Watermark Robustness
Watermark robustness describes how well an invisible AI-content watermark survives real-world transformations — resizing, recompression, format conversion, re-uploading to social platforms — versus deliberate, targeted removal. A robust watermark is built to survive the first category; no publicly known watermarking scheme, including Certivu's, is claimed to survive the second. Understanding that distinction is central to using watermarks honestly as a resilience signal rather than as tamper-proof evidence.
What watermarks are designed to survive
Certivu's watermark embeds an opaque lookup identifier into mid-frequency regions of an image or audio signal using frequency-domain (DCT) techniques, chosen specifically because ordinary processing — JPEG recompression at reasonable quality, resizing, and the transformations social platforms apply automatically on upload — tends to preserve those frequencies. That's what makes a watermark useful as a fallback: when a token or embedded manifest gets stripped by a platform's re-encoding pipeline, the watermark can often still be recovered and matched back to a signed provenance record.
What watermarks are not claimed to survive
Watermarking is not claimed to be unremovable. Someone specifically motivated to strip a watermark — through heavy cropping, adversarial noise designed to target the watermark, aggressive re-compression, or manual editing focused on defeating detection — can degrade or remove it, a limitation every publicly known image or audio watermarking scheme shares. This is why Certivu treats a watermark as a resilience signal, not proof: the cryptographic signature on a signed record is the actual source of truth, and a missing or degraded watermark doesn't invalidate a valid signature reachable another way, nor does it mean the content was never signed.
Why this honesty matters
Overstating watermark durability creates a false sense of security and, in a compliance context, could mislead a platform or regulator about what a marking actually guarantees. Certivu's verification response reflects this directly: watermark-based matches contribute to a lower confidence tier than a verified cryptographic signature, and the system never claims a watermark's absence proves human origin — it may simply mean the mark was degraded, removed, or never present in the first place.
FAQ
Can someone remove an AI watermark on purpose?
Yes. Watermarking is designed to survive ordinary handling — resizing, recompression, re-uploading — but it is not claimed to be unremovable against someone specifically trying to strip it. Certivu does not claim otherwise for its own watermark.
If a watermark is removed, does that mean the content is no longer verifiable?
Not necessarily. Certivu checks multiple signals in order — a provided token, embedded format-native metadata, the watermark, then fuzzy fingerprint matching — so a stripped watermark alone doesn't prevent verification if another signal is still present. If none are, verification correctly reports that no provenance was found rather than guessing.
Does a missing watermark mean content wasn't AI-generated?
No. A missing or unrecoverable watermark only means no watermark signal could be found in that specific copy of the content — it says nothing about whether the content was AI-generated or where it came from.