Live data from Hacker News

OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

openai.com

131–140 of 198 posts

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#134

if you tell it to generate the AI image with a black background you can visually see the synthid with a good enough monitor, it's just a repeating fuzzy pattern, nothing special. I have found great success of getting rid of it by masking every 2nd pixel, regenerating missing pixels and then once again masking every 2nd pixel offset by 1. Used an off the shelf model to fill in the pixels, but I also exported a depthma…

Can an image just be stretched or compressed a very tiny bit?

[deleted]

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#136
post #77

if you tell it to generate the AI image with a black background you can visually see the synthid with a good enough monitor, it's just a repeating fuzzy pattern, nothing special. I have found great success of getting rid of it by masking every 2nd pixel, regenerating missing pixels and then once again masking every 2nd pixel offset by 1. Used an off the shelf model to fill in the pixels, but I also exported a depthma…

i wouldn't have any confidence in being able to remove a 0.5 bit watermark (presence/absence). what you see is probably a functional decoy.

[deleted]

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#137

Earlier quoted context omitted.

This isn't DRM right? This is metadata attached to the image that makes it clear it was synthetically generated. The public has a huge incentive to know when images are AI generated and the harm to legitimate users seems pretty small: aka someone might complain online that you use AI

billions? of "fake" images not generated by ai but just photoshopped and ... not really harmful. There is no case that any of its particularly harmful outside of things like CSAM which is illegal.

Have you looked at twitter or Facebook and seen the swaths of our population that are just fully believing fake AI slop about politics, crime, etc?

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#138

Seems inferior to C2PA, which is actually an open standard: https://contentauthenticity.org/

Completely different things.

C2PA is basically a signature that serves to prove it came from certain source.

It's useful in case you want to prove you got an image from AI model to someone who doesn't believe you.

It's trivially removable and not useful against people trying to pass off generated images as real.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#139
post #122

if you tell it to generate the AI image with a black background you can visually see the synthid with a good enough monitor, it's just a repeating fuzzy pattern, nothing special. I have found great success of getting rid of it by masking every 2nd pixel, regenerating missing pixels and then once again masking every 2nd pixel offset by 1. Used an off the shelf model to fill in the pixels, but I also exported a depthma…

It’s definitely hackable, Some of our engineers worked on this long time ago https://deepwalker.xyz/blog/bypassing-synthid-in-gemini-phot...

Conducting insurance fraud? What a usecase.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#140
post #86

Earlier quoted context omitted.

I guarantee this works poorly, at best. If this actually works solidly, Google is in deep, deep, deep shit. It would mean that I can put a mark on my non-AI videos and demand that Google not allow upload of my identifiably copyrighted content. This would completely obliterate YouTube.

No, it wouldn't. ContentID is already used by Google for that exact purpose. They appear to be fully in favor of enforcing IP law provided the owning party raises a complaint.

ContentID is generated internally by Google and you have to qualify (aka be able to threaten Google with lawyers) in order to effectively participate. It also seems to be defeatable by such advanced techniques as flipping the video left to right.

If SynthID works, this would allow people to tag their own videos with a watermark that is invariant across various levels of compression and editing. It would enable automated scanning of YouTube videos for uploads and the consequent class-action lawsuits.

Because of that, I can fairly confidently say that this doesn't work. However, it will function to divert some attention for a while. And that's what Google and OpenAI intended in the first place.

Post reply on HN