20 ms·
OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool
- CSMastermind 5mo agoAren't these kinds of watermarks easy to remove or distort? Seems like they're only helpful as long as people are relying on them sparingly so it's not worth the effort to circumvent. If social media platforms started banning images with these watermarks seems like they'd be stripped out overnight.
- Tiberium 5mo agoI still don't think there's a single GitHub repo that actually removes real SynthID watermarks from Nano Banana 2/NBPro outputs. Most of them are just some research projects that haven't achieved this. The only methods so far I've seen are weird tricks with transparency/overlaying the original image if you're using edits, and also using a diffusion model to regenerate the NB-generated image at low noise levels, but this also modifies the original.
- vunderba 5mo agoRight I think that’s why you probably need to start with very low levels of denoising and experiment with different approaches. Set up as a ComfyUI workflow that does a few things: it tries SDXL, Flux, and a couple of different denoising methods at the lowest possible strength (progressively incrementing) to avoid changing the image too much, while also running a SynthID check each time, and repeating this in a loop until the watermark is essentially gone. At the same time, you’d probably want to add some kind of threshold based on a perceptual hash aka the maximum perceptual quality difference you’re willing to accept.
- amazingamazing 5mo agoNo, they are very resistant to modification that can be done easily. That being said I doubt it is impossible
- snissn 5mo agoI’m surprised! I guess I’m being naive but I would imagine you could pass an image to an image model without synthid and have it reconstruct the image in a net new way without the markers. I guess I’m wrong? That’s cool if the watermarks are so deeply ingrained that they persist
- cephei 5mo agoAs I understand it, they modify the image by applying a special Gaussian noise filter which affects each pixel in the image in subtle (possibly not reversible) ways. The detecting service will look for this noise pattern to flag it, so even a part of the image is enough to know it was generated by AI.
- vitorgrs 5mo agoYes, Gemini can actually say how much of the image is AI generated.
- janalsncm 5mo agoYeah cropping, color shifting, resizing and compression don’t remove it. That said, there’s pretty well known workarounds: https://github.com/wiltodelta/remove-ai-watermarks https://github.com/wiltodelta/remove-ai-watermarks
- surgical_fire 5mo agoThe sort of people that generate AI images that need a watermark are not exactly the kind of people prone for this sort of effort.
- Arnt 5mo agoThis one was released a few years ago and still seems unbroken. I'm sure it will be broken at some point, but if you have to wait a year or two from when you make a deepfake until you can post it on Facebook, maybe that's enough. Maybe even a month is enough.
- programd 5mo agoDefine easily. There is an approach that apparently works and is based on spectral analysis of the images. https://github.com/aloshdenny/reverse-SynthID https://github.com/aloshdenny/reverse-SynthID
- toraway 5mo agoFWIW there are a few people in the issues saying that the tool is giving false negatives and the output image gets flagged by the actual Gemini API as having SynthID. Most recently 3 weeks ago without a response.
- ZeWaka 5mo agoI imagine the technique of having AI recreate the image from scratch based on a very detailed description might work.
- raincole 5mo agoThat'd not work with today's technology. No open model's prompt adherence is anywhere remotely close to ChatGPT/NanoBanana. 'remotely' here is a funny understatement, as I don't have a strong enough word in my vocabulary to describe how far the open models are behind the closed ones. Writing a more detailed description does not make the models stick to it more.
- vunderba 5mo agoDefinitely. I run an entire site built around a series of benchmarks that focus on prompts of increasingly difficult complexity with a focus on adherence, and even the state-of-the-art local models are probably only about thirty percent as good as proprietary models like Gemini 3.1 Flash Image and GPT Image 2. Comparing Qwen-Image, Flux.2, ZiT, NB2, and gpt-image-2 https://genai-showdown.specr.net/?models=qi,nbp3,f2d,g2,zt https://genai-showdown.specr.net/?models=qi,nbp3,f2d,g2,zt
- kube-system 5mo agoIs there no way to do this without uploading it?
- duskwuff 5mo agoCurrently, there is not. OpenAI has promised "public verification tooling" down the line, but I'll believe it when I see it.
- woadwarrior01 5mo agoI'd built an on-device app for detecting C2PA and IPTC metadata in images, amongst other things. I might be able to add support for SynthID detection once it's been reverse engineered.
- PunchyHamster 5mo agoso ? people wanting to make AI propaganda will just make tool to remove it. Possibly using AI to do it too
- pta2002 5mo agoI assume a selfish benefit is that OpenAI and Google don't want the models to train on their own data. There is just /so much/ AI generated content online that they definitely need to filter it out somehow when assembling the training data. This is a pretty effective way to do that, with the nice bonus of being mostly good from a PR standpoint.
- sgc 5mo agoI immediately thought that was the real reason. Their models will quickly break without some sort of consensus on how to reliably exclude them.
- amazingamazing 5mo agoGood. Despite people saying it will be removed, I have seen no reproducible repo demonstrating it.
- raincole 5mo agoStable Diffusion with 10%~15% denoising strength. Done. I tested the day 1 when Nano Banana Pro was released and it worked. It still works today for Nano Banana 2. I didn't post this anywhere because I (arrogantly) thought saying it publicly would make the internet worse. But it was pure arrogancy: if I came up with this the first day then of course other millions of programmers did too. That being said, it'll introduce the typical artifacts from SD models and that might be detected by other methods (or just by zooming in a lot and looking carefully).
- vunderba 5mo agoYup, OOC a while back I put together a ComfyUI node that took in a NB image and start with the smallest amount of denoise strength using Flux.1 (but works with any model), then run img2img with a synthid check incrementing denoise in a loop until it was defeated. Never released it, but it was obvious to most people in the SD community that denoising using a diffusion model was a relatively trivial means to beat most steganographic watermarks.
- londons_explore 5mo agoYet is in itself fairly trivial to detect assuming you use some open-weight image model as a base.
- amazingamazing 5mo agoPost a repro. I can do that too but then the similarity index is weak. The point is that it it looks indistinguishable then the integrity persists. In my tests the image looks clearly distinct. In other words, if you can tell the difference then it isn’t a good test.
- zulban 5mo ago
- minimaxir 5mo agoI'm annoyed that Google is keeping it closed-sourced and limited to partners. Is there a negative externality about open-sourcing image watermark technology so anyone can use it and audit the watermarks independently? If not, then I may have a repository for an open-source invisible and tamper-resistant image watermarking approach that's feature complete...
- parhamn 5mo agomight be easier to strip it?
- thisisthenewme 5mo agopotentially to stop bad actors from poisoning datasets by just adding the filter to real pictures?
- bsder 5mo agoThe fact that they have to keep this closed source is a giant red flag. It means that you can copy it or strip it if you have the knowledge. I'm not all that worried about stripping it (I'm sure that's trivial). The problem that I am worried about is that it can be copied (I'd bet $20 that's trivial, too). People WILL put this on images so that they can be "discredited".
- flaxxer 5mo ago[dead]
- bstsb 5mo agoalways trust a vibe-coded website which uses a Discord bot as its backend (i'm sure there are countless bypasses out there, but please don't use something like this)
- amazingamazing 5mo agoYou can tell the difference in the example with your bare eyes lol
- Retr0id 5mo agoWhy does this matter?
- big_toast 5mo agoWhat information is included in the metadata or SynthID? How many bits can be encoded in a SynthID? Can it be used to create something like nutritional labels for synthetic content? 10% synthetic text, 30 synthetic images. Your reality was 15% synthetic today (75% mega corp, 25% open-weight neocloud).
- big_toast 5mo agoI guess the SynthID-Image paper from Oct 2025[0] was an encoder-decoder for which they tested checking a flag or a 136 bit payload in 512x512 images and the watermark's robustness after various transformations. Presumably the deployed version is meaningfully different. [0]:https://arxiv.org/html/2510.09263v1 https://arxiv.org/html/2510.09263v1
- echelon 5mo agoThis is very similar to audiowmark https://github.com/swesterfeld/audiowmark https://github.com/swesterfeld/audiowmark You can stuff per-item database unique IDs, user IDs, geohashes, and other nefarious things inside. We need to protest this LOUDLY. Our devices are being locked down, we're having attestation and trusted computing forced on us, the internet all over the world is undergoing age verification with full ID verification. Just because this is on "ai images" today doesn't mean it won't be on all images - screenshots, your camera reel, etc. - in the fullness of time. This is scary. These are the tools of 1984. They've been boiling the water slowly, but in the last year things have really started to pick up pace. Please push back. Loudly. Everyone at Google and OpenAI working on this: WHAT THE FUCK ARE YOU DOING. STOP. We have laws and mechanisms to prevent revenge porn, CSAM, defamation, etc. They are robust and can be made even stronger. We do not need to sacrifice the security of our privacy and our speech to fight imagined harms when the real danger is turning into an authoritarian society.
- Extropy_ 5mo agoMost cameras already produce metadata. You can remove this metadata. Can you not also detect and remove watermarks?
- julianozen 5mo agoWhile these are great, isn’t the problem that malicious actors will create systems that do not use synthID
- nerdsniper 5mo agoIt helps significantly in the current moment. A lot of people are lazy and are getting caught quickly by SynthID. Eventually it won’t matter when image generation is cheap. But few self-host today and few are willing to pay unsubsidized prices, so the vast majority are using the Gemini, OpenAI, and Midjourney. If all 3 adopted SynthID, only a small fraction would use something else.
- deleted 5mo ago[deleted]
- echelon 5mo agoThese systems should be removed. This is antithetical to freedom and privacy. There should be no way for anyone to track down who posted a political meme, anti-religious message, or any other legally protected speech. This will come back to bite us in the ass if we keep building it. Soon every image or communication we make will be watermarked if we continue to let this shit seep into the commons. Everything from your phone photos, to your screenshots, to your social media posts. One day soon Republicans or Democrats or whoever doesn't like your freedoms will use this tech to identify you and control you. There are laws for harms - CSAM, revenge porn, etc. Social media platforms can identify, ban, and report abusers. The framework of the law can take care of the rest. Our digital footprint should not be tracked and barcoded.
- toraway 5mo agoThat's a lot of hyperbole, there's no cause/effect relationship I can think of here that could realistically produce your slippery slope. Google or anyone else could start adding those unique tracking watermarks you're concerned about any time they want, regardless of whether they use this AI detection watermark, that to be clear can not track you in any way.
- WhatIsDukkha 5mo agoThis is just performative nonsense. As someone that creates things with tools with different media I would just hard avoid this tool that adds... arbitrary metadata not of my choosing. Should I seriously make a texture for a videogame with this weird DRM glorp in it? How old is photoshop and why is it exempt?
- ericpruitt 5mo agoJust because something isn't perfect doesn't mean it's not useful. I've already seen posts online that were able to be proven as falsified because someone ran the images through Google for SynthID checks. > How old is photoshop and why is it exempt? For one, it's not developed by Google or OpenAI. The barrier to entry to making realistic but deceptive images with Photoshop is far higher than with AI, and there are already techniques that can, imperfectly, be used to detect the use of traditional image editing.
- WhatIsDukkha 5mo agoSo 999 people that are just making an image need to be DRM'ed so that you might catch the 1 person making "realistic but deceptive" images... like this is some kind of special case of ... internet images.
- space_fountain 5mo agoThis isn't DRM right? This is metadata attached to the image that makes it clear it was synthetically generated. The public has a huge incentive to know when images are AI generated and the harm to legitimate users seems pretty small: aka someone might complain online that you use AI
- WhatIsDukkha 5mo agobillions? of "fake" images not generated by ai but just photoshopped and ... not really harmful. There is no case that any of its particularly harmful outside of things like CSAM which is illegal.
- rickcarlino 5mo agoWhat if they use advanced evasion techniques like printing it out and scanning it or taking a photo with their phone?
- Retr0id 5mo agoSynthID is fairly resistant to this sort of thing, although not perfect.
- saberience 5mo agoWhat happens if you generate an image with only a single pixel color or say two colors?
- SiempreViernes 5mo agoYou waste a lot of compute on overhead?
- akersten 5mo agoThis was done in the past, Google saw it, and now either refuses to generate or doesn't emit the SynthID watermark for those images
- userbinator 5mo agoYou create an image so trivial that no one would care if it was AI-generated or not.
- saberience 4mo agoThat's not really the point. I was wondering at what point of complexity the SynthID watermark is added. I.e. it doesn't make sense for a purely white or black image, but as you gradually add colors or features, at some point they would want to add a watermark, but based on what? It's an interesting question.
- 4ashz 5mo agoFirst they verify whether a picture came from OpenAI, then they'll include subscriber data and geolocation. Well, they'll finally find out that no one wants to look at AI generated pictures or text. Once they do that, the tool will fail for the public and only work for the government.
- Gigachad 5mo agoSeemingly the only use for photo realistic ai generation is deception. We are already seeing AI generated video used in political ads in America.
- himata4113 5mo agoif you tell it to generate the AI image with a black background you can visually see the synthid with a good enough monitor, it's just a repeating fuzzy pattern, nothing special. I have found great success of getting rid of it by masking every 2nd pixel, regenerating missing pixels and then once again masking every 2nd pixel offset by 1. Used an off the shelf model to fill in the pixels, but I also exported a depthmap first (before any alternations) and denoised it so generated masked pixels comform to the original content. The result was obviously not 100% perfect, but with more time and a model fine tuned for this specific use-case would be able to remove any kind of ai watermarking without too many issues.
- tantalor 5mo agoBut why
- teravor 5mo agoi wouldn't have any confidence in being able to remove a 0.5 bit watermark (presence/absence). what you see is probably a functional decoy.
- huflungdung 5mo ago[dead]
- deleted 5mo ago[deleted]
- yorwba 5mo ago
- userbinator 5mo agoCurrently, this article is conveniently right next to it: https://news.ycombinator.com/item?id=48200569 https://news.ycombinator.com/item?id=48200569
- cosmobiosis 5mo agoWell that's not very useful. I think that can easily be hacked and many people were doing that frankly
- mpetrovich 5mo agoSeems inferior to C2PA, which is actually an open standard: https://contentauthenticity.org/ https://contentauthenticity.org/
- progbits 5mo agoCompletely different things. C2PA is basically a signature that serves to prove it came from certain source. It's useful in case you want to prove you got an image from AI model to someone who doesn't believe you. It's trivially removable and not useful against people trying to pass off generated images as real.
- BhaskarDeo 5mo ago[dead]
- sigbeta 5mo agoI think this is a move by openai/google to prevent their own models from training on ai slop rather than some morally righteous public initiative.
- potsandpans 5mo agoWhile this is definitely one of the topics of the moment. I find these threads really just ragebait magnets. A bunch of people effectively talking past one another: privacy vs preserving the status quo. It's certain now that most of the Western world has slid into fascism. Privacy and common decency advocates are all but lost. I will say this, for everyone celebrating this as something that is "extremely beneficial to the cultural moment", If I were an adversarial nation-state actor, I might be extremely interested in reverse engineering this and poisoning the well by applying it to real images. Let's make the world impossible to understand.
- keyle 5mo agoIs it like metadata in mp3? If I take a screenshot of an AI image, will that then be seen as an AI image? Is that 'hidden in the image' or as metadata?
- nojs 5mo agoIt’s in the image, designed to survive those kinds of operations
- 827a 5mo agoInteresting that it seems to be the case that SynthID has been totally busted open, but OpenAI's new watermark has not yet [1] [1] https://github.com/wiltodelta/remove-ai-watermarks https://github.com/wiltodelta/remove-ai-watermarks
- deleted 5mo ago[deleted]
- atleastoptimal 5mo agoEventually this won't matter as open source models will be good enough to fool 99% of people.
- svara 5mo agoI think something like this will need to become ubiquitous, widely supported in software and understood by lay people: https://en.wikipedia.org/wiki/Content_Credentials https://en.wikipedia.org/wiki/Content_Credentials
- myaccountonhn 4mo agoI imagine it'd be more impactful to add attestations to cameras so one can validate that X photo came from Y camera.
- OvervCW 4mo agoUseless because you can use a camera to take a photo of a synthetic image.
- CroviaTrust 4mo ago[flagged]