In short
- SynthID-Image is the largest deployment. It marks images as AI-generated: a disclosure, not a signature of ownership.
- Ordinary handling is mostly solved. Regeneration through a generative model is not.
- No invisible mark is permanent against a motivated adversary. Its job is to let an honest viewer find the credential.
SynthID is everywhere now
SynthID-Image is the largest deployment. Google DeepMind's October 2025 report describes watermarking over ten billion images and video frames across Google products. The externally available variant, SynthID-O, encodes a 136-bit payload in a 512 × 512 image. The detector uses conformal p-values calibrated on held-out sets so false positives can be pinned very low, with the detector abstaining when unsure. It is designed to survive cropping, compression, filtering and screenshots.1
Verification is available to trusted testers rather than the public, and as of May 2026 OpenAI pairs SynthID with C2PA on its own outputs.1,6
Note the purpose. SynthID marks images as AI-generated. It is a disclosure, not a signature of ownership. That distinction is the ethical floor of this product: deprint reports a SynthID mark and never removes one.
Where the ideas came from
The lineage runs through three ideas. Tree-Ring (NeurIPS 2023) plants a pattern in the diffusion model's initial noise, structured in Fourier space so it survives crops, flips and rotations.2 Stable Signature (Meta) fine-tunes the model's decoder so every output carries a fixed signature. Adobe's TrustMark (ICCV 2025) is a post-hoc encoder for any image at any resolution, holding quality above 43 dB PSNR while resisting both in-place and geometric edits.3
TrustMark is the family deprint's own mark belongs to, since a photograph has no diffusion process to hide a pattern in.
How much can a mark carry?
Payload is the number of bits a watermark holds. Zero bits means only "present or not". Around a hundred is enough for an identifier that can be looked up, which is all a pointer to a credential needs.
Single series, so no legend. Ours is at full strength, the rest are stepped back. Zero is drawn as a hollow ring, never an invisible bar. The deprint figure is a design target.
A dot plot, not bars: F1 is a score, not a quantity that grows from zero. The 20× figure is reported as approximately random, so it sits on the coin-flip line.
| Method | Owner | Payload (bits) | Min. image (px) | Quality (PSNR dB) | Published |
|---|---|---|---|---|---|
| SynthID-O | Google DeepMind | 136 | 512 | — | Oct 2025 |
| TrustMark | Adobe | ~100 | any | > 43 | ICCV 2025 |
| Stable Signature | Meta | 48 | — | — | 2023 |
| Tree-Ring | UMD | 0 | — | — | NeurIPS 2023 |
| deprint mark | the maker | 96 | 256 | > 42 | target |
Table 2A dash means the paper does not report it, never a zero. The deprint row is a design target, not a measurement.
How marks get broken
The attacks are well mapped. A December 2024 survey of StegaStamp, Tree-Ring, Stable Signature and Latent Watermark finds that simple distortions are mostly handled, but regeneration attacks, where an image is passed through a diffusion autoencoder and re-synthesised, degrade post-hoc marks badly. Semantic-level marks like Tree-Ring fare better against regeneration but worse against targeted forgery.4
On the text side, an August 2025 study showed SynthID-Text loses most of its signal to paraphrase and copy-paste dilution, which is why layered approaches are winning.5
So what should a maker do?
No invisible mark is permanent against a motivated adversary with a generative model. The mark's job is to survive ordinary handling so an honest viewer can find the credential. For adversaries, the credential's cryptography and your published manifest are what you point to.
Sources
- SynthID-Image: Image watermarking at internet scale, Google DeepMind, arXiv, Oct 2025
- Tree-Ring Watermarks, NeurIPS 2023
- TrustMark, Adobe Research, ICCV 2025
- Invisible Watermarks: Attacks and Robustness, arXiv, Dec 2024
- Robustness Assessment of Text Watermarking for SynthID, arXiv, Aug 2025
- C2PA adoption in 2026: hardware, platforms and verification, SoftwareSeni