Inserting an undetectable 1-bit watermark into a multi megapixel image is not particularly difficult. If you assume competence from Google, they probably have two different watermarks. A sloppy one they offer an online oracle for and one they keep in reserve for themselves (and law enforcement requests). Also given that it's Google we are dealing with here, they probably save every single image generated (or at least…
Reverse engineering Gemini's SynthID detection
61–66 of 66 posts
Re: Reverse engineering Gemini's SynthID detection
#62Re: Reverse engineering Gemini's SynthID detection
#63SynthID is visible in some generations (areas with a lot of edges, or text), I wonder if this would make them look better.
Re: Reverse engineering Gemini's SynthID detection
#64Re: Reverse engineering Gemini's SynthID detection
#65Inserting an undetectable 1-bit watermark into a multi megapixel image is not particularly difficult. If you assume competence from Google, they probably have two different watermarks. A sloppy one they offer an online oracle for and one they keep in reserve for themselves (and law enforcement requests). Also given that it's Google we are dealing with here, they probably save every single image generated (or at least…
The dual-watermark theory makes alot of sense for defensive engineering. You always assume your outer layer will be broken and so keep a second layer that isn't publicly testable. Same as defence in depth anywhere else. I'm curious - as new models are being built constantly and they're naturally non-deterministic, do you think it's possible for end users to prove that?
How is the model relevant? The models are proprietary and you never see any of its outputs that haven't been watermarked.
Re: Reverse engineering Gemini's SynthID detection
#66Seems like a very low-quality AI-assisted research repo, and it doesn't even properly test against Google's own SynthID detector. It's not hard at all (with some LLM assistance, for example) to reverse-engineer network requests to be able to do SynthID detection without a browser instance or Gemini access, and then you'd have a ground truth.
I read a lot of comments on HN that say something is not hard, yet don't provide a POC of their own or link to research they have knowledge of. I also read a lot of comments on HN that start by attacking the source of the information, such as saying it was AI assisted, instead of the actual merits of the work. The HN community is becoming curmudgeonly and using AI tooling as the justification.
As for AI specifically.. life is too short to read all the interesting pages already, and AI just makes is so much worse.
- AI is verbose in general, so you are spending a lot of time reading and not getting much new facts out of that.
- Heavy AI use often means that author has little idea about the topic themselves, and thus cannot engage in comments. Since discussion with authors are often most interesting part of HN, that makes submission less interesting.
And yes, it is possible to use AI assistance to create nice and concise report on the topics you can happily talk about, but then this would not be labeled as "AI".