English

SynthID-Image: Image watermarking at internet scale

Cryptography and Security 2025-10-13 v1 Artificial Intelligence

Abstract

We introduce SynthID-Image, a deep learning-based system for invisibly watermarking AI-generated imagery. This paper documents the technical desiderata, threat models, and practical challenges of deploying such a system at internet scale, addressing key requirements of effectiveness, fidelity, robustness, and security. SynthID-Image has been used to watermark over ten billion images and video frames across Google's services and its corresponding verification service is available to trusted testers. For completeness, we present an experimental evaluation of an external model variant, SynthID-O, which is available through partnerships. We benchmark SynthID-O against other post-hoc watermarking methods from the literature, demonstrating state-of-the-art performance in both visual quality and robustness to common image perturbations. While this work centers on visual media, the conclusions on deployment, constraints, and threat modeling generalize to other modalities, including audio. This paper provides a comprehensive documentation for the large-scale deployment of deep learning-based media provenance systems.

Keywords

Cite

@article{arxiv.2510.09263,
  title  = {SynthID-Image: Image watermarking at internet scale},
  author = {Sven Gowal and Rudy Bunel and Florian Stimberg and David Stutz and Guillermo Ortiz-Jimenez and Christina Kouridi and Mel Vecerik and Jamie Hayes and Sylvestre-Alvise Rebuffi and Paul Bernard and Chris Gamble and Miklós Z. Horváth and Fabian Kaczmarczyck and Alex Kaskasoli and Aleksandar Petrov and Ilia Shumailov and Meghana Thotakuri and Olivia Wiles and Jessica Yung and Zahra Ahmed and Victor Martin and Simon Rosen and Christopher Savčak and Armin Senoner and Nidhi Vyas and Pushmeet Kohli},
  journal= {arXiv preprint arXiv:2510.09263},
  year   = {2025}
}
R2 v1 2026-07-01T06:29:10.873Z