Live data from Hacker News

OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

openai.com

51–60 of 198 posts

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#51

This is just performative nonsense. As someone that creates things with tools with different media I would just hard avoid this tool that adds... arbitrary metadata not of my choosing. Should I seriously make a texture for a videogame with this weird DRM glorp in it? How old is photoshop and why is it exempt?

Strictly speaking, DRM = digital rights management, which is related to intellectual property.

SynthID would only be DRM if Google/OpenAI were claiming IP rights over their images. I don’t even know if that’s legal though.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#52
post #40
post #33

Earlier quoted context omitted.

These systems should be removed. This is antithetical to freedom and privacy. There should be no way for anyone to track down who posted a political meme, anti-religious message, or any other legally protected speech. This will come back to bite us in the ass if we keep building it. Soon every image or communication we make will be watermarked if we continue to let this shit seep into the commons. Everything from you…

That's a lot of hyperbole, there's no cause/effect relationship I can think of here that could realistically produce your slippery slope. Google or anyone else could start adding those unique tracking watermarks you're concerned about any time they want, regardless of whether they use this AI detection watermark, that to be clear can not track you in any way.

> That's a lot of hyperbole, there's no cause/effect relationship I can think of here that could realistically produce your slippery slope.

Have you been watching the headlines over the last year? It's like there's a global push towards locked down and verified computing (age verification, TPMs everywhere, Captchas that only work on non-rooted phones, ...).

You can look out the window and see movement in this direction happening right now. Governments and corporations around the world can't get enough of this shit. Privacy matters, advocating for it is not a "slippery slope."

> this AI detection watermark [...] that to be clear can not track you in any way.

Is that clear? We have no idea what metadata they are or aren't embedding in SynthID.

> Google or anyone else could start adding those unique tracking watermarks you're concerned about any time they want,

The point is that this is bad and should be denounced!

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#53

Aren't these kinds of watermarks easy to remove or distort? Seems like they're only helpful as long as people are relying on them sparingly so it's not worth the effort to circumvent. If social media platforms started banning images with these watermarks seems like they'd be stripped out overnight.

No, they are very resistant to modification that can be done easily. That being said I doubt it is impossible

Yeah cropping, color shifting, resizing and compression don’t remove it. That said, there’s pretty well known workarounds:

https://github.com/wiltodelta/remove-ai-watermarks

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#54

What happens if you generate an image with only a single pixel color or say two colors?

This was done in the past, Google saw it, and now either refuses to generate or doesn't emit the SynthID watermark for those images

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#56

What information is included in the metadata or SynthID? How many bits can be encoded in a SynthID? Can it be used to create something like nutritional labels for synthetic content? 10% synthetic text, 30 synthetic images. Your reality was 15% synthetic today (75% mega corp, 25% open-weight neocloud).

I guess the SynthID-Image paper from Oct 2025[0] was an encoder-decoder for which they tested checking a flag or a 136 bit payload in 512x512 images and the watermark's robustness after various transformations. Presumably the deployed version is meaningfully different. [0]: https://arxiv.org/html/2510.09263v1

This is very similar to audiowmark

https://github.com/swesterfeld/audiowmark

You can stuff per-item database unique IDs, user IDs, geohashes, and other nefarious things inside.

We need to protest this LOUDLY.

Our devices are being locked down, we're having attestation and trusted computing forced on us, the internet all over the world is undergoing age verification with full ID verification.

Just because this is on "ai images" today doesn't mean it won't be on all images - screenshots, your camera reel, etc. - in the fullness of time.

This is scary.

These are the tools of 1984. They've been boiling the water slowly, but in the last year things have really started to pick up pace. Please push back. Loudly.

Everyone at Google and OpenAI working on this: WHAT THE FUCK ARE YOU DOING. STOP.

We have laws and mechanisms to prevent revenge porn, CSAM, defamation, etc. They are robust and can be made even stronger. We do not need to sacrifice the security of our privacy and our speech to fight imagined harms when the real danger is turning into an authoritarian society.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#57
post #11
post #8

Earlier quoted context omitted.

I’m surprised! I guess I’m being naive but I would imagine you could pass an image to an image model without synthid and have it reconstruct the image in a net new way without the markers. I guess I’m wrong? That’s cool if the watermarks are so deeply ingrained that they persist

As I understand it, they modify the image by applying a special Gaussian noise filter which affects each pixel in the image in subtle (possibly not reversible) ways. The detecting service will look for this noise pattern to flag it, so even a part of the image is enough to know it was generated by AI.

Yes, Gemini can actually say how much of the image is AI generated.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#58

What information is included in the metadata or SynthID? How many bits can be encoded in a SynthID? Can it be used to create something like nutritional labels for synthetic content? 10% synthetic text, 30 synthetic images. Your reality was 15% synthetic today (75% mega corp, 25% open-weight neocloud).

Don’t think that would be possible. If I paste a synthetic piece into an otherwise organic image, the synth id isn’t going to know that.

Synth ID can detect parts of images with the watermark.

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#59
post #56

Earlier quoted context omitted.

I guess the SynthID-Image paper from Oct 2025[0] was an encoder-decoder for which they tested checking a flag or a 136 bit payload in 512x512 images and the watermark's robustness after various transformations. Presumably the deployed version is meaningfully different. [0]: https://arxiv.org/html/2510.09263v1

This is very similar to audiowmark https://github.com/swesterfeld/audiowmark You can stuff per-item database unique IDs, user IDs, geohashes, and other nefarious things inside. We need to protest this LOUDLY. Our devices are being locked down, we're having attestation and trusted computing forced on us, the internet all over the world is undergoing age verification with full ID verification. Just because this is on "…

Most cameras already produce metadata. You can remove this metadata. Can you not also detect and remove watermarks?

Re: OpenAI Adopts Google's SynthID Watermark for AI Images with Verification Tool

#60
post #56

Earlier quoted context omitted.

This is very similar to audiowmark https://github.com/swesterfeld/audiowmark You can stuff per-item database unique IDs, user IDs, geohashes, and other nefarious things inside. We need to protest this LOUDLY. Our devices are being locked down, we're having attestation and trusted computing forced on us, the internet all over the world is undergoing age verification with full ID verification. Just because this is on "…

Most cameras already produce metadata. You can remove this metadata. Can you not also detect and remove watermarks?

The paper references some threat models they considered. They suggest someone might "possess paired information (both original and watermarked content)" and therefore be able to undo watermarking. Presumably it's fairly easy to get identity operations out of image APIs that would result in this situation. I'm not sure that addresses echelon's main concerns though.
Post reply on HN