Live data from Hacker News

Reverse engineering Gemini's SynthID detection

github.com

51–60 of 66 posts

Re: Reverse engineering Gemini's SynthID detection

#51

Earlier quoted context omitted.

Fundamentally it's a fuzzy signal and people shouldn't rely on it. The general public does not understand Boolean logic (oh, so the SynthID is not there, therefore this image is real). The sooner AI watermarking faces its deserved farcical demise the better. Also something about how AI is not special and we haven't added or needed invisible watermarks for other ways media can be manipulated deceptively since time imm…

I’m not very well read on the topic and you seen to take a strong “con” stance. Curious to hear why you think it deserves such a demise

[deleted]

Re: Reverse engineering Gemini's SynthID detection

#52
post #4

> We're actively collecting pure black and pure white images generated by Nano Banana Pro to improve multi-resolution watermark extraction. Oh hey, neat. I mentioned this specific method of extracting SynthID a while back.[1] Glad to see someone take it up. [1]: https://news.ycombinator.com/item?id=47169146#47169767

FWIW, I had Nano Banana create pure white/black images in February, and there was no recognizable watermark in them (all pixels really were #ffffff / #000000 IIRC). Meta: your comment was marked [dead], like a few other constructive comments I saw in recent days. Not sure why.

I tried it with Nano Banana 2 through the API just now, and it was content filtering me on both white and black images.

Re: Reverse engineering Gemini's SynthID detection

#53

> We're actively collecting pure black and pure white images generated by Nano Banana Pro to improve multi-resolution watermark extraction. Oh hey, neat. I mentioned this specific method of extracting SynthID a while back.[1] Glad to see someone take it up. [1]: https://news.ycombinator.com/item?id=47169146#47169767

[deleted]

Re: Reverse engineering Gemini's SynthID detection

#54

Ok i get that eventually someone was gonna do this but why would we want to purposely remove one of the only ways of detecting if an image is ai generated or not...?

Because an attacker will do that the same thing and without sharing that knowledge good actors are in the dark. It's the same reason we share known security problems, since there will be bad actors that discover the same bugs and use them for much worse.

Re: Reverse engineering Gemini's SynthID detection

#55

Earlier quoted context omitted.

Fundamentally it's a fuzzy signal and people shouldn't rely on it. The general public does not understand Boolean logic (oh, so the SynthID is not there, therefore this image is real). The sooner AI watermarking faces its deserved farcical demise the better. Also something about how AI is not special and we haven't added or needed invisible watermarks for other ways media can be manipulated deceptively since time imm…

I’m not very well read on the topic and you seen to take a strong “con” stance. Curious to hear why you think it deserves such a demise

Not GP, but I’m pretty “con” too.

Because it’s meaningless for what it’s being marketed for. It’s conceptually inverted. It’s a detector that will detect 100% of the stuff that doesn’t mind being detected, and only the dumbest fraction of stuff that doesn’t want to be detected.

No fault of the extremely smart and capable people who built it. It’s the underlying notion that an imperceptible watermark could survive contact with mass distribution… it gives the futile cat-and-mouse vibes of the DRM era.

Good guys register their guns or whatever, bad guys file off the serial numbers or make their own. Sometimes poorly, but still.

All of which would be fine as one imperfect layer of trust among many (good on Google for doing what they can today). The frustrating/dangerous part is that it seems to be holding itself out as reliable to laypeople (including regulators). Which is how we end up responding to real problems with stupid policy.

People really want to trust “detectors,” even when they know they’re flawed. Already credulous journalists report stuff like “according to LLMDetector.biz, 80% of the student essays were AI-generated.” Jerry Springer built an empire on lie detector tests. British defense contractor ATSC sold literal dowsing rods as “bomb detectors,” and got away with it for a while [2].

It’s backward to “assume it’s not AI-origin unless the detector detects a serial number, since we made the serial number hard to remove.” Instead, if we’re going to “detector” anything, normalize detecting provenance/attestation [e.g. 0]: “maybe it’s an original @alwa work, but she always signs her work, and I don’t see her signature on this one.”

Something without a provable source should be taken with a grain of salt. Make it easy for anyone to sign their work, and get audiences used to looking for that signature as their signal. Then they can decide how much they trust the author.

Do it through an open standards process that preserves room for anyone to play, and you don’t depend on Big Goog’s secret sauce as the arbiter of authenticity.

I hear that sort of thinking is pretty far along, with buy-in from pretty major names in media/photography/etc. The C2PA and CAI are places to look if you’re interested [1].

…and that is why I am “con.”

[0] https://contentcredentials.org/

[1] https://c2pa.org/ , https://contentauthenticity.org/

[2] https://en.wikipedia.org/wiki/ADE_651

Re: Reverse engineering Gemini's SynthID detection

#57
post #11
post #7

kinda ironic you can clearly see signs of Claude, as it shows misaligning table walls in the readme doc

Parenthesized, comma-separated lists with no “and” is an even stronger tell. Claude loves those.

I also use those extensively, they just flow better, especially if you have an "and" in the surrounding sentence.

Re: Reverse engineering Gemini's SynthID detection

#58

Im confident i saw the watermark in use today, in nano banana, i copied the image from chrome into slack. the resulting upload was a black square with a red dot. and not the image i had generated.

I remember experiencing something similar. But then iirc I noticed you can draw on a screenshot and I think i was copying the random dots I made by accidental clicks... You sure it wasnt this?
Post reply on HN