While Invisible Watermarks Like SynthID Show Promise, Labeling AI Content Remains a Challenge

Administrator

Administrator
Staff member
Apr 20, 2025
3,674
674
113

While Invisible Watermarks Like SynthID Show Promise, Labeling AI Content Remains a Challenge

6a6a0307dcdb3.jpg


Can Invisible Watermarks Solve the Flood of Fake Online Images?

The sheer amount of artificial intelligence (AI) media being created today is hard to fully grasp. Historically, it took nearly a century and a half after the invention of the camera for humans to produce 1.5 billion photographs. In contrast, modern AI tools reached that exact milestone in just a year and a half. Today, a single major tech firm estimates that its systems have generated more than 100 billion images and videos in just a few short years.

To help people tell the difference between real life and computer-generated creations, several tech organizations are introducing invisible watermarks. These hidden digital stamps are designed to label computer-made files and stay attached even when the files are edited or shared online.

A Hidden Stamp in the Pixels

Currently, there are two main ways to label computer-generated pictures. The first method uses hidden data tags attached to the file. While these tags are highly secure and difficult to fake, they are incredibly easy to remove. Simply taking a screenshot or saving the image in a different format can wipe this data away completely.

The second method involves weaving an invisible pattern directly into the pixels of an image, the frames of a video, or the sound waves of an audio clip. Because this pattern is built into the file itself, it is meant to survive the normal wear and tear of the internet, such as being shrunk, compressed, or turned into memes.

Engineers designed these pixel-level stamps to be tough. They anticipated that people would try to erase them, so they built the system to withstand basic edits like adding color filters or cropping the edges.

Testing the Limits of the Technology

To see if these claims hold up, a series of tests simulated how images degrade when they are repeatedly downloaded and shared online. Using a computer script, a set of test images—including one made entirely by AI and another edited with AI tools—were compressed and resized hundreds of times.

The results showed that the technology is remarkably durable, but it does have clear limits:

  • The Good: Even after being compressed 300 times until they were blurry, the images still contained the hidden watermark. Taking a screenshot of the full image also preserved the watermark.
  • The Bad: The system failed when the images were cropped. Removing just 20 percent of the border after multiple rounds of compression made the watermark completely undetectable. Cutting the image in half broke the watermark even faster, at around 250 rounds of compression.

This means that while the technology is tough, a simple crop combined with normal internet sharing can still render the watermark useless, leaving no proof that the image was generated by a computer.

Why Digital Stamps Aren't Perfect

Even if the watermarks were impossible to erase, they still face major practical hurdles. First, there is no single standard. Different tech companies use their own unique watermarking systems. A detector built by one company cannot read the watermark made by another company. This fragmentation means a user might check a suspicious image with one tool, find nothing, and wrongly assume the image is real.

Second, access to these detection tools is heavily restricted. To prevent bad actors from testing ways to bypass the system, the creators do not offer a public website or open software for checking images. Instead, users must ask a specific digital assistant to verify the file.

Furthermore, users are limited to only about ten checks per day, and the system may lock users out even sooner if they upload similar-looking images. During times when false information spreads rapidly, having a limit on truth-checking is a serious drawback.

The Unlabeled Flood

The biggest issue with relying on watermarks is that they are entirely voluntary. While some of the largest tech companies have agreed to use them, many other creators do not. Anyone with a home computer can download open-source AI models that generate realistic images without any watermarks or labels whatsoever.

Because there will always be a flood of unlabeled computer-generated content, watermarks cannot be trusted as a complete solution. In fact, they might create a false sense of security, leading people to believe that any image without a watermark must be authentic.

As the internet becomes crowded with an infinite supply of synthetic media, some experts suggest a shift in strategy. Instead of trying to label every fake image, the focus may need to shift toward securing and verifying genuine, real-world content, such as photos taken by physical cameras. By proving what is real, we can better protect against the endless tide of digital fabrications.