SynthID-Image: Image watermarking at internet scale

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gowal, Sven, Bunel, Rudy, Stimberg, Florian, Stutz, David, Ortiz-Jimenez, Guillermo, Kouridi, Christina, Vecerik, Mel, Hayes, Jamie, Rebuffi, Sylvestre-Alvise, Bernard, Paul, Gamble, Chris, Horváth, Miklós Z., Kaczmarczyck, Fabian, Kaskasoli, Alex, Petrov, Aleksandar, Shumailov, Ilia, Thotakuri, Meghana, Wiles, Olivia, Yung, Jessica, Ahmed, Zahra, Martin, Victor, Rosen, Simon, Savčak, Christopher, Senoner, Armin, Vyas, Nidhi, Kohli, Pushmeet
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915544499748864
author Gowal, Sven
Bunel, Rudy
Stimberg, Florian
Stutz, David
Ortiz-Jimenez, Guillermo
Kouridi, Christina
Vecerik, Mel
Hayes, Jamie
Rebuffi, Sylvestre-Alvise
Bernard, Paul
Gamble, Chris
Horváth, Miklós Z.
Kaczmarczyck, Fabian
Kaskasoli, Alex
Petrov, Aleksandar
Shumailov, Ilia
Thotakuri, Meghana
Wiles, Olivia
Yung, Jessica
Ahmed, Zahra
Martin, Victor
Rosen, Simon
Savčak, Christopher
Senoner, Armin
Vyas, Nidhi
Kohli, Pushmeet
author_facet Gowal, Sven
Bunel, Rudy
Stimberg, Florian
Stutz, David
Ortiz-Jimenez, Guillermo
Kouridi, Christina
Vecerik, Mel
Hayes, Jamie
Rebuffi, Sylvestre-Alvise
Bernard, Paul
Gamble, Chris
Horváth, Miklós Z.
Kaczmarczyck, Fabian
Kaskasoli, Alex
Petrov, Aleksandar
Shumailov, Ilia
Thotakuri, Meghana
Wiles, Olivia
Yung, Jessica
Ahmed, Zahra
Martin, Victor
Rosen, Simon
Savčak, Christopher
Senoner, Armin
Vyas, Nidhi
Kohli, Pushmeet
contents We introduce SynthID-Image, a deep learning-based system for invisibly watermarking AI-generated imagery. This paper documents the technical desiderata, threat models, and practical challenges of deploying such a system at internet scale, addressing key requirements of effectiveness, fidelity, robustness, and security. SynthID-Image has been used to watermark over ten billion images and video frames across Google's services and its corresponding verification service is available to trusted testers. For completeness, we present an experimental evaluation of an external model variant, SynthID-O, which is available through partnerships. We benchmark SynthID-O against other post-hoc watermarking methods from the literature, demonstrating state-of-the-art performance in both visual quality and robustness to common image perturbations. While this work centers on visual media, the conclusions on deployment, constraints, and threat modeling generalize to other modalities, including audio. This paper provides a comprehensive documentation for the large-scale deployment of deep learning-based media provenance systems.
format Preprint
id arxiv_https___arxiv_org_abs_2510_09263
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SynthID-Image: Image watermarking at internet scale
Gowal, Sven
Bunel, Rudy
Stimberg, Florian
Stutz, David
Ortiz-Jimenez, Guillermo
Kouridi, Christina
Vecerik, Mel
Hayes, Jamie
Rebuffi, Sylvestre-Alvise
Bernard, Paul
Gamble, Chris
Horváth, Miklós Z.
Kaczmarczyck, Fabian
Kaskasoli, Alex
Petrov, Aleksandar
Shumailov, Ilia
Thotakuri, Meghana
Wiles, Olivia
Yung, Jessica
Ahmed, Zahra
Martin, Victor
Rosen, Simon
Savčak, Christopher
Senoner, Armin
Vyas, Nidhi
Kohli, Pushmeet
Cryptography and Security
Artificial Intelligence
We introduce SynthID-Image, a deep learning-based system for invisibly watermarking AI-generated imagery. This paper documents the technical desiderata, threat models, and practical challenges of deploying such a system at internet scale, addressing key requirements of effectiveness, fidelity, robustness, and security. SynthID-Image has been used to watermark over ten billion images and video frames across Google's services and its corresponding verification service is available to trusted testers. For completeness, we present an experimental evaluation of an external model variant, SynthID-O, which is available through partnerships. We benchmark SynthID-O against other post-hoc watermarking methods from the literature, demonstrating state-of-the-art performance in both visual quality and robustness to common image perturbations. While this work centers on visual media, the conclusions on deployment, constraints, and threat modeling generalize to other modalities, including audio. This paper provides a comprehensive documentation for the large-scale deployment of deep learning-based media provenance systems.
title SynthID-Image: Image watermarking at internet scale
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2510.09263