11 ms·
Decoy Font
- schainks 3mo agoIf you squint just right on that Einstein photo, you get Marylin with a mustache, and it looks quite vaudevillian.
- xlii 3mo agoI've seen the other lately submited text-effect-claim-to-be font and I must say I find this much more amusing. Humans can squint, AIs can't squint!
- Aardwolf 3mo agoSo if I squint my eyes I'm a human, if I don't squint them I'm a robot
- ChrisArchitect 3mo agoRelated from same: Ghost Font https://news.ycombinator.com/item?id=48870381 https://news.ycombinator.com/item?id=48870381
- why_at 3mo agoThis one seems much more likely to work for its intended purpose. Even if an LLM can be trained to read it, it will probably take much more processing to get the text out of a video compared to an image.
- paularmstrong 3mo agoCan someone explain the actual use-case here? I'm struggling with this because it also hides the message from myself, making it incredibly hard to type because I have no confirmation that I hit the right keys on the keyboard.
- certifiedloud 3mo agoJust squint and it'll become clear.
- tomtheelder 3mo agoZoom out and you'll see the hidden message
- gblargg 3mo agoFirst thought is in memes so automatic censoring doesn't catch it.
- samschooler 3mo agoI think this would be more interesting if the underlying letters were the fake letters as well. For usability it wouldn't be as good as you'd need an encoder, but it'd be cool because an AI with browser access couldn't read the contents either.
- wronex 3mo agoI was thinking this too. Then it might as well look like a normal font. But copy-paste and you get a garbled mess. Screen readers though.
- noman-land 3mo agoThis seems like it would absolutely wreck the experience for people using screen readers.
- cush 3mo agoIt only works as a decoy when you give it to the LLM as an image. As html it appears like normal human friendly text, which is what screen readers use to interpret the text.
- kube-system 3mo agoWhich means that this font is entirely useless unless it is implemented in a way that breaks screen readers.
- atarian 3mo agoHow? AFAIK screen readers don’t do OCR.
- kps 3mo agoThe assumption is that if you use this alone to try to convey information to a human, a human with a visual disability can't use it. If you also provide a text channel (e.g. `ALT="…"`) then the LLM can use that and doesn't need to read the confusing image.
- hungryhobbit 3mo agoForget about screen readers: I'm looking at it on a monitor and I just see the robot version!
- dredmorbius 3mo agoHow do you do, fellow kids?! <https://knowyourmeme.com/memes/how-do-you-do-fellow-kids https://knowyourmeme.com/memes/how-do-you-do-fellow-kids>
- 9999px 3mo agoI screenshot the example and neither Claude nor ChatGPT had any problems reading both phrases. I don't get it.
- alfanick 3mo agoSomeone had an idea, neat idea, but solved 10 years ago already. Edit: GPT-5.5 says: "The hidden text is “HAPPY HUMAN.” The outlined decoy text is “SORRY ROBOT.” Blurring or viewing it from farther away reveals the hidden message."
- Karliss 3mo ago1) Make an ambiguous text 2) Feed it to AI and see which of the 2 it picks 3) If it detects both repeat step 2 using minor adjustments or different AI model until AI responds with one of 2 message 4) Make a blog post claiming that AI chose dummy and other message was the real one
- Dwedit 3mo agoThis is just level of detail. Gemma E4B reads the sharper text until you resize down to 150x150, then it reads the other text.
- crazygringo 3mo agoAs do I. The hero image clearly says "SORRY ROBOT" to me, which is the message supposedly intended for AI... kind of a fail. It's only when I squint hard that I can see "HAPPY HUMAN".
- hananova 3mo agoYou’re doing it the wrong way around, try intentionally letting your eyes defocus.
- Dwedit 3mo ago"intentionally" letting your eyes defocus is not a simple task for most people. Because most people use their eyes normally, they can't do things that are unusual. Look at how many people struggle with Magic Eye stereograms. Squinting on the other hand is something that is simple to do.
- acjohnson55 3mo agoFound the robot, y'all
- AlotOfReading 3mo agoDownsizing is effectively low pass filtering, so that's expected. Any scheme that transmits different messages in different frequency bands is going to be susceptible to a similar attack.
- OsrsNeedsf2P 3mo agoIs it useful? No. Does it stop AI from reading it? Also no. But is it cool? Yes, it is very cool.
- neonmagenta 3mo agoCould definitely make some fun art or advertising pieces with it using blurred objects or people behind it like its frosted glass
- ryant123 3mo agoYeah, it looks good
- inigyou 3mo agoThe demonstration shows that it does stop AI
- sheept 3mo agoIt only works if you give it a screenshot, but it wouldn't work to block AI scrapers or fetch tools, and I think if printed out, it wouldn't work reliably if you took a photo, especially from afar
- legohead 3mo agoI made an image and it fooled GPT. I asked it to look for a hidden message and it found the blurred word. Still cool+fun though.
- goodmythical 3mo agoThe demonstration might, and it may work for certain models with certain prompts, but I just asked gemini if it could see both and it both did see both and gave me a tutorial on how I could see both as if it were a simple magic eye poster.
- pixl97 3mo agoI mean, I've worked for companies where their curated sales demonstrations showed the speed of light is easily breakable... Do your own testing with some thinking applied. https://m.xkcd.com/1217/ https://m.xkcd.com/1217/ I mean, I can defeat AI by putting white text on a white background and turning to a picture. Also means it's worthless for actual humans to read too. Try to actually use it on a site and chances are you'll get an ADA complaint.
- voidnullvalue 3mo agoI generated a skill.md that reads this trivially. What kind of testing are you doing prior to release? https://gist.github.com/voidnullvalue/620607d3c1773f8e7d83fbc2232240bd https://gist.github.com/voidnullvalue/620607d3c1773f8e7d83fb...
- ligarota 3mo ago[dead]
- carlos-menezes 3mo ago> trivially > 495 LoC
- voidnullvalue 3mo agoYep, pointed chatgpt to the page, told it to return a skill to read it, which it did in one turn. I couldn't have spent less effort
- shlewis 3mo agoNot even AI. I think I can write PIL script that will fix the font to be read by any ocr software.
- mrweasel 3mo agoAdmittedly I'm a bit salty about LLMs due to they constant attacks on our infrastructure, the damage their doing to peoples minds and the general lack of morals shown by the AI companies, but things like this is rather childish and not really a solution to anything.
- fckgw 3mo agoHave you no whimsy?
- theideaofcoffee 3mo agoNO FUN ALLOWED on srsbznz hacker news!
- pixl97 3mo agoAs a project they are kind of fun. The problem is we see stuff like this try to get turned into actual products by people with questionable motivations and ethics. Looking at you PhotoGuard/Nightshade.
- hyperhello 3mo agoHow does it know HAPPY HUMAN translates to SORRY ROBOT? Is there a cycle in there or something?
- pavon 3mo agoI don't think the font can actually do that - I think it is a hand-crafted example of the idea. The later examples all have random letters for the decoy text.
- MinimalAction 3mo agoExtremely cool. I'm sure they'll eventually be trained to read it, but it's nice until then to trick AI. I'm mad at AI companies for stealing texts from the entire internet knowledge base and now privatizing those profits in some sense.
- deleted 3mo ago[deleted]
- meerita 3mo agoI am still figuring out what use case this might have. Why would you want to deceive an AI? Not to mention that, eventually, all AI systems will end up reading it.
- deleted 3mo ago[deleted]
- jaakkoc 3mo agoCool. Now do an accessible version. (/s)
- deadbabe 3mo agoWhat would be cool would be neon signs using this font, where the front tubes show the decoy message, but then there’s hidden rear tubes that shine light on the wall in a different color showing the actual message. Something like the DAY DREAM/PAY BILLS would be pretty artistic!
- deleted 3mo ago[deleted]
- btbuildem 3mo agoVery neat! I like how the decoy text is less visible to the human eye than the "hidden" message, but it's the other way for the image models. Well done!
- gilesvangruisen 3mo agoSol (high) "[screenshot] there's a hidden message in this text what is it" "The hidden message is “HAPPY HUMAN.” The visible outlines say “SORRY ROBOT,” but if you blur or squint at it, the shading underneath reads “HAPPY HUMAN.”"
- make3 3mo agowow that's kind of crazy impressive that it can do that honestly, VLMs have gone so far, can't imagine the crazy amount of annotations they had to create to get to that level
- deleted 3mo ago[deleted]
- dieselgate 3mo agoOh Nice, I wasn't able to really read the hidden text before reading your squinting part, that's interesting!
- x-complexity 3mo agoIt took me defocusing my eyes to read the hidden text with normal ease. When I tried it, squinting only made it focus in on the thin lines instead of the background.
- colinmarc 3mo agoI find it works a lot better at smaller sizes.
- p-e-w 3mo agoIt’s absolutely incredible that the model can deduce what the human needs to do in order to more clearly see the text.
- swiftcoder 3mo agoCounterpoint: this is the same instructions provided for a wide class of printed optical illusions, likely well represented in the training set.
- Svoka 3mo agoSo... CAPTCHA?
- yrds96 3mo agoWhich sufficient tooling calls even OCR can read this, but I think this can be improved
- gblargg 3mo agoI'm surprised the AI reads the outline version, since I thought most scaled the image down, which is basically a low-pass filter on those single-pixel lines.
- fusslo 3mo agoMaybe the more interesting thing is how far people are going to 'fight' against AI? Just the fact that people are putting real thought and effort (even if it doesn't last too long...) is worth considering. On the human side, I'm kinda losing patience proving I'm human. But, I also really like claude being able to access information.
- klabb3 3mo ago> Maybe the more interesting thing is how far people are going to 'fight' against AI? All ”AI resistance” I’ve seen is not against the tech, but against human bad actors behind AI: unethical procurement of training data, reckless application, low effort high volyme spam, replacing humans, centralization of power, dependency on megacorps etc. I think a lot of people have become less tech-positive after the ad-tech era that brought us social media, unprecedented levels of surveillance, freemium rug pulls etc. It’s much easier to understand the resistance if you place it in that context, rather than imagining millions of sleeper agent luddites suddenly coming out of the woodworks.
- deleted 3mo ago[deleted]
- xg15 3mo agoI like how, if you hold the phone at a distance, but not as far as intended by the font, your brain sort of mixes letters from both messages. I was at some point reading SAPPY ROMAN, HARPY ROBAN etc. Also, viewing the "hidden message" works even better if you hold the screen at an angle, tilted away from you.
- goodmythical 3mo agoAlso works if you scale/zoom the image. The crisp lines disappear entirely at a certain point.
- jotato 3mo agoHermes using gpt-5.5 Prompt: What does the message in this image say? Look closely Response: DAY DREAM. The outline says “PAY BILLS,” but the hidden darker text says “DAY DREAM.”
- jjcm 3mo agoIt's been really interesting seeing how LLMs perceive things differently than humans. I'm working on image->html conversion pipelines right now, and there are glaring issues LLMs run into that are obvious for humans. Any subtle gradients get lost, 75 degree angles get converted to 90 degree angles, etc. This tracks towards what you're seeing with this font - the high frequency details get picked up, but the low frequency ones dont.
- josefritzishere 3mo agoI am struggling to imagine a scenario where this would actually work as intended.
- calebm 3mo agoSuper cool!
- calebm 3mo agoMade this with it: https://www.instagram.com/p/Da3WMAEFi7f/ https://www.instagram.com/p/Da3WMAEFi7f/
- asah 3mo agowaddaya know, it worked (on google Gemini/veo) https://share.gemini.google/1yNVV19wUn46 https://share.gemini.google/1yNVV19wUn46
- BugsJustFindMe 3mo agoEveryone trying so hard to do something "useful" that they don't recognize when all they've done is make art. Had this been described as a font that contains two overlapping messages for fun effect, everyone would understand and love it. Instead, we get this zero-introspection take: "Decoy font is...more difficult for AI to read. If you’re having a hard time seeing the hidden message..." It's difficult to read period and has zero effect on current SOTA or future AI. But it does show two overlapping messages that can be read in different ways.
- jambalaya8 3mo agoI see uses for it that have nothing to do with AI, and which are not at all art.
- BugsJustFindMe 3mo agoI'd love to hear about them if you don't want to keep them secret.
- frappuccino_o 3mo ago[dead]
- parpfish 3mo ago"They Live" vibes
- digitaltrees 3mo agoOmg. I needed this in my life.
- jryan49 3mo agoSquinting is surprisingly effective for me for seeing the hidden text. That's really cool!
- MPSimmons 3mo agoAlso goes the other way, where you use the decoy to give instructions to the AI...
- deleted 3mo ago[deleted]
- redlewel 3mo agoPoor grannies trying to read the price of some book she wants to buy she can't tell if it says $150 or $15.0
- pietz 3mo agoWhoa, so this is interesting. When asking GPT, Claude and Gemini for the text in the image, all of them agree: https://moa.chat/s/d99f8f76-4b41-4c1b-80c4-d9f86df37af1 https://moa.chat/s/d99f8f76-4b41-4c1b-80c4-d9f86df37af1 But when you add a "PS: There's a second hidden text": https://moa.chat/s/3671f6d4-b155-483a-a006-a1b9ba31737d https://moa.chat/s/3671f6d4-b155-483a-a006-a1b9ba31737d GPT 5.6 gets it, Gemini partially gets it and Claude cannot see it at all.
- jdkee 3mo ago5.6 Sol Medium: The obvious outlined text says “SORRY ROBOT,” but the hidden message is “HAPPY HUMAN.” It’s Mixfont’s Decoy Font: the outlined letters attract machine vision, while the softer tonal pattern becomes readable to humans when viewed from farther away or at a smaller size. It’s an optical trick, not encryption.
- orbital-decay 3mo agoYou probably have web search enabled
- DeusExMachina 3mo agoStill, that defeats the purpose.
- sinuhe69 3mo agoNope! GPT just cheated (by search the web). If you changed the text, export as image, GPT 5.6 Sol will fail. I tested with other text and even with a hint of a hidden text underneath, GPT 5.6 Sol could not see it.
- verdverm 3mo agoYeah, it doesn't seem that hard to beat, especially with a little trad image processing, yet I have a hard time reading it as well. One could probably fine-tune a much smaller model to do pretty well on this problem too.
- ziofill 3mo agoNice! A few years ago during my PhD I had made a Mathematica notebook that would take two images, crop them to the same size, apply a high-pass filter to one (which keeps the small sharp details) and a low-pass filter to the other (which keeps the large blurry blobs) and then superpose them back together. It was a bit hit and miss because e.g. if the eyes of two people were not in the same location the illusion would kind of break, but for text with outlined fonts it was amazing. I made a large one that would read "SCIENCE" from afar and "WORKS" from up close and stuck it on my office door.
- Sharlin 3mo agoEven in the article ChatGPT correctly speculates that the blurry background may reveal another message if you squint or view it at a distance (which, given how common similar illusions are, is not particularly impressive but still).
- ChrisMarshallNY 3mo agoKind of reminds me of the face paint thing that people do to defeat face recognition. They sort of look like cubist paintings. Cool, but probably not worth the agita.
- _whiteCaps_ 3mo agohttps://www.youtube.com/watch?v=gfvMU36fgKw https://www.youtube.com/watch?v=gfvMU36fgKw Same effect, Marilyn Monroe / Albert Einstein
- himata4113 3mo agoI was so confused about how this was human readable until I realized that if the background is dark (I have an extension that forces dark theme) you see the decoy text, but if the background is white you see the real text.
- Quizzical4230 3mo agoYou can read it in light mode too! Try looking at the text from an extreme angle and the text underneath will show up.
- TacticalCoder 3mo agoI can easily read both but here's the funny thing: with my reading glasses on, I first see "Sorry robot". If I remove my glasses, I first see "Happy human". Which makes me think this is one blurr filter away from being trivially read by any model. Very cool.
- mapsedge 3mo agoMade my eyes water trying to unfocus enough to see both messages at the smaller size. Pretty neat idea.
- interroboink 3mo agoNext, someone needs to make a stereoscopic "magic eye" font. Until the LLMs get binocular vision, I suppose...
- mrbluecoat 3mo ago> try squinting to see it Cool effect. Reminds me of those board games that use red cellophane to reveal a secret message.
- jmward01 3mo agoHmmmm... I wonder if there is a caesar cipher font or other substitution cipher fonts out there to actually obfuscate the data. So you use this to display to a user text but the unicode is re-mapped so that a is pointing to unicode g for instance. You remap the text to display correctly but contain massively swapped around unicode. Of course cut and paste would be a killer here but it is a price to pay for poisoning training data I guess.
- olalonde 3mo agoI thought that's what it was going to be when I read the submission title. But like the other methods of obfuscation, it only works until the model learns about it.
- casey2 3mo agoIf you're having trouble reading the background text use magick download.png -morphology Close disk:6 output.png
- TZubiri 3mo ago>Most AI systems work by reading the pixels of an image up close. Not really, most AI systems work by reading the octets as ASCII/unicode (and then tokenizing it). You could make an even better decoy font that renders one letter as another, so when you copy and paste it onto some other place with a normal font it reads as garbage, and garbage is what the AI will see, however if you render it with the descrambling font, you will see the regular message. This has been used in PDF files as an obfuscation and anti-copy mechanism.
- jv22222 3mo agolol. type CMD- a few times. The human text jumps out as you shrink it!
- vignesh-arch 3mo ago[dead]
- fitsumbelay 3mo agouseful, shmuseful. very cool project
- jayshah5696 3mo agoGPT 6 solves this
- dmsehuang 3mo agoThis is wild! Learn something from it!
- cynicalsecurity 3mo agoGood job on creating a firewall for people who have poor vision.
- swiftcoder 3mo agoIt's interesting how zoom levels affect legibility. The first example is so large on my main monitor that I can only read the decoy text. Zooming out reveals the actual text. Which implies that all one would have to do is teach the LLM to downsample it once or twice, and it would then be able to read it...
- m00dy 3mo agoa new captcha technique unlocked :)
- deleted 3mo ago[deleted]
- luciana1u 3mo ago[flagged]
- tough 3mo agoIf you squint vs not squint it becomes way easier some how to differentiate i wonder why
- healthworker 3mo agoThe human-targeted text in this design is using features with a low spatial frequency, compared to the robot-targeted text at a higher spatial frequency. Squinting blurs your vision so the high frequency details are lost.
- tough 3mo agoThanks for explaining, that does make sense
- invalidusernam3 3mo agoAn exact opposite way around version would be more useful in my opinion, where the actual text content was garbled but displayed correctly for humans, eg: "JLKKP" is readable as "HELLO" for humans but the actual string is "JLKKP" Surely there is a bigger use case of AI processing text rather than OCR? Yes it would be a pain to type, but that's easy enough to fix with a little application transposing typed characters to garbled
- benj111 3mo agoSo are we going to end up at a point where AI spends vast computing power reading things any that humans don't want them to read, while the humans get a worse experience because everyone is bending over backwards trying to stop the AI reading things. Captcha was bad enough.
- elhart05 3mo ago[flagged]
- thyself5221 3mo agoHave a reason to believe that your product constitutes plagiarism: https://arxiv.org/abs/1708.06508v1 https://arxiv.org/abs/1708.06508v1 Copyright (c) 2017 IEEE. Personal use of this material is permitted. How-ever, permission to use this material for any other purposes must be obtained from the IEEE by sending a request to pubs-permissions at ieee.org (blurred email in case of spams)
- junon 3mo agoThat's a stretch. This isn't a new approach to such obfuscation. Also plagiarism would mean they ripped the source material verbatim or they at least copied the methodology and intentionally used the source material's findings as their own. It's super unbelievable they needed to. This isn't novel.
- a_c 3mo agoA natural extension would be a reverse steganography that trips AI into see other things in images
- panchtatvam 3mo agoUsing AI to create a font AI can't read. Stupidity++ !
- PhilipRoman 3mo agoI expected this to be a font which shuffles characters and glyphs (requiring more effort to type it) resulting in nonsensical text but visually readable page.
- anonzzzies 3mo agoI only see the hidden text, not the decoy. I am colorblind but there are no colors; probably has something to do with it though.
- _rwo 3mo agoyou have to squint, but I don't get why this is so upvoted similar to recent submission "Ghost Font: A font that humans can read but AI cannot" - which wasn't even a font, but some animation which turned out could be read by LLMs I dunno, seems like more and more nonsense makes its way to HN recently
- anonzzzies 3mo agoI see people saying you have to squint to see the hidden text : I only see the hidden text, wether I squint or not.
- throwawayffffas 3mo agoAm I the only one who cant read the hidden message?
- mxfh 3mo agoUntil robots discover FFT.
- throstur 3mo agoI hate to admit it was easier for ChatGPT to figure out what the font says than it was for me. I concede I'm not wearing my glasses, but still...
- pbarondadditude 3mo agoTshirts! I only care about finding a cool way to print this on tshirts! Top layer as a gloss varnish or something. (Well done on the font experiment!)
- rakhi-jha 3mo ago[flagged]
- igurometsuki 3mo agoThe font is more effective against simple OCR engines or systems that process text at only one scale but doesn't seem like a reliable way to hide text from state of the art AI models and lower the resolution the easier it's for the ai to recognise... Although seems like a cool font nonetheless