Live data from Hacker News

OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

openai.com

151–160 of 198 posts

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#151
post #137

Earlier quoted context omitted.

billions? of "fake" images not generated by ai but just photoshopped and ... not really harmful. There is no case that any of its particularly harmful outside of things like CSAM which is illegal.

Have you looked at twitter or Facebook and seen the swaths of our population that are just fully believing fake AI slop about politics, crime, etc?

Most of those people wont be checking the provenance of the images. FB have stopped from their fact-checking processes.

Only the investigative or journalistically inclined will make use of this, and those people already fact check.

Where’s the en mass gain?

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#153
post #122

if you tell it to generate the AI image with a black background you can visually see the synthid with a good enough monitor, it's just a repeating fuzzy pattern, nothing special. I have found great success of getting rid of it by masking every 2nd pixel, regenerating missing pixels and then once again masking every 2nd pixel offset by 1. Used an off the shelf model to fill in the pixels, but I also exported a depthma…

It’s definitely hackable, Some of our engineers worked on this long time ago https://deepwalker.xyz/blog/bypassing-synthid-in-gemini-phot...

it would be nice to show an amplified pixelwise difference between the before and after images

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#154
post #147
post #77

Earlier quoted context omitted.

i wouldn't have any confidence in being able to remove a 0.5 bit watermark (presence/absence). what you see is probably a functional decoy.

You can use the verification tool to check whether the watermark is still detectable and iterate until you successfully removed it . Of course if you need to regenerate the image with an unwatermarked image-generation model to remove it, it more or less still serves its purpose.

How confident are you that the verification tool detects all of the watermark, and not just one layer?

I would layer two watermarks and let the public remove the most visible one.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#156

Earlier quoted context omitted.

The point of SynthID is to make generated images identifiable, in an attempt to prevent 1984-esque situations where you can't believe your eyes and ears. Applying it to screenshots and camera output defeats its only purpose. If the powers-that-be want to enforce age verification, watermarking camera output is not the correct technology to do so. It would be something like HDCP, where camera manufacturers are given ke…

You have missed the point by such a wide margin that I have to wonder if it wasn't intentional. The same techniques used here can be applied in other domains for other purposes. That would not "defeat its only purpose". The danger is the normalization of watermarking for [ insert good reason here ] with regulation eventually making it mandatory once everyone is accustomed to it. Rinse and repeat to gradually boil the…

you're the one missing the point: why would this technique be used for any of those? the comment you're replying to describes both the incentives to not do that and existing technology that would be more effective for what you imagine

and yeah exactly printers already watermark, why would they need synthid

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#157

Earlier quoted context omitted.

Well the person I replied to seems to think it'll be at least semi-effective.

How effective something is as an authoritarian tool (or whatever arbitrary purpose) can be (and very often is) completely unrelated to its effectiveness for some other unrelated purpose. It isn't clear to me why even highly effective AI image watermarks would be better than zero watermarks given what I pointed out about local models.

[deleted]

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#158
post #103

Earlier quoted context omitted.

This isn't DRM right? This is metadata attached to the image that makes it clear it was synthetically generated. The public has a huge incentive to know when images are AI generated and the harm to legitimate users seems pretty small: aka someone might complain online that you use AI

Not yet, but it is easy to imagine many ways it would be used for DRM.

is it though?

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#159

Earlier quoted context omitted.

Perhaps bother to read what you linked before being snarky? > They are not complete DRM mechanisms in their own right, but are used as part of a system for copyright enforcement ... Because watermarks in and of themselves are not, in fact, DRM. Even if I agree that their mass adoption by BigTech is a really bad sign for personal privacy and (eventually) freedom.

Yes I did read it years ago and again today? If you read my original point you'd see I said "weird DRM glorp" which you and other have tried, and failed to only closely parse "DRM" so that you could nitpick poorly. It is integral and part of DRM systems and certainly "weird DRM glorp" for an actual close reader. DRM is not just "I cant watch X movie because DRM" even if that is the statistically prevalent understandi…

encryption is DRM!!!1!1!1

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#160

What happens if you generate an image with only a single pixel color or say two colors?

You create an image so trivial that no one would care if it was AI-generated or not.

That's not really the point. I was wondering at what point of complexity the SynthID watermark is added.

I.e. it doesn't make sense for a purely white or black image, but as you gradually add colors or features, at some point they would want to add a watermark, but based on what? It's an interesting question.

Post reply on HN