Google's SynthID Watermark Has Been Reverse Engineered
Key Takeaways
- →Denny's spectral method reported cutting SynthID carrier energy 75.8 percent and phase coherence 91.4 percent.
- →A separate attack, UnMarker, reported 79 percent removal against SynthID; Google disputed the figure.
- →The watermark still survives reposts, recompression, cropping, and casual edits.
- →SynthID-Text removal exceeded 90 percent under a combined extraction and paraphrase attack.
- →Treat a single watermark as one layer of evidence, not final proof, and layer it with C2PA metadata.

On this page⌄
The short version: SynthID is not fully beaten, yet it has been taken apart and worked around in part, and Google argues the practical impact is smaller than it sounds. In April 2026, a developer named Alosh Denny put out a spectral-analysis technique that finds and removes SynthID's watermark from images produced by Gemini. A separate academic effort, UnMarker, said it removed the mark 79 percent of the time against SynthID in particular. Google has responded publicly to both, contending that real-world removal falls below the reported numbers, and no fix has been released. Below is what actually occurred, what remains true, and what it implies if your business counts on watermarking to prove that AI made a piece of content.
What SynthID actually is
SynthID is the watermarking system built by Google DeepMind. By Google's own account, it places an "invisible digital watermark" in AI-generated images and video, a mark "imperceptible to humans" that is meant to hold up against cropping, filters, frame-rate changes, and lossy compression. A different variant marks audio coming from Google's Lyria music model. A further one handles text from the Gemini app, nudging token probability scores in a manner a reader cannot see. In Google's May 19, 2026 update, the company reports that since SynthID launched three years earlier it has watermarked over 100 billion images and videos plus 60,000 years of audio, with verification spreading across the Gemini app, Search, and Chrome (Google's blog post).
Google's own documentation asserts durability but offers no independent checks of those claims, and it says nothing about the attacks described further down.
What the reverse engineering actually showed
Denny's approach rests on one insight: the signal SynthID embeds is not random noise. It is an ordered pattern, assembled from carrier frequencies sitting at an almost constant phase, so with a large enough image sample it can be pulled out through statistics. His published technique (code on GitHub) runs as follows:
- Gather a collection of watermarked reference images at one resolution. His public codebook contained around 100 black and 100 white reference images at 1024x1024, along with 88 watermarked images at 1536x2816, a second resolution.
- Apply a two-dimensional Fourier transform to those images and search for a steady pattern with little variation between them.
- After the carrier pattern is pinned down for a particular resolution and model, take it away from any fresh image carrying the SynthID watermark.
On the numbers reported, the technique produced a 75.8 percent fall in carrier energy and a 91.4 percent fall in phase coherence across the dominant carrier frequencies, with a PSNR of 43.5 dB and an SSIM of 0.997, which means to the human eye the cleaned output looks essentially identical to the source. Denny also created a detector to tell whether an image continues to hold the SynthID pattern, claiming about 90 percent accuracy, which lets the attack check itself. The code and those statistics sit in public where anyone can review them, and one third party has now checked them. Hacker Factor ported Denny's code to C, ran both that and the original Python against its own FotoForensics image collection, and found the detector "closer to 70%" rather than the claimed 90%, while judging that "even at 70%, this is still damning to Google's claims about resiliency and accuracy" (Hacker Factor). So the method reproduces, at a lower accuracy than its author reported.
Google's public answer has not been to admit the system is broken. The firm insists the watermark cannot be stripped out wholesale by standard techniques unless the image is harmed, and it questions how meaningful the reported results are in practice. It has released no revised figure of its own.
A separate attack, UnMarker, hits SynthID from a different angle
UnMarker, which Andre Kassis and Urs Hengartner of the University of Waterloo presented at the IEEE Symposium on Security and Privacy 2025, works through a different route: it attacks the spectral structure of an image head-on, with no need to identify the watermarking system in use and no reliance on feedback from a detector. Its authors reported a success rate of roughly 79 percent against SynthID in particular, and about 60 percent against newer alternatives such as StegaStamp and Tree-Ring, which held up considerably better, while older schemes such as HiDDeN and Yu2 "were entirely defeated". Across all the watermark types tested, removal ranged from 57 to 100 percent (IEEE Spectrum's coverage). Google publicly pushed back on the 79 percent figure, asserting that its own testing produced a "significantly lower" rate of success, though it never disclosed the number it found.
Because two separate, publicly documented attacks reach the watermark of an AI-generated image from opposite directions, this article says "reverse engineered and partly bypassed" instead of the more forceful term the research teams themselves occasionally reach for. Neither approach asserts a 100 percent, catch-all defeat of SynthID across every image and every situation.
SynthID-Text has its own, different weakness
Google's text-side watermark is distinct from the one used on images, and it carries a weakness of its own that has been carefully documented: paraphrasing. Researchers in ETH Zurich's SRI Lab discovered that targeted queries can reliably expose SynthID-Text (in their tests, spoofing attempts worked only about 4 percent of the time under ordinary conditions, climbing to roughly 15 percent when an attacker triples the query budget), yet the very features that stop spoofing leave it more open to another form of attack: pushing the watermarked text through a paraphrasing step. When extraction and paraphrase were combined, their reported removal rate went past 90 percent (SRI Lab's analysis). A further academic paper measuring how well SynthID-Text endures attacks arrives at a comparable conclusion, phrased less precisely: paraphrasing, copy-paste edits, and back-translation "can significantly degrade watermark detectability" (arXiv 2508.20228).
In practical terms: if your business leans on SynthID-Text to verify whether a passage was produced by Gemini, someone with enough determination can send it through a rewriting step and the mark will probably vanish.
What SynthID still does well
None of this makes the watermark pointless. Measured against Google's own stated design goals and against the attacks covered above, SynthID and comparable invisible watermarks still withstand:
- A screenshot that is reposted as-is, with no editing, by someone unaware that watermark forensics exists
- Routine re-compression (JPEG, standard video codecs)
- Straightforward cropping and format conversion
- Light-touch edits that do not rebuild or heavily reprocess the image
That accounts for a sizable portion of how AI-made content truly circulates out in the world: reposted, downloaded, screenshotted, yet never targeted on purpose. The one thing it does not account for is somebody deliberately running a tool that is freely available to remove the mark ahead of publishing.
What this means if you are shipping AI media
If your business has to establish whether content is or is not AI-generated, three conclusions follow from all of the above.
One. Do not treat any one watermark as proof on its own. Stack several: C2PA Content Credentials stored in the file's metadata, an invisible watermark within the pixels, a visible label in suitable places, and an internal audit trail of your own recording what was produced and when. Every layer gives way to a different type of attack, and that is precisely why more than one is worthwhile.
Two. Ask every vendor which watermarking method they deploy and which of its limitations are known. A vendor claiming their invisible watermark cannot be broken is either ignorant of the public research described earlier or counting on you being so. In either case, read that as a cue to press further with more questions.
Three. The law still asks for machine-readable provenance, no matter how durable a watermark proves to be. Under the EU AI Act, the Article 50(2) obligation to mark AI-generated content counted among the provisions touched by the 2026 EU Digital Omnibus timeline changes, whereas the remaining Article 50 transparency duties continue on their original timetable. That legal point deserves to be checked against the current text for your own situation rather than lifted from any one blog post, this one included. What stays fixed is the underlying reality: a lasting compliance approach should rest primarily on C2PA-style manifest metadata, treating the invisible watermark as supporting, not standalone, evidence.
The honest summary
SynthID has neither been shown to be unbreakable nor shown to be useless. Against it stand a public, auditable method that removes most of its signal from images with no visible harm, a separate academic attack reporting a comparable outcome through another route, and a clearly documented vulnerability to paraphrasing on the text side. Google contests how much any of this counts in the real world, and no patched release has appeared. Until one does, the sensible stance for anybody distributing AI media is to view any single watermark, from any vendor, as just one layer of evidence and never as conclusive proof, and to design the remainder of the provenance stack on that basis.
Keep reading
To place this within the wider AI video market, look at AI video generation in 2026 and our comparison of AI video tools. If you are putting together a provenance or content-authentication pipeline and would value a fresh pair of eyes on the plan, our enterprise AI service handles exactly this type of work, or book a strategy call to go over one particular choice.
Frequently Asked Questions
Has SynthID actually been broken or is that overstated?+
Should we stop using SynthID-watermarked AI media?+
Does the SynthID break affect EU AI Act Article 50 compliance?+
Are there any AI watermarks that actually survive a determined adversary?+
Where does the SynthID break leave studios and broadcasters that depend on AI media provenance?+
Designing a layered AI provenance pipeline before the December 2 EU AI Act watermarking deadline? We build C2PA + watermark + audit-trail stacks for premium-buyer engagements.
Explore Enterprise AIAbout the Author

Rajat Gautam
AI Engineer and Consultant
My work goes far beyond recommending tools - I design AI systems that integrate directly into your workflows, eliminate inefficiencies, and deliver measurable business impact. Every solution I build is tailored, practical, and built with long-term scalability in mind.
Need help with this?
Visuals
AI Cinematic and Motion Design
We build the video system: brand templates, avatar and voice setup, and the review gate that keeps every output on standard. Your team produces the volume once it is built.
Explore service →
Visuals
AI Product Photography
We build the image pipeline for your catalogue: your SKUs, your look, your brand rules, wired into your product feed. Once it is built, your team runs the volume.
Explore service →
Related Topics
Related Articles



Ready to transform your business with AI? Let's talk strategy.
Book a Free Strategy Call