Live data from Hacker News

OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

openai.com

181–190 of 198 posts

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#181
post #122

Earlier quoted context omitted.

It’s definitely hackable, Some of our engineers worked on this long time ago https://deepwalker.xyz/blog/bypassing-synthid-in-gemini-phot...

I'm shocked that someone would write a blog post like this in which they openly admit to something that is widely understood to be fraud. Even if I'm sympathetic to why this individual chose to do this, and the technical side is interesting, I think the decision to just publicly tell a story in which you criminally defraud the villain is not a choice I'd ever make.

It appears that this company already does fraud so they're most likely comfortable with fraud. It seems normal in isolation, but from an outside lense it's crazy.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#182
post #179
post #177

Earlier quoted context omitted.

"image recitation block" means they are blocking generation of images that already exist in their database (training data).

Just to confirm, what this means is that the training data contains one or multiple pitch black images, and their system is refusing to reproduce them verbatim?

no insider knowledge here. my assumption is that the image hash matches a training data image. "all black" is a pretty easy hash to match.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#183

Earlier quoted context omitted.

I'm shocked that someone would write a blog post like this in which they openly admit to something that is widely understood to be fraud. Even if I'm sympathetic to why this individual chose to do this, and the technical side is interesting, I think the decision to just publicly tell a story in which you criminally defraud the villain is not a choice I'd ever make.

It appears that this company already does fraud so they're most likely comfortable with fraud. It seems normal in isolation, but from an outside lense it's crazy.

Sorry, but what you’re saying goes beyond the kind of free expression I would respect. Can you tell us what fraud you believe we’re committing, under what law, and based on what evidence?

This blog post clearly shows that Deepwalker can break SynthID, which is a closed-source watermarking system.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#184

Earlier quoted context omitted.

You are asserting that the existence of metadata in other venues to be proof that this form of watermarking metadata is just fine with you and should be for everyone else because... nope don't see any reason listed here. I have an IP address so therefore this is all fine? "Every accusation is a confession" also seems like an insinuation that I have something to hide but you have "nothing to hide, nothing to fear"ie t…

Lmao you don’t have to use these AI image tools then, it’s not that hard

Lmao I said that in my original post, lmao not that hard to read.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#185

This is just performative nonsense. As someone that creates things with tools with different media I would just hard avoid this tool that adds... arbitrary metadata not of my choosing. Should I seriously make a texture for a videogame with this weird DRM glorp in it? How old is photoshop and why is it exempt?

NO OFFENSE - I think this is genuinely worth digging down that: - you identify as an artist of sorts, - you can't tell AI from human images, and - you sound absolutely pissed off by this. In my personal experience watching online flamewars, there seem to be two types of people when it comes to AI, even among highly tech literate, which are: - those who can tell that an image was AI generated, instantly, even at thumb…

I don't actually care about AI images?

Most people put so little effort into prompting them that they come out statistically "average" which makes them blatantly ugly.

Most of them are pretty bad just like 90% of everything is bad. Humans create bad art all day long too.

I gave a specific example of a making a texture for a videogame? How does that change what you actually said to me very specifically despite maybe not reading what I said?

To the extent that I'm upset its at peoples capitulation at this DRM nonsense over being overly reactive to ... internet images which dont matter.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#186
post #174

Earlier quoted context omitted.

Idk, wasn't there a survey by Scott Alexander or Aella or something which showed that people aren't reliably able to distinguish AI generated images from human paintings? Not that some people suck at it, but that it's not really possible in any statistically significant way, with a curated set of images. ie. you would fail too.

That[1] used a hand picked set of ambiguous images and still got 60% overall accuracy across 11k participants. I don't know much about statistics[2], but 1) 60% HAS to be statistically significant, and it was 2) under ADVERSARIAL, not neutral, condition. So people can tell. Anyways, that's besides my point. The point of mine is that, it always turn into all-caps flamewars like this, with no middle ground or third cam…

Hmm yes, I had it backwards. I agree this is very statistically significant, but the effect size is tiny. Up from random chance to a mere 60%, means that Scott proved with high statistical significant that people reliably cannot tell.

Also I'm not that worried about the adversarial conditions, any real life conditions are likely adversarial in the relevant sense. No one is one-shotting generation and serving you that, obviously output has been selected for quality. I would call Scott's test not adversarial, but fair.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#187
post #183

Earlier quoted context omitted.

It appears that this company already does fraud so they're most likely comfortable with fraud. It seems normal in isolation, but from an outside lense it's crazy.

Sorry, but what you’re saying goes beyond the kind of free expression I would respect. Can you tell us what fraud you believe we’re committing, under what law, and based on what evidence? This blog post clearly shows that Deepwalker can break SynthID, which is a closed-source watermarking system.

Its the framing story that implies them committing fraud.

> I immediately said yes, even though I wasn't entirely sure. They wanted to play games, so I decided to play along.

The article never says the generated images were used to make a fraudulent claim, but its implied by the juxtaposition.

A few words to indicate that the challenge to break SynthID was for their own amusement would break this implication.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#188

if you tell it to generate the AI image with a black background you can visually see the synthid with a good enough monitor, it's just a repeating fuzzy pattern, nothing special. I have found great success of getting rid of it by masking every 2nd pixel, regenerating missing pixels and then once again masking every 2nd pixel offset by 1. Used an off the shelf model to fill in the pixels, but I also exported a depthma…

So it actually affects the quality of the image. Well, that sucks.

a model trained specifically for this would not have accuracy loss ~99% identical if I had to guess I got to around 85%.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#189

Earlier quoted context omitted.

Perhaps bother to read what you linked before being snarky? > They are not complete DRM mechanisms in their own right, but are used as part of a system for copyright enforcement ... Because watermarks in and of themselves are not, in fact, DRM. Even if I agree that their mass adoption by BigTech is a really bad sign for personal privacy and (eventually) freedom.

Yes I did read it years ago and again today? If you read my original point you'd see I said "weird DRM glorp" which you and other have tried, and failed to only closely parse "DRM" so that you could nitpick poorly. It is integral and part of DRM systems and certainly "weird DRM glorp" for an actual close reader. DRM is not just "I cant watch X movie because DRM" even if that is the statistically prevalent understandi…

Watermarking might be a necessary part of DRM but it is not sufficient. As a trivial example, you could watermark someone else’s IP but the watermark would not make it yours.

Fundamentally SynthID is not Digital Rights Management because it is not being used for OpenAI or Google to exercise a digital right on the images.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#190
post #183

Earlier quoted context omitted.

It appears that this company already does fraud so they're most likely comfortable with fraud. It seems normal in isolation, but from an outside lense it's crazy.

Sorry, but what you’re saying goes beyond the kind of free expression I would respect. Can you tell us what fraud you believe we’re committing, under what law, and based on what evidence? This blog post clearly shows that Deepwalker can break SynthID, which is a closed-source watermarking system.

I mean it's on your own page: https://deepwalker.xyz/use-cases, while not particulary 'fraud', it's definitely in the grey area of what is allowed and definitely breaks ToS.

I guess it would be more accurate to say that it enables fraud. It's the same way proxy companies advertise themselves as "validation and data gathering" when in real-world use they're used for botting, ad farms, spamming engagement etc.

Post reply on HN