The CLI still advertised --model, --steps, --guidance-scale, --device and a deprecated --auto. Each pinned a value the two surviving profiles fix -- the model stack, the per-stage distilled schedule, CFG 1.0, CUDA -- so the only outcome any of them had was an error raised several frames below the caller, under a message naming an internal profile. A flag whose sole result is a refusal is worse than no flag: it advertises a capability that does not exist, and it lets a wrapper thread a value that will silently do nothing. They are gone from the parser, from InvisibleEngine, and from WatermarkRemover, so the failure is now a TypeError or a Click "No such option" at the point the caller can act on. The install hint was wrong in the same way. is_available() checked torch and diffusers, then told the user to install [diffusion] -- which contains neither DiffSynth nor the Z-Image face stage both profiles run. Following the advice produced a second, different failure. The module list and the extra name now live once in watermark_profiles (REMOVAL_MODULES, INVISIBLE_EXTRA) and are read by both the CLI gate and the remover's precondition, which cannot drift apart because they are the same tuple. The adaptive-polish default moved out of the argument parser. It was resolved by reading Click's parameter source, which put per-profile data in the CLI layer, left the engine declaring the opposite default (False vs True) so a library caller and a CLI caller on one profile got different output, and lost the polish entirely for anything that supplies the flag non-interactively. The flag is now tri-state (default=None) and resolve_adaptive_polish owns the per-profile answer. The seed follows the same rule: the CLI stopped pre-resolving it. Dead code removed with it: six scan_*_video wrappers and the _scan_video helper none of them had a caller for, PNG_METADATA_KEYS, feather_region_composite and the remover region path that was only reachable from a no-caller convenience wrapper, remove_watermark_batch on both layers, try_empty_device_cache, the _generate/_run_qwen_zimage pass-through pair, self.model_id, and the _internal PEP 562 shim that no caller ever went through. get_device now answers cuda or cpu only: mps and xpu travelled one frame to the same CUDA-only refusal while costing a device probe each, and that refusal now names the resolved device, so device=None on a CUDA-less host says 'cpu' rather than 'None'. The XPU wheel index went with them. Docs: README, cli, installation, python-api, supported-signals, known-limitations and module-internals all still described the removed profiles, the CPU/MPS/XPU ladder, a `default`->`sdxl` alias, and the wrong extra. known-limitations still listed the retired SDXL strength ladder as current. scripts/smoke_matrix.py and real_examples_e2e.py drove --device mps. Next release is 0.25.0, not a patch: this removes public parameters and narrows a published extra on top of the released 0.24.0. pre-commit: 1) maintain.sh - exit 0 (1091 tests, Pyright 0 errors, no vulnerabilities); 2) /simplify - 4 agents, 11 findings applied, 2 skipped (dropping the `device` parameter entirely, which raiw-app pins; folding diffsynth into the `diffusion` extra, which video-only callers do not need); 3) docs sync - grepped every removed identifier across README, docs/, scripts/, .claude/; updated 9 docs; 4) CLAUDE.md - added the no-error-only-knobs rule to .claude/rules/development.md Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
8.8 KiB
Supported signals
This page describes the current support boundary. A check mark means that the repository contains a corresponding code path. It does not guarantee detection or removal on every future vendor version.
Visible marks
The visible command registers these mark keys:
| Key | Mark | Expected area | Important limit |
|---|---|---|---|
gemini |
Google Gemini sparkle | Usually bottom right | Detection includes a false positive gate. |
doubao |
豆包AI生成 |
Bottom right | Vendor specific text detector. |
jimeng |
★ 即梦AI |
Bottom right | Vendor specific text detector. |
qwen |
千问AI生成 |
Bottom right | Strict visual gate. |
kling |
可灵AI 3.0 |
Bottom right | Only calibrated variants are covered. |
yuanbao |
元宝 over AI生成 |
Bottom right | Standard two-line variant only. |
samsung |
✦ Contenuti generati dall'AI |
Bottom left | Calibrated for the Italian text variant. |
runninghub |
RunningHub AI生成 |
Top left | Strict visual and position gates. |
baidu |
百度 AI生成 |
Bottom right | Detector and extended removal footprint. |
liblib |
LibLibAI |
Bottom center | Includes a minimum image size gate. |
jimeng_pill |
AI生成 pill |
Top left | Weak detector with additional product and background gates. |
--mark auto evaluates all registered marks and removes every selected match.
Known marks are localized to a mask, then the selected fill backend reconstructs
the masked area.
Marks from other vendors are not detected automatically. Use erase --region
when you can select the affected area yourself.
Visible video marks
| Key | Mark | Motion | Important limit |
|---|---|---|---|
sora |
Sora 2 mascot and wordmark | Moves among frame positions | Requires a temporally recurring visual match; the older Sora Turbo corner swirl is a different unsupported mark. |
veo |
Current four-point diamond and legacy Veo text |
Fixed bottom-right corner | Uses separate silhouettes and requires a recurring match; learned fill is preferable on structured backgrounds. |
seedance |
Boxed AI label |
Fixed bottom-right corner | Requires an anchored recurring match; the full localized box is filled because a thinner synthetic shape mask leaves the real translucent rim behind. |
dola |
Dola AI text |
Fixed bottom-right corner | Requires an anchored recurring match; ByteDance or BytePlus provenance can relax only an existing visual run. |
hailuo |
`MINIMAX | hailuo AI` composite label | Fixed lower edge |
kling |
Kling swirl, KLING AI, version, and optional PRO suffix |
Fixed bottom-right edge | Combines a synthetic logo rescue with font variants, an edge gate, a white-label gate, and anchored temporal recurrence. |
video identify, video visible, and video all share this registry and the
same temporal arbiter. It is separate from the image registry because selection
is made over a sequence rather than one raster. The default auto mode scans
all six entries in one decode pass and selects the first temporally stable
match in table order; an explicit mark restricts the scan to that row.
Accepted fills are motion-aligned across adjacent frames by default. The prior
fill contributes only where its warped mask covers the current removal mask and
nearby source context agrees. Scene cuts or disjoint marks retain the
independent frame fill.
Fill backends
| Backend | Install | Behavior |
|---|---|---|
cv2 |
remove-ai-watermarks[visible] |
Classical OpenCV inpainting |
migan |
remove-ai-watermarks[migan] |
MI-GAN through ONNX Runtime; practical learned CPU video tier |
lama |
remove-ai-watermarks[lama] |
big-LaMa through ONNX Runtime; offline video quality tier |
auto |
Depends on installed extras | Selects LaMa, then MI-GAN, then OpenCV |
The learned backends download model files on first use.
Metadata and provenance
The inspection and stripping code handles signals in these groups:
- C2PA Content Credentials and supported cloud manifest references;
- EXIF and XMP generator fields;
- IPTC AI disclosure fields;
- PNG text chunks and embedded generation parameters;
- China TC260 AIGC labels in supported image placements and the normative
MP4/MOV
moov.udta.meta.keys/ilst, MKV/WebMSegment.Tags.Tag.SimpleTag, AVILIST/INFO/AIGC, and FLVscript.onMetaData.AIGCplacements; - xAI and Grok EXIF signature fields;
- Samsung AI editing markers;
- Hugging Face job metadata;
- open Stable Diffusion style DWT-DCT watermarks with the
detectextra; - Adobe TrustMark with the
trustmarkextra.
identify combines detected signals into a ProvenanceReport. It reports
unknown when evidence is absent. It never treats missing metadata as proof that
an image is human made.
File and container formats
Pixel based image commands discover these extensions:
- PNG;
- JPEG;
- WebP;
- HEIC and HEIF;
- AVIF.
HEIC, HEIF, and AVIF pixel decoding requires the independent heif extra in
addition to the selected pixel feature. Metadata scanning does not.
Metadata inspection and removal additionally have container paths for:
- JPEG XL metadata;
- MP4, MOV, M4V, and M4A;
- WebM, MKV, MKA, AVI, FLV, MP3, WAV, FLAC, OGG, OGA, Opus, and AAC when ffmpeg is available.
JPEG image metadata stripping removes targeted metadata segments without re-encoding the entropy coded image scan. PNG and WebP removal preserves pixel values through lossless output paths. HEIC, HEIF, AVIF, and other containers use their format specific paths.
Invisible watermarks
The invisible command uses diffusion regeneration. It targets watermark
patterns by changing the image rather than decoding and deleting a known
payload.
Current pipeline values, both CUDA-only:
qwen-zimage, the default;sdxl-zimage, the same recipe and the same face stage on an SDXL global pass.
The controlnet, sdxl, qwen and default values were removed. A retired name
is rejected at parse time rather than remapped onto a surviving profile.
SynthID does not have a public local pixel decoder in this project. The tool can infer likely presence from supported provenance metadata, but after that metadata is removed a local negative result is inconclusive.
For MP4, MOV, and M4V, video invisible or the explicit
video all --invisible option can regenerate the video through a VAE and strip
source metadata. The shipped profile is oracle-certified, but it is not a local
decoder. A fresh source-positive, output-negative pair from Gemini's built-in
SynthID verifier is an optional per-file audit. A normal Gemini answer may instead
infer from a visible logo or metadata; asking it to reinterpret a completed
verifier result is not a second oracle run.
The optional detect extra is different: it provides a local decoder for the
open DWT-DCT watermark used by some Stable Diffusion, SDXL, and FLUX workflows.
That signal is carrier and transformation sensitive, so a negative is still
not a universal clean verdict.
Provider overview
| Provider or family | Visible | Invisible path | Metadata or provenance |
|---|---|---|---|
| Google Gemini | Sparkle | Diffusion regeneration for SynthID | C2PA and related source signals |
| Google Veo video | Veo diamond and legacy text | Oracle-certified VAE removal for SynthID | C2PA and related source signals |
| OpenAI image generators | None registered | Diffusion regeneration for supported invisible signals | C2PA and generator provenance |
| Stable Diffusion and SDXL | None registered | Diffusion regeneration; optional open decoder | Embedded parameters and text metadata |
| FLUX | None registered | Diffusion regeneration; optional open decoder | C2PA for supported sources |
| Adobe Firefly | None registered | No proprietary local decoder | C2PA; optional TrustMark decoder |
| Midjourney | None registered | No registered pixel decoder | EXIF, XMP, and IPTC signals |
| ByteDance generators | Doubao and Jimeng marks | No registered pixel decoder | TC260 AIGC and supported C2PA signals |
| Qwen | Qwen mark | No registered pixel decoder | TC260 AIGC |
| Kling | Kling image and video marks | No registered pixel decoder | TC260 AIGC |
| Hailuo / MiniMax video | Hailuo composite video label | No registered pixel decoder | TC260 AIGC where present |
| Baidu | Baidu mark | No registered pixel decoder | TC260 AIGC |
| LibLibAI | LibLibAI mark | No registered pixel decoder | TC260 AIGC |
| RunningHub | RunningHub mark | No registered pixel decoder | TC260 AIGC |
| Samsung Galaxy AI | One locale specific mark | No registered pixel decoder | C2PA and Samsung markers |
For detector thresholds, measured limits, and incident history, see module internals and known limitations.