I Tested Google’s New AI-Powered Image Recognition Algorithm, and It’s Difficult (but Not Impossible) to Fool.

These days, we’re all faced with an abundance of AI-generated images—from school posters to restaurant menus—and while some signs that an image is AI-generated are still present, they’re not always obvious. In many cases, distinguishing an AI-generated image from the real thing is nearly impossible.

This is a problem for a variety of reasons, and that’s why AI companies are trying to solve it. Images generated by Gemini and ChatGPT contain an invisible watermark called SynthID . This means AI-generated images don’t require visible markings to identify their origin. Of course, detecting the presence of this watermark requires a detector. As it happens, Google recently launched a standalone SynthID verification tool online, free for anyone to use. I tried “SynthID Detector,” and while it mostly works as expected, it’s not perfect.

How Google’s SynthID detector works

SynthID does not guarantee consistent AI detection. Source: Lifehacker

Gemini has been allowing you to upload images and check whether they were created by AI for some time now. The new online portal makes it even easier—though you still need to sign in with your Google account. Once logged in, you can check a wide variety of files. This tool supports JPG, JPEG, PNG, BMP, WEBP, AVIF, HEIC, HEIF, TIFF, TIF, and GIF image formats; MP4, MOV, and WEBM video; and WAV, MP3, OGG, FLAC, AAC, and M4A audio. If a file was created by AI that supports SynthID, it should have a watermark. (The SynthID watermark is a standard supported by Nvidia, OpenAI, Kakao, and Google, although OpenAI hasits own detection tool .)

You may also like

Google doesn’t explain exactly how SynthID works, presumably to make it harder to circumvent, but it confirms that the watermark is “resistant to common transformations.” The company also states that the watermark is “embedded in the content itself,” meaning in the pixels for images and videos, and in the frequency components for audio. The company also acknowledges that its detection tool isn’t infallible. What it calls “heavy modifications” can degrade the watermark’s quality, as can multiple “transformations” applied to the same image. It’s recommended to use the highest possible quality files, so I imagine the more data, the more reliable the detection (similar to AI-based text detectors).

Google also claims that SynthID watermarks are “invisible” to humans, so you don’t need to look for them or listen for them—they’re only detectable using an AI-powered detection tool like this one. If you’re creating images, videos, or audio using AI, watermarks shouldn’t affect the quality of the final result in any way.

Testing SynthID Detector in Practice

I started with a few simple tests. The detector correctly identified that the images created in Gemini and ChatGPT and downloaded directly to disk were indeed fake. Confirmation took just a few seconds, and it also identified the AI ​​tool used to create them.

It also correctly flagged one of my photos as not containing AI, though it was a bit evasive, stating that it was “unlikely” the media file was created by AI. All the detector could say with certainty was the absence of a SynthID watermark, indicating that it was specifically checking for that watermark. It wasn’t looking for any other signs of AI.

What do you think at the moment?

In most tests, the detector worked flawlessly. Source: Lifehacker

I then tried taking screenshots of the same AI-generated images, and the detector correctly identified them as being from Google and Anthropic’s AI tools. This demonstrates that something is hidden deep in the pixels, not in the file’s metadata itself, which is what the SynthID watermark reveals. Simply copying and pasting won’t work around this. Applying the “oil painting” filter in Photoshop to the AI ​​image didn’t confuse the detector, nor did adding a slight blur. Adjusting the color, contrast, and tone had no effect, and the detector still detected SynthID when I cropped and merged two different AI images: one from Gemini and one from ChatGPT.

Ultimately, I managed to fool the detector. Once, when I heavily pixelated an AI-generated image—in which case, I suspect, my disinformation campaign would still have been quite ineffective—and again, when I created a composite image that was 75% real images and 25% AI-generated images. With fewer AI objects, the detector might fail.

In this photo, only the man in the foreground is artificial intelligence, but the detector identified him as fake. Source: Lifehacker

Based on this result, I used ChatGPT to add another person to the authentic group photo, although this time the tool detected SynthID—despite the fact that a smaller portion of the image was AI-generated. Images that are only partially AI-generated may require some rework, which is understandable, as the detector has less data to work with.

There’s a limit, apparently around 10 files per day—10 each for images, videos, and audio files. Once you reach the limit, you must wait 24 hours before trying again. As far as I understand, SynthID Detector is exactly what Google describes: a useful test, but far from a guarantee of success or failure.

More…

Leave a Reply