Discussion summary
A discussion about Meta's signature detection methods reveals vulnerabilities and debates on research accuracy. Participants mention bypass techniques, statistical analysis, and privacy concerns.
What the discussion says
- Some believe the signature can be easily bypassed using known methods.
- Questions raised about the reliability of peer-reviewed research findings.
- Concerns about privacy and platform restrictions, especially on Android and iOS.
“The signature is easily bypassed now: https://twotensors.ai/”
“The claims in the research seem poorly supported, according to some reviewers.”
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- also, easily bypassed now: https://twotensors.ai/by flaxxer
- How common is it for peer reviewed papers like this to be so far off their claimed findings?
“According to Google's peer-reviewed and published paper, they claim to have a true positive rate (TPR) above 99.97% -- meaning that they will miss their own watermarks less than 1 in 10,000 times. However, my own empirical testing found that is it much closer to 1 in 20.”
by kamranjon - The point is to embed a particular signature, which was generated randomly, in the image. The distance function discussed is the same as the popcount of the xor. It's well know that the xor of random data with correlated data is statistically random. Hence, however well correlated the signatures of unwatermarked images may be with each other, they would show no correlation with the signature of a watermarked image. That is, unless the watermark by extremely bad luck happened to be near one of these clusters the author discovered. This does represent a genuine flaw, but an extremely minor one, and one that can be easily mitigated with no changes to the underlying algorithm,by f33d5173
- This is a great statistical analysis and it was a pleasure to read, but I wasn't expecting the claims to be so poorly supported. There's also a reply from one of the Meta authors there, worth checking out.by richardfey
- A watermark is not just “transparency.” It can reveal what tool someone used, how they work, or that an image came from a stigmatized platform. In sensitive contexts—politics, sexuality, medical issues, protest material, or private expression—that can become surveillance.
I am working on Saigon Watermarks: https://apps.apple.com/us/app/saigon-watermark/id6777061197 for detecting and removing provenence markers in AI.
The tool also removes c2pa markers, which google is now linking the device that took the photo with the photo.
scary stuff.
https://security.googleblog.com/2025/09/pixel-android-truste...
by itake - Related to this, the EU AI Act requires mandatory watermarking that is cannot be removed or is illegal to remove.
https://digital-strategy.ec.europa.eu/en/policies/eu-icons-l...
If Facebook already embeds user IDs in images (AI or no AI) I can only drool to think what kind tracking, advertising and mass surveillance opportunities are coming.
by miohtama