Live data from Hacker News

Reverse engineering Gemini's SynthID detection

github.com

11–20 of 66 posts

Re: Reverse engineering Gemini's SynthID detection

#14

Ok i get that eventually someone was gonna do this but why would we want to purposely remove one of the only ways of detecting if an image is ai generated or not...?

It was always going to be available to some people, but not everyone would know or believe that. Now they will.

Re: Reverse engineering Gemini's SynthID detection

#15

Ok i get that eventually someone was gonna do this but why would we want to purposely remove one of the only ways of detecting if an image is ai generated or not...?

Uh... you can do this pretty easily since day 1. Just use Stable Diffusion with a low denoising strength. This repo presents an even less destructive way[0], but it has always been very easy to hide that an image is generated by Nano Banana.

[0]: if it does what it claims to do. I didn't verify. Given how much AI writing in the README my hunch is that this doesn't work better than simple denoising.

Re: Reverse engineering Gemini's SynthID detection

#16
post #4

> We're actively collecting pure black and pure white images generated by Nano Banana Pro to improve multi-resolution watermark extraction. Oh hey, neat. I mentioned this specific method of extracting SynthID a while back.[1] Glad to see someone take it up. [1]: https://news.ycombinator.com/item?id=47169146#47169767

FWIW, I had Nano Banana create pure white/black images in February, and there was no recognizable watermark in them (all pixels really were #ffffff / #000000 IIRC). Meta: your comment was marked [dead], like a few other constructive comments I saw in recent days. Not sure why.

I suspect they strip the SynthID for these specific cases to prevent exfiltration of the steganography.

I appreciate you pointing it out, but this account is banned. Thank you for vouching though!

Re: Reverse engineering Gemini's SynthID detection

#17

It says not to use these tools to misrepresent AI-generated content as human-created. But the project is a watermark removal tool with a pip-installable CLI and strength settings named "aggressive" and "maximum." Calling this research while shipping turnkey watermark stripping is trying to have it both ways in a way that's uncomfortable to read. The README itself reads like unedited AI output with several layers of h…

Agreed. This isn't punk this just helps the bad guys. Society needs to know what content is AI generated and what is not.

This was never going to be a reliable way to do it. It's basically the evil bit . It only works for as long as everyone is making a good-faith effort to follow the convention. But the bad guys do not do that.

Re: Reverse engineering Gemini's SynthID detection

#18

It says not to use these tools to misrepresent AI-generated content as human-created. But the project is a watermark removal tool with a pip-installable CLI and strength settings named "aggressive" and "maximum." Calling this research while shipping turnkey watermark stripping is trying to have it both ways in a way that's uncomfortable to read. The README itself reads like unedited AI output with several layers of h…

Agreed. This isn't punk this just helps the bad guys. Society needs to know what content is AI generated and what is not.

It really doesn't need such capability. Nor does it need the capability to know what human generated it either.

Re: Reverse engineering Gemini's SynthID detection

#20

I don't understand all the handwringing. If it's this easy to remove SynthID from an AI-generated image then it wasn't a good solution in the first place.

Yes. This kind of project needs aggressive red teaming, it leads to better products and we need excellent products in this space.

This project proves what red teaming was in place wasn't good enough.

Post reply on HN