[HN Gopher] Reverse engineering Gemini's SynthID detection
       ___________________________________________________________________
        
       Reverse engineering Gemini's SynthID detection
        
       Author : _tk_
       Score  : 78 points
       Date   : 2026-04-09 20:10 UTC (2 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | andrewmcwatters wrote:
       | > We're actively collecting pure black and pure white images
       | generated by Nano Banana Pro to improve multi-resolution
       | watermark extraction.
       | 
       | Oh hey, neat. I mentioned this specific method of extracting
       | SynthID a while back.[1]
       | 
       | Glad to see someone take it up.
       | 
       | [1]: https://news.ycombinator.com/item?id=47169146#47169767
        
         | raphman wrote:
         | FWIW, I had Nano Banana create pure white/black images in
         | February, and there was no recognizable watermark in them (all
         | pixels really were #ffffff / #000000 IIRC).
         | 
         | Meta: your comment was marked [dead], like a few other
         | constructive comments I saw in recent days. Not sure why.
        
           | andrewmcwatters wrote:
           | I suspect they strip the SynthID for these specific cases to
           | prevent exfiltration of the steganography.
           | 
           | I appreciate you pointing it out, but this account is banned.
           | Thank you for vouching though!
        
       | refulgentis wrote:
       | It says not to use these tools to misrepresent AI-generated
       | content as human-created. But the project is a watermark removal
       | tool with a pip-installable CLI and strength settings named
       | "aggressive" and "maximum." Calling this research while shipping
       | turnkey watermark stripping is trying to have it both ways in a
       | way that's uncomfortable to read.
       | 
       | The README itself reads like unedited AI output with several
       | layers of history baked in.
       | 
       | - V1 and V2 appear in tables and diagrams but are never
       | explained. V3 gets a pipeline diagram that hand-waves its
       | fallback path.
       | 
       | - The same information is restated three times across Overview,
       | Architecture, and Technical Deep Dive. ~1600 words padded to feel
       | like a paper without the rigor.
       | 
       | - Five badges, 4 made up, for a project with 88 test images, no
       | CI, and no test suite. "Detection Rate: 90%" has no methodology
       | behind it. "License: Research" links nowhere and isn't a license.
       | 
       | - No before/after images, anywhere, for a project whose core
       | claim is imperceptible modification.
       | 
       | - Code examples use two different import styles. One will throw
       | an ImportError.
       | 
       | - No versioning. If Google changes SynthID tomorrow, nothing
       | tells you the codebook is stale.
       | 
       | The underlying observations about resolution-dependent carriers
       | and cross-image phase consistency are interesting. The packaging
       | undermines them.
        
         | jonshariat wrote:
         | Agreed. This isn't punk this just helps the bad guys. Society
         | needs to know what content is AI generated and what is not.
        
           | SR2Z wrote:
           | If that's the case, society will inevitably be disappointed.
           | 
           | There are already ten million AI image generators, the
           | overwhelming majority of which do not watermark their
           | outputs. Google auto-inserting them is nice, but ultimately
           | this kind of tool to remove them will inevitably be
           | widespread.
        
           | recursive wrote:
           | This was never going to be a reliable way to do it. It's
           | basically the evil bit . It only works for as long as
           | everyone is making a good-faith effort to follow the
           | convention. But the bad guys do not do that.
        
           | charcircuit wrote:
           | It really doesn't need such capability. Nor does it need the
           | capability to know what human generated it either.
        
       | kelsey98765431 wrote:
       | if you downscale then upscale it removes the watermark
        
       | armanj wrote:
       | kinda ironic you can clearly see signs of Claude, as it shows
       | misaligning table walls in the readme doc
        
         | rafram wrote:
         | Parenthesized, comma-separated lists with no "and" is an even
         | stronger tell. Claude loves those.
        
         | TacticalCoder wrote:
         | > kinda ironic you can clearly see signs of Claude, as it shows
         | misaligning table walls in the readme doc
         | 
         | This one is such a gigantic clusterfuck... They're mimicking
         | ASCII tables using Unicode chars of varying length and, at
         | times, there's also an off-by-one error. But the model (not
         | Claude, but the model underneath it) is capable of generating
         | ASCII tables.
         | 
         | P.S: I saw the future... The year is 2037 and we've got Unicode
         | tables still not properly aligned.
        
         | dgellow wrote:
         | I mean, just reading the readme content it is pretty obvious it
         | is Claude
        
       | khernandezrt wrote:
       | Ok i get that eventually someone was gonna do this but why would
       | we want to purposely remove one of the only ways of detecting if
       | an image is ai generated or not...?
        
         | lokar wrote:
         | It was always going to be available to some people, but not
         | everyone would know or believe that. Now they will.
        
           | subscribed wrote:
           | More likely than not it would be used to deanonymise the
           | author.
           | 
           | So it's a "no" by default.
        
         | raincole wrote:
         | Uh... you can do this pretty easily since day 1. Just use
         | Stable Diffusion with a low denoising strength. This repo
         | presents an even less destructive way[0], but it has always
         | been very easy to hide that an image is generated by Nano
         | Banana.
         | 
         | [0]: if it does what it claims to do. I didn't verify. Given
         | how much AI writing in the README my hunch is that this doesn't
         | work better than simple denoising.
        
       | M4v3R wrote:
       | SynthID is visible in some generations (areas with a lot of
       | edges, or text), I wonder if this would make them look better.
        
       | sodacanner wrote:
       | I don't understand all the handwringing. If it's this easy to
       | remove SynthID from an AI-generated image then it wasn't a good
       | solution in the first place.
        
         | rustyhancock wrote:
         | Yes. This kind of project needs aggressive red teaming, it
         | leads to better products and we need excellent products in this
         | space.
         | 
         | This project proves what red teaming was in place wasn't good
         | enough.
        
         | raincole wrote:
         | There is no _solution_. I don 't know why people discuss this
         | subject as if there is a technical solution. As if there are
         | fairies or souls hidden in the pixels that help us tell what is
         | AI generated and what is not.
        
           | sodacanner wrote:
           | Sure, and things like this help drive home that SynthID
           | wasn't a solution at all.
        
           | DonsDiscountGas wrote:
           | If you want to make an AI generated image but don't want
           | other people to know that it's AI, the most obvious solution
           | is to not use Gemini. Synth ID is watermarking. It's only
           | ever going to be useful to good actors, who want an AI
           | generated image and aren't trying to hide the fact that it's
           | AI generated.
        
             | dummydummy1234 wrote:
             | Never underestimate that people are lazy.
        
           | levocardia wrote:
           | Sure there is a solution, you are just looking at it the
           | wrong way. Make non-AI images provably unaltered with signed
           | keys from the device (e.g. the camera) that took it.
        
             | Diggsey wrote:
             | Which works for about 5 minutes until someone leaks a
             | manufacturer's private key or extracts it from a device...
        
             | IncreasePosts wrote:
             | How many minutes do you think it would take before someone
             | figured out how to crack that?
        
               | subscribed wrote:
               | On Pixels and iPhones it would be impossible since they
               | have actually secure hardware that could both hold the
               | keys and sign/verify the image.
        
               | IncreasePosts wrote:
               | The camera module sits outside the secure area, meaning
               | it would need to send data in to be signed. How does the
               | phone know that it's getting legitimate data from the
               | camera module, or data someone else is just piping in?
               | Also, you could probably get a fairly high quality image
               | by just taking a photo of something AI generated in the
               | right lighting conditions.
        
             | raincole wrote:
             | If the premise is that everyone would _just_ agree on the
             | same protocol, I have an even more unbreakable solution:
             | every image has to be upload to a blockchain the moment it
             | is (claimed to be) created. Otherwise it 's AI.
             | 
             | If only everyone _just_ agrees with me.
        
       | doctorpangloss wrote:
       | Okay... this tests its own ability to remove the watermark
       | against its own detector. It doesn't test against Gemini's
       | SynthID app. So it does nothing...
        
       | Tiberium wrote:
       | Seems like a very low-quality AI-assisted research repo, and it
       | doesn't even properly test against Google's own SynthID detector.
       | It's not hard at all (with some LLM assistance, for example) to
       | reverse-engineer network requests to be able to do SynthID
       | detection without a browser instance or Gemini access, and then
       | you'd have a ground truth.
        
         | ddtaylor wrote:
         | I read a lot of comments on HN that say something is not hard,
         | yet don't provide a POC of their own or link to research they
         | have knowledge of.
         | 
         | I also read a lot of comments on HN that start by attacking the
         | source of the information, such as saying it was AI assisted,
         | instead of the actual merits of the work.
         | 
         | The HN community is becoming curmudgeonly and using AI tooling
         | as the justification.
        
       | coppsilgold wrote:
       | Inserting an undetectable 1-bit watermark into a multi megapixel
       | image is not particularly difficult.
       | 
       | If you assume competence from Google, they probably have two
       | different watermarks. A sloppy one they offer an online oracle
       | for and one they keep in reserve for themselves (and law
       | enforcement requests).
       | 
       | Also given that it's Google we are dealing with here, they
       | probably save every single image generated (or at least its
       | neural hash) and tie it to your account in their database.
        
       ___________________________________________________________________
       (page generated 2026-04-09 23:00 UTC)