Has Google’s AI watermarking system been reverse-engineered?
A software developer claims to have reverse-engineered Google DeepMind’s SynthID system, showing how AI watermarks can be stripped from generated images or manually inserted into other works. A claim that, according to Google, isn’t true.
The developer, going by the username Aloshdenny, has open-sourced their work on GitHub and documented his process, claiming all it required was 200 Gemini-generated images, signal processing, and “way too much free time.” A little weed also seemed to help.
“No neural networks. No proprietary access,” Aloshdenny said on Medium. “Turns out if you’re unemployed and average enough ‘pure black’ AI-generated images, every nonzero pixel is literally just the watermark staring back at you.”
SynthID is a near-invisible watermarking system that tags content generated by Google’s AI tools, embedding itself in the pixels of images at the point of creation. It was designed to be difficult to remove without degrading the image quality, and is used widely across the AI products offered by Google — everything spat out by models like Nano Banana and Veo 3 carries SynthID watermarks, and it’s even being applied to YouTube’s AI-generated creator clones.
Aloshdenny says he found the system to be “genuinely good engineering,” and was still unable to remove SynthID entirely in tests, instead relying on confusing SynthID decoders that try to read watermarked images.
The process used to crack the underlying mechanics of Google’s watermark is technically complex for non-developers. You can read the full breakdown on Aloshdenny’s Medium page (which was apparently written up while Aloshdenny was “high”) if you’re curious, but here’s a simplified explainer:
- Generate 200 entirely black or pure white images using Gemini. Enhance the contrast and saturation, and then denoise the saturation to expose the watermark patterns.
- Average the patterns together to find the magnitude and phase of the watermark signal at every frequency bin, per channel.
- Hunt for signs of these frequencies in images and partially remove them at the same angle at which they were inserted during generation.
“The fact that the best I could pull off was confuse the decoder enough that it gives up — not actually delete the thing — says a lot about how well it was designed,” says Aloshdenny. “It’s not perfect. But it’s not trying to be unbreakable. It’s trying to raise the cost of misuse high enough that most people don’t bother.”
I haven’t tried Aloshdenny’s project that reverse-engineers Google’s SynthID watermarking system, so I can’t vouch for how effective it actually is. That said, at this point in time, it doesn’t appear that SynthID has been reverse-engineered, at least not to the point where script-kiddies can download a tool and remove (or add) Google’s watermark to trick AI detection systems. Google also doesn’t believe it stands up to Aloshdenny’s claims.
“It is incorrect to say this tool can systematically remove SynthID watermarks,” Google spokesperson Myriam Khan told The Verge. “SynthID is a robust, effective watermarking tool for AI-generated content.”
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
- Jess Weatherbed
Related Articles
The attacks on Sam Altman are a warning for the AI world
Before allegedly throwing a Molotov cocktail at OpenAI CEO Sam Altman’s home, the 20-year-old accused attacker wrote about his fear that the AI race would cause humans to go extinct, the San Francisco...
Chrome now lets you turn AI prompts into repeatable ‘Skills’
Jess Weatherbed is a news writer focused on creative industries, computing, and internet culture. Jess started her career at TechRadar, covering news and hardware reviews.Google is launching a new Chrome...
荣耀PC家族大爆发!荣耀“打洲本”“养虾本”集中亮相
< img id="wx_img" src="https://www.qbitai.com/wp-content/uploads/imgs/qbitai-logo-1.png" width="400" height="400"> 2026-04-14 ...
教育部等五部门关于印发《“人工智能+教育”行动计划》的通知
教育,正在成为AI落地的最大场景。 近日,教育部、国家发展改革委、工业和信息化部、科技部、国家数据局联合印发《“人工智能+教育”行动计划》(以下简称《行动计划》)。 一句话总结:AI不再是加分项,而是必修课。 《行动计划》提出推进“十五五”期间“人工智能+教育”四大重点任务: 1、推动人工智能人才培养与素养提升 2、促进人工智能与教育深度融合 3、建强“人工智能+教育”基础环境 4、打造“人工智能+教育”开放生...

