Developer Shows to Obscure Google SynthID Watermark

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Aloshdenny claimed to reverse‑engineer Google DeepMind’s SynthID watermarking system and posted the code on GitHub, describing the method in a Medium article.
- SynthID is a near‑invisible watermark embedded in pixels of images generated by Google’s AI tools (e.g., Nano Banana, Veo 3, YouTube creator clones) and is designed to be hard to remove without degrading quality.
- Aloshdenny generated 200 pure‑black or pure‑white Gemini images, enhanced contrast and saturation, denoised, and averaged the resulting patterns to isolate the watermark’s frequency‑bin signal for partial removal.
- Aloshdenny reported that his technique could only confuse the SynthID decoder, not fully delete the watermark, and he praised its engineering quality.
- Google spokesperson Myriam Khan said the tool cannot systematically remove SynthID watermarks and affirmed SynthID’s robustness.
Why it matters: The demonstration shows that Google’s watermark can be fuzzed enough to fool detection tools, which could aid malicious actors seeking to hide AI‑generated images, while Google’s rebuttal stresses that the barrier still raises the cost of misuse for most users.




