
Google's SynthID survives 300 rounds of compression but a 20% crop kills it
Ryan Whitwam put AI-generated and AI-edited images through 300+ randomized compression and resize cycles and SynthID detection held even after the images degraded into near-unrecognizable blobs, surviving screenshots too — but a 20% border crop defeated it. Robustness is real and a disinformation defense still is not: Google's detector cannot read OpenAI's watermark, open models emit unmarked output indefinitely, and a missing mark reads as proof of human origin, which is why Ars favors C2PA provenance metadata over detection.
Source: arstechnica.com ↗
It took until 1975—149 years after the invention of the camera—for humanity to create 1.5 billion images. It took generative AI just 18 months to do the same.
Starling Lab (Stanford/USC)
Why this matters
- → SynthID watermarks survive heavy editing but 20% crops defeat them entirely
- → Generative AI produces 1.5 billion images every 18 months — detection scales or fails catastrophically
- → Invisible watermarks alone cannot stop AI disinformation without cryptographic provenance metadata
Watermarks vs. scale