Google DeepMind's SynthID AI Watermark Defeated by Amateur Researcher
Is this a scandal?
No longer — the story has resolved. Noise 1/100, cooling down, across 1 source.
Google will likely be forced to update SynthID to use dynamic or per-user phase templates, which will significantly increase computational overhead. Expect a broader industry shift toward cryptographic signing, like C2PA, rather than relying solely on pixel-level watermarking which has now been proven fragile.
Noise 1/100 — louder than 90% of tracked AI controversies.
Why it matters
Demonstrates current AI provenance standards are cryptographically fragile against targeted spectral analysis, undermining trust in content authentication.
Key points
- Developer Alosh Denny published an open-source phase shift attack that removes SynthID watermarks.
- The exploit achieved a 91% phase coherence drop and 75% carrier energy reduction in tests.
- The attack uses spectral analysis of multiple samples to reverse-engineer the embedding pattern.
- Third-party tool Rephrasy has since released a remover specifically targeting SynthID text patterns.
- SynthID was previously considered robust against standard compression but failed against targeted frequency attacks.
The story
A software developer has published an open-source method to remove Google DeepMind’s SynthID watermark from AI-generated images using a spectral phase shift attack. Developer Alosh Denny demonstrated that the technique achieves a 91% drop in phase coherence and 75% reduction in carrier energy, effectively stripping the invisible provenance signal. The exploit relies on analyzing multiple generated samples to reverse-engineer the embedding pattern rather than breaking encryption keys. While Google designed SynthID to survive standard image compression and cropping, this specific mathematical approach targets the underlying frequency domain where the watermark resides. Third-party tools like Rephrasy have already adapted similar removal techniques for text-based SynthID implementations. This development highlights significant vulnerabilities in statistical watermarking systems currently deployed as industry-standard safety measures against synthetic media misuse.
Who's involved
Argues that Google built a 'tell' rather than secure authentication by using a fixed pattern across billions of outputs.
Maintains that SynthID is a robust tool for AI safety and content provenance, though currently facing technical scrutiny.
Noise Level
The timeline
Vulnerability Disclosed
An engineer publishes a method to isolate and remove the watermark using 200 black images and signal processing.
Google Launches SynthID
DeepMind introduces SynthID as a robust, invisible watermark for AI-generated images.
The full record
Sources & methodology
- One researcher beat Google's watermark with a math trick. ... — x.com · located later (2026-07-30)
- Google's SynthID AI Watermark Bypassed by Open Source ... — startupfortune.com · located later (2026-07-30)
- How Google's SynthID AI Watermark Was Reverse ... — stork.ai · located later (2026-07-30)
- Has Google's AI watermarking system been reverse- ... — theverge.com · located later (2026-07-30)
- SynthID Detector & Watermark Remover — rephrasy.ai · located later (2026-07-30)
- Someone tried to remove SynthID watermarks before? — reddit.com · located later (2026-07-30)
- Google's AI Watermark Was Cracked. Here's What That ... — dev.to · located later (2026-07-30)
The records from this story's original coverage were pruned, so items marked located later were found by searching for it afterwards. The summary above has since been rewritten to take them into account — it is not the text first published. How we score →
The forecast
Google will likely be forced to update SynthID to use dynamic or per-user phase templates, which will significantly increase computational overhead. Expect a broader industry shift toward cryptographic signing, like C2PA, rather than relying solely on pixel-level watermarking which has now been proven fragile.
Forecast, not fact — an editorial estimate we score when this resolves.
That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.
Join the Discussion
Discuss this story
Community comments coming in a future update
Be the first to share your perspective. Subscribe to comment.