SynthID Detector (synthid.com)

75 points by ilreb 8 hours ago

justhw an hour ago

I tested about 8 pictures. All 8 were made with OpenAI and Google. 2 were altered by and had text and picture overlays. The 6 didn't and SynthID caught them. The 2 altered passed. Interesting!

charcircuit 10 minutes ago

No artist wants their artwork be defined by the noise synthid ads.

Tiberium 7 hours ago

It's baffling that this requires auth. OpenAI's own tool (https://openai.com/research/verify/) doesn't require auth.

Even Google themselves previously offered a no-auth way (just very niche): if you uploaded an image to Google Image search, and went to "About this image", it would show if the image was Google AI-generated. Now it doesn't.

possibilistic 7 hours ago

These are "spy"marks, not watermarks:

https://brand.io/article/spymarks/

We need to inform everyone that this technology can encode database identifiers and enough entropy to uniquely identify you as an author (or downloader).

This extends to other forms of media as well.

moritzwarhier 5 hours ago

Cool post, but I'm wondering what would a realistic way to avoid this?

It's not really possible to ban steganography, is it?

> That future lies halfway between now and 1984. So let’s stay off that timeline, shall we?

> Call a spymark what it is. A spy tool used to spy on you and everyone you interact with.

cubefox 7 hours ago

They are not spymarks if they don't encode any personal IDs and are merely used to indicate that an image was AI-generated. I don't think Google or OpenAI use SynthID to include personal data.

MisterMunchkin 7 hours ago

morkalork 7 hours ago

98codes 6 hours ago

It's worth nothing that this IS Google.

Given that it's an ad company, they want something to connect what you're doing to the rest of their data, and they couldn't possibly keep the old image search results there if they want people to use this.

Retr0id 7 hours ago

It's presumably so they can rate-limit people who are trying to reverse-engineer or otherwise strip it (e.g. iteratively tweaking until it stops getting detected)

user43928 7 hours ago

I wonder how relevant this really is.

How hard can it be to download a set of real images and generated ones in order to train a model to detect and strip the watermark with minimal perceptual difference?

brokensegue 7 hours ago

Yeah I've been wanting to run a ton of Wikipedia images through the detector to see if fakes snuck in. Doesn't seem to be a practical way to do this. Even Open AIs tool has a low rate limit

wodenokoto 7 hours ago

The EULA you have to accept hints that they are afraid you are going to abuse it to remove synthID - e.g, set up and edit and check loop

dannyw 7 hours ago

That’s the justification, but the EULA incorporates Google’s regular consumer terms; which means what you upload can also be used for advertising and targeting; and basically any purpose whatsoever by Google.

apefulsin 7 hours ago

Any access to a watermark detector can be used to remove the watermark. Presumably they want to be able to track who is doing that.

lelandfe 7 hours ago

I've never seen it mentioned anywhere so I will just here complain that Google also removed the ability to paste images into Google Image search some years ago for no apparent reason. It worked great and I used it all the time.

mh- 7 hours ago

Click the little camera icon in the search box and it pops a modal that says Search any image with Google Lens.

The textbox below it says Paste image link, but you can actually paste an image from your clipboard here, too.

qingcharles 6 hours ago

lelandfe 7 hours ago

dannyw 7 hours ago

I wonder if it’s a deliberate anti-user decision to get more URLs and less pasted images.

URLs expand Googlebot’s indexes; pasted images don’t.

charcircuit an hour ago

bossyTeacher 7 hours ago

I might be missing something but Google Image Search still works for me.

RugnirViking 7 hours ago

this + image translate with copy+paste is the only reason I ever use yandex of all places...

cubefox 7 hours ago

OpenAI's tool is worse though, because it doesn't detect SynthID from non-OpenAI models. I just tried it with various images created by Imagen / Nano Banana.

MisterMunchkin 7 hours ago

It's deliberate so that you can't find a way to bypass it.

Retr0id 7 hours ago

It's a real shame Google isn't more transparent about how it actually works, and doesn't provide any mechanism for classifying images in bulk or offline.

This is the best SynthID write-up I've found so far: https://fyx.me/articles/attempting-model-extraction-of-googl...

It covers how it actually works (probably), and how to train your own classifier for it, with some seemingly decent results.

MisterMunchkin 7 hours ago

They don't want you to know, because they're the baddies. Imagine how much money they can get from advertisers if they're able to identify every single piece of code, reddit thread, email, GitHub readme that you've ever written based on your secret ID. They're creaming themselves just thinking about it.

"Excellent work acquiring that outlook data Anat, now let's cross check the defunct company emails against YouTube videos edited with Google PrivateEditAI™ to figure out what the social security number of this YouTube account is."

Avicebron 7 hours ago

Unfortunately this is the truth, no one can be given a benefit of the doubt because despite years of good grace they have been anti-user and enshittified everything they touch.

elevation 7 hours ago

> It's a real shame Google isn't more transparent about how it actually works

> classifying images in bulk or offline

You've described exactly the elements spammers and fraudsters need to be able to defeat this mechanism.

Retr0id 7 hours ago

Well it's not a very good mechanism then, is it.

_flux 7 hours ago

jdranczewski 7 hours ago

Finally, the previous implementations were very silly! OpenAI had a nice tool, but it only detected their own watermarks, and Google's process was "upload the image to Gemini and ask if it's AI generated", which seemed like a perplexing waste of tokens and breath.

(While a sibling comment points out putting the image through Google Image Search as an alternative, I don't remember this being signposted in the support article I've read, so I unfortunately didn't know about it)

Computer0 6 hours ago

It also was the exact opposite of the commonly shared sentiment “Don’t blindly trust the ai”

nialv7 7 hours ago

Why the hell do I need to sign in?

wildzzz 7 hours ago

Probably to help prevent people from reverse engineering synthID to build a filter.

chrsstrm an hour ago

Or they could, I don't know, read the research paper for it - https://arxiv.org/abs/2510.09263

RobGR 7 hours ago

If I go directly to the URL it wants me to agree to some stuff before I even know what the service is. I had to come to these comments to figure that out (without agreeing to anything first).

NeumannGod 5 hours ago

Is there an open standard or something for people generating images to encode them or is the standard private and only shared with frontier model builders? That's a shame if latter. But pretty cool standardizing technology.

addedlovely 44 minutes ago

I hate that Google don't have an API or open library to detect gemini images, unless you're enterprise. Create a problem then charge API access to get the solution.

sarkarghya 7 hours ago

sha-3 7 hours ago

No option to detect generated text. SynthID also watermarks text, right?

nonethewiser 7 hours ago

Thats what I was expecting. I thought so.

jakozaur 7 hours ago

I worry we’ll have to approach this the other way around: verify that photos came from a camera, using hardware support like Apple’s Reference Image, rather than try to detect every AI generated one.

In many situations, photos are evidence. AI tools make convincing fakes, such as images of defect product.

MisterMunchkin 7 hours ago

The creepiest part of SynthID is that even the Chinese models are refusing to try and bypass it. Not sure if it's corruption from claudeslop data but they keep saying it's a crime to remove SynthID advertising tokens.

>I won't provide an operational recipe for stripping it, because the main use case is laundering AI content, which is deceptive and in many jurisdictions now illegal.

pbronez 7 hours ago

This is a Google Deepmind project to “Identify AI generated media”

More detail at https://deepmind.google/models/synthid/

For those who, like me, were hoping it was a vision model to identify synthesizer models from photos of concerts and music studios!

iamleppert 7 hours ago

Wouldn't it be easy to just generate a training dataset and use a model to identify and remove said watermarks?

cubefox 7 hours ago

There is a rate limit of around 10 checks in 24 hours.

ChrisArchitect 7 hours ago

anon48293 7 hours ago

Hey OpenAi, generate a text of 100 words.

Hey Gemini, find a synonym for every second adjective. Replace in text.

Hey Grok, find a synonym for every third proper noun. Replace in text.

Hey …

nonethewiser 6 hours ago

>Hey OpenAi, generate a text of 100 words.

Too short for watermarking but point taken of course.

Probably more like

    response = frontier_synthid_model(prompt)
    
    while frontier_synthid_validator(response) == false
        response = cheapo_chinese_model.prompt(
            "pls remove synthid",
            response
        )

MisterMunchkin 7 hours ago

Ah but that's the genius of the scheme. Every single one of those providers will detect your secret ID and refuse the request. And sneak their own one in for good measure.

Muromec 7 hours ago

What's what you use the stupid silly local model^W script.

latexr 8 hours ago

Can’t be used without signing in with a Google, Apple, or ChatGPT account.

giancarlostoro 7 hours ago

Also it can't detect any Synths in The Commonwealth.

nonethewiser 7 hours ago

Who thought it was a good idea to Institute it like this?

tosh 7 hours ago

is this by Google?

spuz 7 hours ago

Yes but OpenAI, NVIDIA, Kakao, Apple have said they will also implement SynthID

m00dy 7 hours ago