Image & Video Generation

Google's SynthID Watermark Has Been Reverse Engineered

Rajat Gautam••9 min read•Updated
Share

Key Takeaways

  • →Denny's spectral method reported cutting SynthID carrier energy 75.8 percent and phase coherence 91.4 percent.
  • →A separate attack, UnMarker, reported 79 percent removal against SynthID; Google disputed the figure.
  • →The watermark still survives reposts, recompression, cropping, and casual edits.
  • →SynthID-Text removal exceeded 90 percent under a combined extraction and paraphrase attack.
  • →Treat a single watermark as one layer of evidence, not final proof, and layer it with C2PA metadata.
Google's SynthID Watermark Has Been Reverse Engineered

The short version: SynthID is not fully beaten, yet it has been taken apart and worked around in part, and Google argues the practical impact is smaller than it sounds. In April 2026, a developer named Alosh Denny put out a spectral-analysis technique that finds and removes SynthID's watermark from images produced by Gemini. A separate academic effort, UnMarker, said it removed the mark 79 percent of the time against SynthID in particular. Google has responded publicly to both, contending that real-world removal falls below the reported numbers, and no fix has been released. Below is what actually occurred, what remains true, and what it implies if your business counts on watermarking to prove that AI made a piece of content.

What SynthID actually is

SynthID is the watermarking system built by Google DeepMind. By Google's own account, it places an "invisible digital watermark" in AI-generated images and video, a mark "imperceptible to humans" that is meant to hold up against cropping, filters, frame-rate changes, and lossy compression. A different variant marks audio coming from Google's Lyria music model. A further one handles text from the Gemini app, nudging token probability scores in a manner a reader cannot see. In Google's May 19, 2026 update, the company reports that since SynthID launched three years earlier it has watermarked over 100 billion images and videos plus 60,000 years of audio, with verification spreading across the Gemini app, Search, and Chrome (Google's blog post).

Google's own documentation asserts durability but offers no independent checks of those claims, and it says nothing about the attacks described further down.

What the reverse engineering actually showed

Denny's approach rests on one insight: the signal SynthID embeds is not random noise. It is an ordered pattern, assembled from carrier frequencies sitting at an almost constant phase, so with a large enough image sample it can be pulled out through statistics. His published technique (code on GitHub) runs as follows:

  1. Gather a collection of watermarked reference images at one resolution. His public codebook contained around 100 black and 100 white reference images at 1024x1024, along with 88 watermarked images at 1536x2816, a second resolution.
  2. Apply a two-dimensional Fourier transform to those images and search for a steady pattern with little variation between them.
  3. After the carrier pattern is pinned down for a particular resolution and model, take it away from any fresh image carrying the SynthID watermark.

On the numbers reported, the technique produced a 75.8 percent fall in carrier energy and a 91.4 percent fall in phase coherence across the dominant carrier frequencies, with a PSNR of 43.5 dB and an SSIM of 0.997, which means to the human eye the cleaned output looks essentially identical to the source. Denny also created a detector to tell whether an image continues to hold the SynthID pattern, claiming about 90 percent accuracy, which lets the attack check itself. The code and those statistics sit in public where anyone can review them, and one third party has now checked them. Hacker Factor ported Denny's code to C, ran both that and the original Python against its own FotoForensics image collection, and found the detector "closer to 70%" rather than the claimed 90%, while judging that "even at 70%, this is still damning to Google's claims about resiliency and accuracy" (Hacker Factor). So the method reproduces, at a lower accuracy than its author reported.

Google's public answer has not been to admit the system is broken. The firm insists the watermark cannot be stripped out wholesale by standard techniques unless the image is harmed, and it questions how meaningful the reported results are in practice. It has released no revised figure of its own.

A separate attack, UnMarker, hits SynthID from a different angle

UnMarker, which Andre Kassis and Urs Hengartner of the University of Waterloo presented at the IEEE Symposium on Security and Privacy 2025, works through a different route: it attacks the spectral structure of an image head-on, with no need to identify the watermarking system in use and no reliance on feedback from a detector. Its authors reported a success rate of roughly 79 percent against SynthID in particular, and about 60 percent against newer alternatives such as StegaStamp and Tree-Ring, which held up considerably better, while older schemes such as HiDDeN and Yu2 "were entirely defeated". Across all the watermark types tested, removal ranged from 57 to 100 percent (IEEE Spectrum's coverage). Google publicly pushed back on the 79 percent figure, asserting that its own testing produced a "significantly lower" rate of success, though it never disclosed the number it found.

Because two separate, publicly documented attacks reach the watermark of an AI-generated image from opposite directions, this article says "reverse engineered and partly bypassed" instead of the more forceful term the research teams themselves occasionally reach for. Neither approach asserts a 100 percent, catch-all defeat of SynthID across every image and every situation.

SynthID-Text has its own, different weakness

Google's text-side watermark is distinct from the one used on images, and it carries a weakness of its own that has been carefully documented: paraphrasing. Researchers in ETH Zurich's SRI Lab discovered that targeted queries can reliably expose SynthID-Text (in their tests, spoofing attempts worked only about 4 percent of the time under ordinary conditions, climbing to roughly 15 percent when an attacker triples the query budget), yet the very features that stop spoofing leave it more open to another form of attack: pushing the watermarked text through a paraphrasing step. When extraction and paraphrase were combined, their reported removal rate went past 90 percent (SRI Lab's analysis). A further academic paper measuring how well SynthID-Text endures attacks arrives at a comparable conclusion, phrased less precisely: paraphrasing, copy-paste edits, and back-translation "can significantly degrade watermark detectability" (arXiv 2508.20228).

In practical terms: if your business leans on SynthID-Text to verify whether a passage was produced by Gemini, someone with enough determination can send it through a rewriting step and the mark will probably vanish.

What SynthID still does well

None of this makes the watermark pointless. Measured against Google's own stated design goals and against the attacks covered above, SynthID and comparable invisible watermarks still withstand:

  • A screenshot that is reposted as-is, with no editing, by someone unaware that watermark forensics exists
  • Routine re-compression (JPEG, standard video codecs)
  • Straightforward cropping and format conversion
  • Light-touch edits that do not rebuild or heavily reprocess the image

That accounts for a sizable portion of how AI-made content truly circulates out in the world: reposted, downloaded, screenshotted, yet never targeted on purpose. The one thing it does not account for is somebody deliberately running a tool that is freely available to remove the mark ahead of publishing.

What this means if you are shipping AI media

If your business has to establish whether content is or is not AI-generated, three conclusions follow from all of the above.

One. Do not treat any one watermark as proof on its own. Stack several: C2PA Content Credentials stored in the file's metadata, an invisible watermark within the pixels, a visible label in suitable places, and an internal audit trail of your own recording what was produced and when. Every layer gives way to a different type of attack, and that is precisely why more than one is worthwhile.

Two. Ask every vendor which watermarking method they deploy and which of its limitations are known. A vendor claiming their invisible watermark cannot be broken is either ignorant of the public research described earlier or counting on you being so. In either case, read that as a cue to press further with more questions.

Three. The law still asks for machine-readable provenance, no matter how durable a watermark proves to be. Under the EU AI Act, the Article 50(2) obligation to mark AI-generated content counted among the provisions touched by the 2026 EU Digital Omnibus timeline changes, whereas the remaining Article 50 transparency duties continue on their original timetable. That legal point deserves to be checked against the current text for your own situation rather than lifted from any one blog post, this one included. What stays fixed is the underlying reality: a lasting compliance approach should rest primarily on C2PA-style manifest metadata, treating the invisible watermark as supporting, not standalone, evidence.

The honest summary

SynthID has neither been shown to be unbreakable nor shown to be useless. Against it stand a public, auditable method that removes most of its signal from images with no visible harm, a separate academic attack reporting a comparable outcome through another route, and a clearly documented vulnerability to paraphrasing on the text side. Google contests how much any of this counts in the real world, and no patched release has appeared. Until one does, the sensible stance for anybody distributing AI media is to view any single watermark, from any vendor, as just one layer of evidence and never as conclusive proof, and to design the remainder of the provenance stack on that basis.

Keep reading

To place this within the wider AI video market, look at AI video generation in 2026 and our comparison of AI video tools. If you are putting together a provenance or content-authentication pipeline and would value a fresh pair of eyes on the plan, our enterprise AI service handles exactly this type of work, or book a strategy call to go over one particular choice.

Frequently Asked Questions

Has SynthID actually been broken or is that overstated?+
SynthID has been reverse engineered and partly bypassed, not cleanly defeated. Denny's spectral method reported a 75.8 percent drop in carrier energy and a 91.4 percent drop in phase coherence, and UnMarker reported 79 percent removal. Google disputes both, saying real-world removal is lower, and has not shipped a fix. Neither method claims a universal defeat of every image.
Should we stop using SynthID-watermarked AI media?+
Google's durability claims still hold against reposts, recompression, cropping, and casual edits, which covers most real-world spread. The article does not advise stopping, it advises treating any single watermark as one layer of evidence rather than final proof. Layer C2PA metadata, a visible label, and your own audit trail.
Does the SynthID break affect EU AI Act Article 50 compliance?+
Under the EU AI Act, the Article 50(2) marking obligation was affected by the 2026 EU Digital Omnibus timeline changes, while other Article 50 transparency duties run on their original schedule. The article notes the current legal text should be checked for your specific case. It recommends C2PA manifest metadata as the primary record, with invisible watermarking as a secondary layer.
Are there any AI watermarks that actually survive a determined adversary?+
No invisible watermark is shown to survive a determined adversary with a public stripping tool. Neither Denny's method nor UnMarker claims a 100 percent universal defeat, but each fails to a different kind of attack. That is why the article recommends multiple layers: C2PA metadata, an invisible watermark, a visible label, and an internal audit trail.
Where does the SynthID break leave studios and broadcasters that depend on AI media provenance?+
The article advises any business shipping AI media to treat a single watermark as one layer of evidence, not final proof. It recommends layering C2PA metadata, an invisible watermark, a visible label, and an internal audit trail, since each layer fails to a different attack. Until Google ships a fix, provenance-dependent teams should build the rest of the stack around that assumption.

Designing a layered AI provenance pipeline before the December 2 EU AI Act watermarking deadline? We build C2PA + watermark + audit-trail stacks for premium-buyer engagements.

Explore Enterprise AI

About the Author

Rajat Gautam

Rajat Gautam

AI Engineer and Consultant

My work goes far beyond recommending tools - I design AI systems that integrate directly into your workflows, eliminate inefficiencies, and deliver measurable business impact. Every solution I build is tailored, practical, and built with long-term scalability in mind.

Need help with this?

Related Topics

SynthID
AI Watermarking
C2PA
Analysis
AI Provenance

Related Articles

Ready to transform your business with AI? Let's talk strategy.

Book a Free Strategy Call