English

SecurityGemini

Method for Removing SynthID Watermarks from Gemini Images via Frequency Analysis Released

This article is a translation. Read the Japanese original

The released project reverse-engineers Google's SynthID watermarking system using only signal processing and frequency analysis, without requiring access to proprietary encoders or decoders. Diagonal bands of high-frequency residual components extracted from pure white images were identified as the spatial frequency signature of the watermark.

After six iterations of development, the development team bypassed the detector for images from gemini-3.1-flash-image-preview and nano-banana-pro-preview using the Round 06 pipeline. The output is visually lossless to the human eye.

The breakthrough came from utilizing a failure mode described in the Gemini app's help text—which stated that detection becomes difficult when complex collages or overlapping textures are present—as an attack specification. By applying a smooth, low-frequency random warp field at the pixel level through an elastic deformation stage, the team fragmented the consensus of the watermark's spatial phase.

In the V4 version, the codebook was reconstructed based on a more extensive dataset. The system separates the watermark from the content by using whether the phase of each frequency bin is locked across all solid-color backgrounds as a metric. This has resulted in the recovery of PSNR.


Source: Reverse engineering Gemini's SynthID detection (HN 177pt, 54 comments) (HN Search (backfill), 2026-04-10)