[HN Gopher] Reverse engineering Gemini's SynthID detection
___________________________________________________________________
Reverse engineering Gemini's SynthID detection
Author : _tk_
Score : 78 points
Date : 2026-04-09 20:10 UTC (2 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| andrewmcwatters wrote:
| > We're actively collecting pure black and pure white images
| generated by Nano Banana Pro to improve multi-resolution
| watermark extraction.
|
| Oh hey, neat. I mentioned this specific method of extracting
| SynthID a while back.[1]
|
| Glad to see someone take it up.
|
| [1]: https://news.ycombinator.com/item?id=47169146#47169767
| raphman wrote:
| FWIW, I had Nano Banana create pure white/black images in
| February, and there was no recognizable watermark in them (all
| pixels really were #ffffff / #000000 IIRC).
|
| Meta: your comment was marked [dead], like a few other
| constructive comments I saw in recent days. Not sure why.
| andrewmcwatters wrote:
| I suspect they strip the SynthID for these specific cases to
| prevent exfiltration of the steganography.
|
| I appreciate you pointing it out, but this account is banned.
| Thank you for vouching though!
| refulgentis wrote:
| It says not to use these tools to misrepresent AI-generated
| content as human-created. But the project is a watermark removal
| tool with a pip-installable CLI and strength settings named
| "aggressive" and "maximum." Calling this research while shipping
| turnkey watermark stripping is trying to have it both ways in a
| way that's uncomfortable to read.
|
| The README itself reads like unedited AI output with several
| layers of history baked in.
|
| - V1 and V2 appear in tables and diagrams but are never
| explained. V3 gets a pipeline diagram that hand-waves its
| fallback path.
|
| - The same information is restated three times across Overview,
| Architecture, and Technical Deep Dive. ~1600 words padded to feel
| like a paper without the rigor.
|
| - Five badges, 4 made up, for a project with 88 test images, no
| CI, and no test suite. "Detection Rate: 90%" has no methodology
| behind it. "License: Research" links nowhere and isn't a license.
|
| - No before/after images, anywhere, for a project whose core
| claim is imperceptible modification.
|
| - Code examples use two different import styles. One will throw
| an ImportError.
|
| - No versioning. If Google changes SynthID tomorrow, nothing
| tells you the codebook is stale.
|
| The underlying observations about resolution-dependent carriers
| and cross-image phase consistency are interesting. The packaging
| undermines them.
| jonshariat wrote:
| Agreed. This isn't punk this just helps the bad guys. Society
| needs to know what content is AI generated and what is not.
| SR2Z wrote:
| If that's the case, society will inevitably be disappointed.
|
| There are already ten million AI image generators, the
| overwhelming majority of which do not watermark their
| outputs. Google auto-inserting them is nice, but ultimately
| this kind of tool to remove them will inevitably be
| widespread.
| recursive wrote:
| This was never going to be a reliable way to do it. It's
| basically the evil bit . It only works for as long as
| everyone is making a good-faith effort to follow the
| convention. But the bad guys do not do that.
| charcircuit wrote:
| It really doesn't need such capability. Nor does it need the
| capability to know what human generated it either.
| kelsey98765431 wrote:
| if you downscale then upscale it removes the watermark
| armanj wrote:
| kinda ironic you can clearly see signs of Claude, as it shows
| misaligning table walls in the readme doc
| rafram wrote:
| Parenthesized, comma-separated lists with no "and" is an even
| stronger tell. Claude loves those.
| TacticalCoder wrote:
| > kinda ironic you can clearly see signs of Claude, as it shows
| misaligning table walls in the readme doc
|
| This one is such a gigantic clusterfuck... They're mimicking
| ASCII tables using Unicode chars of varying length and, at
| times, there's also an off-by-one error. But the model (not
| Claude, but the model underneath it) is capable of generating
| ASCII tables.
|
| P.S: I saw the future... The year is 2037 and we've got Unicode
| tables still not properly aligned.
| dgellow wrote:
| I mean, just reading the readme content it is pretty obvious it
| is Claude
| khernandezrt wrote:
| Ok i get that eventually someone was gonna do this but why would
| we want to purposely remove one of the only ways of detecting if
| an image is ai generated or not...?
| lokar wrote:
| It was always going to be available to some people, but not
| everyone would know or believe that. Now they will.
| subscribed wrote:
| More likely than not it would be used to deanonymise the
| author.
|
| So it's a "no" by default.
| raincole wrote:
| Uh... you can do this pretty easily since day 1. Just use
| Stable Diffusion with a low denoising strength. This repo
| presents an even less destructive way[0], but it has always
| been very easy to hide that an image is generated by Nano
| Banana.
|
| [0]: if it does what it claims to do. I didn't verify. Given
| how much AI writing in the README my hunch is that this doesn't
| work better than simple denoising.
| M4v3R wrote:
| SynthID is visible in some generations (areas with a lot of
| edges, or text), I wonder if this would make them look better.
| sodacanner wrote:
| I don't understand all the handwringing. If it's this easy to
| remove SynthID from an AI-generated image then it wasn't a good
| solution in the first place.
| rustyhancock wrote:
| Yes. This kind of project needs aggressive red teaming, it
| leads to better products and we need excellent products in this
| space.
|
| This project proves what red teaming was in place wasn't good
| enough.
| raincole wrote:
| There is no _solution_. I don 't know why people discuss this
| subject as if there is a technical solution. As if there are
| fairies or souls hidden in the pixels that help us tell what is
| AI generated and what is not.
| sodacanner wrote:
| Sure, and things like this help drive home that SynthID
| wasn't a solution at all.
| DonsDiscountGas wrote:
| If you want to make an AI generated image but don't want
| other people to know that it's AI, the most obvious solution
| is to not use Gemini. Synth ID is watermarking. It's only
| ever going to be useful to good actors, who want an AI
| generated image and aren't trying to hide the fact that it's
| AI generated.
| dummydummy1234 wrote:
| Never underestimate that people are lazy.
| levocardia wrote:
| Sure there is a solution, you are just looking at it the
| wrong way. Make non-AI images provably unaltered with signed
| keys from the device (e.g. the camera) that took it.
| Diggsey wrote:
| Which works for about 5 minutes until someone leaks a
| manufacturer's private key or extracts it from a device...
| IncreasePosts wrote:
| How many minutes do you think it would take before someone
| figured out how to crack that?
| subscribed wrote:
| On Pixels and iPhones it would be impossible since they
| have actually secure hardware that could both hold the
| keys and sign/verify the image.
| IncreasePosts wrote:
| The camera module sits outside the secure area, meaning
| it would need to send data in to be signed. How does the
| phone know that it's getting legitimate data from the
| camera module, or data someone else is just piping in?
| Also, you could probably get a fairly high quality image
| by just taking a photo of something AI generated in the
| right lighting conditions.
| raincole wrote:
| If the premise is that everyone would _just_ agree on the
| same protocol, I have an even more unbreakable solution:
| every image has to be upload to a blockchain the moment it
| is (claimed to be) created. Otherwise it 's AI.
|
| If only everyone _just_ agrees with me.
| doctorpangloss wrote:
| Okay... this tests its own ability to remove the watermark
| against its own detector. It doesn't test against Gemini's
| SynthID app. So it does nothing...
| Tiberium wrote:
| Seems like a very low-quality AI-assisted research repo, and it
| doesn't even properly test against Google's own SynthID detector.
| It's not hard at all (with some LLM assistance, for example) to
| reverse-engineer network requests to be able to do SynthID
| detection without a browser instance or Gemini access, and then
| you'd have a ground truth.
| ddtaylor wrote:
| I read a lot of comments on HN that say something is not hard,
| yet don't provide a POC of their own or link to research they
| have knowledge of.
|
| I also read a lot of comments on HN that start by attacking the
| source of the information, such as saying it was AI assisted,
| instead of the actual merits of the work.
|
| The HN community is becoming curmudgeonly and using AI tooling
| as the justification.
| coppsilgold wrote:
| Inserting an undetectable 1-bit watermark into a multi megapixel
| image is not particularly difficult.
|
| If you assume competence from Google, they probably have two
| different watermarks. A sloppy one they offer an online oracle
| for and one they keep in reserve for themselves (and law
| enforcement requests).
|
| Also given that it's Google we are dealing with here, they
| probably save every single image generated (or at least its
| neural hash) and tie it to your account in their database.
___________________________________________________________________
(page generated 2026-04-09 23:00 UTC)