Even Google themselves previously offered a no-auth way (just very niche): if you uploaded an image to Google Image search, and went to "About this image", it would show if the image was Google AI-generated. Now it doesn't.
https://brand.io/article/spymarks/
We need to inform everyone that this technology can encode database identifiers and enough entropy to uniquely identify you as an author (or downloader).
This extends to other forms of media as well.
It's not really possible to ban steganography, is it?
> That future lies halfway between now and 1984. So let’s stay off that timeline, shall we?
> Call a spymark what it is. A spy tool used to spy on you and everyone you interact with.
Why? I assume by default they are uniquely identifiable, because it just makes sense for them (tracking misuse at the very least), it's trivial to implement and trivial to hide or plausibly deny.
Given that it's an ad company, they want something to connect what you're doing to the rest of their data, and they couldn't possibly keep the old image search results there if they want people to use this.
I don't think that dodgy folks have any issue with registering thousands of IDs. I know that I used to regularly get approached by these Chinese companies that were selling good reviews of my free apps. They did this by having thousands of legit AppleID accounts that would download and rate the app.
I haven't been approached by one of these in a long time. I guess Apple figured out how to put the kibosh on them.
The textbox below it says Paste image link, but you can actually paste an image from your clipboard here, too.
I suppose it was too convenient.
URLs expand Googlebot’s indexes; pasted images don’t.
This is the best SynthID write-up I've found so far: https://fyx.me/articles/attempting-model-extraction-of-googl...
It covers how it actually works (probably), and how to train your own classifier for it, with some seemingly decent results.
"Excellent work acquiring that outlook data Anat, now let's cross check the defunct company emails against YouTube videos edited with Google PrivateEditAI™ to figure out what the social security number of this YouTube account is."
> classifying images in bulk or offline
You've described exactly the elements spammers and fraudsters need to be able to defeat this mechanism.
Most AI images are either extremely low-effort or not actively trying to be deceptive, so defenders can still catch the majority. If someone is actively circumventing they'll probably circumvent both, anyway.
(While a sibling comment points out putting the image through Google Image Search as an alternative, I don't remember this being signposted in the support article I've read, so I unfortunately didn't know about it)
https://help.openai.com/en/articles/8912793-provenance-signa...
There is rate limit though
In many situations, photos are evidence. AI tools make convincing fakes, such as images of defect product.
>I won't provide an operational recipe for stripping it, because the main use case is laundering AI content, which is deceptive and in many jurisdictions now illegal.
More detail at https://deepmind.google/models/synthid/
For those who, like me, were hoping it was a vision model to identify synthesizer models from photos of concerts and music studios!
Or did it just become public
Edit:
Blog post today https://blog.google/innovation-and-ai/models-and-research/go...
Hey Gemini, find a synonym for every second adjective. Replace in text.
Hey Grok, find a synonym for every third proper noun. Replace in text.
Hey …
Too short for watermarking but point taken of course.
Probably more like
response = frontier_synthid_model(prompt)
while frontier_synthid_validator(response) == false
response = cheapo_chinese_model.prompt(
"pls remove synthid",
response
)https://deepwalker.xyz/blog/evaluating-synthid-watermark-rob...