A software developer claims to have reverse-engineered Google DeepMind’s SynthID system, showing how AI watermarks can be stripped from generated images or manually inserted into other works. A claim that, according to Google, isn’t true.

The developer, going by the username Aloshdenny, has open-sourced their work on GitHub and documented his process, claiming all it required was 200 Gemini-generated images, signal processing, and “way too much free time.” A little weed also seemed to help.

“No neural networks. No proprietary access,” Aloshdenny said on Medium. “Turns out if you’re unemployed and average enough ‘pure black’ AI-generated images, every nonzero pixel is literally just the watermark staring back at you.”

SynthID is a near-invisible watermarking system that tags content generated by Google’s AI tools, embedding itself in the pixels of images at the point of creation. It was designed to be difficult to remove without degrading the image quality, and is used widely across the AI products offered by Google — everything spat out by models like Nano Banana and Veo 3 carries SynthID watermarks, and it’s even being applied to YouTube’s AI-generated creator clones.

Aloshdenny says he found the system to be “genuinely good engineering,” and was still unable to remove SynthID entirely in tests, instead relying on confusing SynthID decoders that try to read watermarked images.

The process used to crack the underlying mechanics of Google’s watermark is technically complex for non-developers. You can read the full breakdown on Aloshdenny’s Medium page (which was apparently written up while Aloshdenny was “high”) if you’re curious, but here’s a simplified explainer:

“The fact that the best I could pull off was confuse the decoder enough that it gives up — not actually delete the thing — says a lot about how well it was designed,” says Aloshdenny. “It’s not perfect. But it’s not trying to be unbreakable. It’s trying to raise the cost of misuse high enough that most people don’t bother.”

I haven’t tried Aloshdenny’s project that reverse-engineers Google’s SynthID watermarking system, so I can’t vouch for how effective it actually is. That said, at this point in time, it doesn’t appear that SynthID has been reverse-engineered, at least not to the point where script-kiddies can download a tool and remove (or add) Google’s watermark to trick AI detection systems. Google also doesn’t believe it stands up to Aloshdenny’s claims.

“It is incorrect to say this tool can systematically remove SynthID watermarks,” Google spokesperson Myriam Khan told The Verge. “SynthID is a robust, effective watermarking tool for AI-generated content.”

Share.
Exit mobile version