Research/Field note

What invisible watermarks survive in 2026

In short

  • SynthID-Image is the largest deployment. It marks images as AI-generated: a disclosure, not a signature of ownership.
  • Ordinary handling is mostly solved. Regeneration through a generative model is not.
  • No invisible mark is permanent against a motivated adversary. Its job is to let an honest viewer find the credential.

SynthID is everywhere now

SynthID-Image is the largest deployment. Google DeepMind's October 2025 report describes watermarking over ten billion images and video frames across Google products. The externally available variant, SynthID-O, encodes a 136-bit payload in a 512 × 512 image. The detector uses conformal p-values calibrated on held-out sets so false positives can be pinned very low, with the detector abstaining when unsure. It is designed to survive cropping, compression, filtering and screenshots.1

Verification is available to trusted testers rather than the public, and as of May 2026 OpenAI pairs SynthID with C2PA on its own outputs.1,6

Note the purpose. SynthID marks images as AI-generated. It is a disclosure, not a signature of ownership. That distinction is the ethical floor of this product: deprint reports a SynthID mark and never removes one.

Where the ideas came from

The lineage runs through three ideas. Tree-Ring (NeurIPS 2023) plants a pattern in the diffusion model's initial noise, structured in Fourier space so it survives crops, flips and rotations.2 Stable Signature (Meta) fine-tunes the model's decoder so every output carries a fixed signature. Adobe's TrustMark (ICCV 2025) is a post-hoc encoder for any image at any resolution, holding quality above 43 dB PSNR while resisting both in-place and geometric edits.3

TrustMark is the family deprint's own mark belongs to, since a photograph has no diffusion process to hide a pattern in.

How much can a mark carry?

Payload is the number of bits a watermark holds. Zero bits means only "present or not". Around a hundred is enough for an identifier that can be looked up, which is all a pointer to a credential needs.

Payload capacity by methodBits an invisible watermark can carry per image
050100150 bitsSynthID-O136TrustMarkdeprint mark96Stable SignatureTree-Ringpresence only

Single series, so no legend. Ours is at full strength, the rest are stepped back. Zero is drawn as a hollow ring, never an invisible bar. The deprint figure is a design target.

Table view
MethodBits
SynthID-O136
TrustMark~100
deprint mark96 (target)
Stable Signature48
Tree-Ring0
Sources 1, 2, 3
SynthID-Text detection under attackF1 score after each kind of edit. 1.0 is perfect, 0.5 is a coin flip.
00.250.50.751coin flipNo attack1.00Synonym substitutionCopy-paste, 10× dilutionCopy-paste, 20× dilution0.50

A dot plot, not bars: F1 is a score, not a quantity that grows from zero. The 20× figure is reported as approximately random, so it sits on the coin-flip line.

Table view
AttackF1
No attack1.000
Synonym substitution0.884
Copy-paste, 10× dilution0.788
Copy-paste, 20× dilution~0.500
Source 5
MethodOwnerPayload (bits)Min. image (px)Quality (PSNR dB)Published
SynthID-OGoogle DeepMind136512—Oct 2025
TrustMarkAdobe~100any> 43ICCV 2025
Stable SignatureMeta48——2023
Tree-RingUMD0——NeurIPS 2023
deprint markthe maker96256> 42target

Table 2A dash means the paper does not report it, never a zero. The deprint row is a design target, not a measurement.

How marks get broken

The attacks are well mapped. A December 2024 survey of StegaStamp, Tree-Ring, Stable Signature and Latent Watermark finds that simple distortions are mostly handled, but regeneration attacks, where an image is passed through a diffusion autoencoder and re-synthesised, degrade post-hoc marks badly. Semantic-level marks like Tree-Ring fare better against regeneration but worse against targeted forgery.4

On the text side, an August 2025 study showed SynthID-Text loses most of its signal to paraphrase and copy-paste dilution, which is why layered approaches are winning.5

So what should a maker do?

No invisible mark is permanent against a motivated adversary with a generative model. The mark's job is to survive ordinary handling so an honest viewer can find the credential. For adversaries, the credential's cryptography and your published manifest are what you point to.

Sources

  1. SynthID-Image: Image watermarking at internet scale, Google DeepMind, arXiv, Oct 2025
  2. Tree-Ring Watermarks, NeurIPS 2023
  3. TrustMark, Adobe Research, ICCV 2025
  4. Invisible Watermarks: Attacks and Robustness, arXiv, Dec 2024
  5. Robustness Assessment of Text Watermarking for SynthID, arXiv, Aug 2025
  6. C2PA adoption in 2026: hardware, platforms and verification, SoftwareSeni