Thread links spymarking to past printer-tracking exposure
4 Sep 21 10:39 PM · 2d ago · 2 posts · 4 comments · 2 sources · development 4 of 4
Commenters draw parallels to steganography and cite a historical case of a leaker identified via hidden printer tracking dots, broadening the discussion beyond AI-specific tools to tracking technology generally.
Google Developer of SynthIDOpenAI Developer of similar tracking/watermarking systemspossibilistic Hacker News submitter of the essayminimaxir HN commenter, tool developer
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
What people said 24 voices · best of 31 · verbatim
-
I feel like there’s some security engineering calculus that would be useful here?You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?There must be value in having a visible vs an…
-
N
Spymarks, Not Watermarks: https:// brand.io/article/spymarks/ Discussion: http:// news.ycombinator.com/item?id=4 9794615
-
Spymarks just seem like another word for https://en.wikipedia.org/wiki/Steganography. On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have produced (for example: a camera we are certain does not watermark, an image editor we are certain doesn't…
-
This is a straightforward example of how the positive or negative valence of a piece of tech depends entirely on how it's used.You just need to address three questions:- who controls what information is going in? (that is, what is the process by which the tech companies who control all the tech are using it)- who controls what information is…
-
> ... particularly concerned about is social media. Most images and videos uploaded to most social media is re-compressed by the target platform. This is a door to tracking that is far too easy for social media platforms to open.This has been going on for a while with Facebook. They seem to embed custom metadata tags so that images shared outside…
-
Spymarks an application of steganography, not a different name for it.> On that note, one way we can prevent it is to assert that all our content is byte-for-byte identical with the last known trusted stage of what we have producedThat doesn't help with things like the typical use of SynthID where the spymarking is done by the same process…
-
Thanks for the article. I hadn't heard of SynthID before and it's good to.It's a shame however, how low quality and vibecoded the live examples are. The first example says "Toy example; not SynthID.", the second one is a generic spectrogram and the third one has an identification space too small to be useful (173 in decimal). I was hoping to see…
-
Imagine these being used as DLP. Each service consuming/publishing content can scan for its spymark/watermark which reference parameters instructing the service on allowed use, revocation etc.Seems like a wet dream for DRM with lots of possible uses that may be considered bad, but there's also some potential to have it be used to better control…
-
Reminds me of Blizzard embedding data inside World of Warcraft screenshots (link goes to a small write-up from 2012 in a forum focused on video game cheats; sorry, could not find a better source):
-
I actually wrote a library to do stego with LLM outputs last year and it turned out to be an almost exact implementation of the Anthropic watermark algo.Repo here https://github.com/sutt/innocuous. It works with last year's llama.cpp. Check out the "Use Cases" and "How it works" sections in the readme if you're interested.
-
They're the simplest way to be automatically able to track AI generated text and I very much love them being used for that, it would be pretty cool if _all_ AIs were forced from training to include these things into their output.The "tracking" bit is kind of nefarious, but that can be removed as a concern if the thing that is being tracked is…
-
The vulnerability of steganography is that is has to pretend that signal is noise. Remove the noise - and the signal is gone. I'm pretty sure that the simplest gaussian blur will remove the spymark from any picture.Or... add some noise. Just align the last bit of every pixel channel with a random bit sequence - and Bob's your uncle.
-
A number of prominent corporations used to embed these in the background images of their internal webpages, so that leakers could be identified from the screenshots they shared. Caused a whole fun adversarial loop where journalists had to transcribed and/or redraw screenshots before publishing to avoid exposing the identity of leakers...
-
> Spymarks are certainly not great for whistleblowers or anyone who doesn’t want to be persecuted for their words or affiliations. No matter where you stand on whatever issues, spymarks can be used against you and those you care about.How do you spymark text that someone else wrote? You can't change the words or they'd notice
-
On the one hand, I 100% want AI-generated videos, images, text, etc to come with some kind of 'spymark'.On the other hand, no matter how robust that solution is, inevitably someone will come up with a way to bypass it, strip them out, etc - so would it really be useful in the long run?
-
"A spymark is a hidden signal that makes your work traceable"Not a single example provided of anything that could be honestly called "your work", just a bizarre attempt to stigmatize accurate detection of genAI output.What was that PG bit about "submarining"?
-
Don't media companies do something like this to track which employee might have leaked films/TV shows/video game trailers/etc online?I recall they had separately watermarked versions of these to make it easier to figure out how things were being leaked.
-
Spooky stuff. This will take surveillance to a whole new level. This is basically email read-receipt tracker, but for all of the digital content. They will know the whole trail - from originator to how it spread. Who read what and when. Big brother will always be watching.
-
> Spymarks just seem like another word for https://en.wikipedia.org/…Stop using links instead of words. Your comment is literally unreadable without going on to other websites.
-
A lot of the discussion is about AI vs no AI, which is valid, but I care about local AI vs centralized AI. Hopefully hardware will become more affordable. A hopefully irrational fear I have is that it'll be like house prices: only ever goes up.
-
Cool. Interesting. It is interesting that these nefarious things are now considered acceptable in order to protect people from AI-generated text… I fear the consequences of this widespread acceptance.
-
Tbh I usually just apply a 'watermark' of jpg compression to images, even if yes the original image never lives as jpg. Easily viewable with ELA even if saved as other formats, resized, etc.
-
Wouldn't synthid type watermarking fall under GDPR. Personally identifiable information attached by third party to content in the expectation that it would be published and trackable?
-
Apple rejected my app for removing c2pa metadata.I don't think its fair to say that metadata on apps will be safely removable in the future.
All 4 developments of Blog essay renames AI "watermarks" as "spymarks," HN… →
Hacker NewsMastodonNewswires