Technology

Google SynthID watermark survives tough tests but cannot label all AI media

Tests found Google's AI watermark can withstand heavy compression, while access limits and unlabeled AI tools leave major verification gaps.

Maya Lindqvist

By Maya Lindqvist · Senior Technology Correspondent

4 min read

Google SynthID watermark survives tough tests but cannot label all AI media
Photo: Ars Technica

The Google SynthID watermark held up through aggressive image degradation in tests reported by Ars Technica, strengthening Google’s case that invisible labels can travel with AI media. The same testing also showed why watermarks alone cannot settle whether online images and videos are real.

Google said at its I/O conference this spring that its products had been used to make more than 100 billion AI images and videos in a few years. The company has paired that scale with wider use of SynthID, including partnerships involving OpenAI, Runway, Nvidia and others, according to Ars Technica.

Starling Lab, a research collaboration between Stanford University and the University of Southern California, has put the scale in historical terms: it estimated that people created 1.5 billion images between the camera’s invention and 1975, while generative AI reached that amount in 18 months.

What is Google SynthID?

SynthID is Google’s invisible watermarking system for AI-generated media. Ars Technica reported that it embeds signals into image pixels, video frames or audio waveforms so a detector can later identify content as AI-made or AI-edited.

Google also uses C2PA, a cryptographic metadata standard, to label some content. Ars Technica noted that C2PA can be removed through common file handling, such as editing and saving an image or taking a screenshot, while watermarks are designed to remain inside the media itself.

Google DeepMind scientist Pushmeet Kohli told Ars Technica that Google built SynthID with expected attacks in mind and tested it against edits such as filtering and cropping. Google has not disclosed many technical details beyond its published paper on the system.

Does Google SynthID survive editing and compression?

Ars Technica tested SynthID by using the Python Pillow library to repeatedly compress and resize two Google AI images: one fully generated by Nano Banana Pro and one original photo altered with Google AI. The report said both carried SynthID watermarks at the start.

After 300 rounds of simulated sharing and recompression, Ars Technica said both full-frame images still triggered SynthID detection. The report also said a screenshot of the full image remained detectable because the watermark signal transferred into the new file.

The watermark eventually failed when heavy degradation was combined with cropping. Ars Technica reported that removing 20 percent of the image after 300 compression rounds made SynthID undetectable, while a 50 percent crop could defeat it after about 250 rounds.

That result suggests SynthID is more durable than some other watermarking efforts. Reuters recently found that Meta’s Content Seal watermark could often be removed by modest cropping, according to Ars Technica’s discussion of the issue.

Can Google SynthID stop AI misinformation?

Google does not describe SynthID as invulnerable. Ars Technica reported that Google’s original SynthID paper says the watermark was not designed to withstand adversarial attacks, and Kohli said Google has not been able to reproduce some claimed workarounds.

Access is another limit. Ars Technica said users must ask Gemini to run a SynthID check, because Google does not offer a public detector webpage or API. The report said Google limits users to about 10 image checks per day and may lock them out sooner when they upload many similar images.

Verification is also fragmented. Ars Technica reported that Google’s detector does not identify OpenAI’s SynthID-based watermark, and OpenAI’s detector does not identify Google’s watermark. A Google spokesperson told Ars Technica the company is working with industry partners toward a more unified verification system.

Starling Lab fellow and senior adviser Adam Rose told Ars Technica that AI media made outside large companies remains a central problem, because people can run models on their own computers without adding labels. Open image models already produce unlabeled content, according to the report.

Photojournalist and Starling fellow Mike Caronna told Ars Technica that authenticated real content may become more valuable than attempts to label every synthetic file. Ars Technica noted that Google’s Pixel phones are among the few mainstream cameras with deep C2PA support for photos and videos, including records of capture and AI edits.

The practical result is narrower than Google’s strongest test results might suggest. SynthID can help identify some AI media made through participating systems, but unlabeled generators, limited detectors and stripped metadata mean readers will still need provenance tools and caution when judging what is real.

This story draws on original reporting from Ars Technica.