48.259377Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-28T02:04:48.259377Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"GQvCwcfgmMXFHMP/2vGklZzCvMHFs8CDvERVedAxybYC+IC8fF9WRMZ9DUIjz/AEKxNW4yqKHJlv4P6f1yH0Cg==","signature_status":"signed_v1","signed_at":"2026-05-28T02:04:48.259824Z","signed_message":"canonical_sha256_bytes"},"source_id":"2604.25491","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f8309fe22ba358154292a704a76033b6d22541528e909ff2d5d3dcd9fb67baf2","sha256:9f26b584b9b7d67fedd9dd2157c44e29bcbd915fe0aec6a61656a61f0060ac92"],"state_sha256":"42fe318e5e633ba7c0aa91f353f196b672b72f7249673d3e7d6ecc3ade01b0d0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"cmO4wUk2VjlBtAkaDUY+9KtfQJ8lnrHoyLQTXTjzZX1KQBHeeHbkmsV1KQcbvZz//z2opKvRqjwkFWxLC4lVDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T09:13:53.688824Z","bundle_sha256":"92739433cda6acaecb16c1e24d2b364f9342cdf3508f36b29a9ed410be03e82b"}}