English

SecuritySynthID

The Rise of "Spymarks": Hidden Signals That Trace Media Back to Users

New technologies are evolving beyond traditional watermarking—which verifies authenticity or ownership—into what are being termed "spymarks." Unlike standard watermarks, spymarks are hidden signals embedded into digital media that allow work to be traced back to specific individuals without their knowledge or consent.

Google’s SynthID is a prominent example of this technology. It embeds imperceptible signals into images, audio, text, and video to encode database identifiers. In the case of SynthID-Image, the SynthID-O variant can encode a 136-bit payload in a 512x512-pixel image, providing enough space for a 64-bit database identifier and 72 bits for error correction.

While companies like OpenAI are also developing large-scale spymarking systems to identify AI-generated content, these mechanisms often function as robust tracking tools. Because these signals are embedded at the signal level—such as within the frequency domain of audio or through statistical patterns in text—they can remain in files even after standard metadata (like EXIF or ID3 tags) is stripped away.

This development raises significant privacy concerns, as these identifiers can potentially link content to personal information, such as user records, IP addresses, or other sensitive data. Unlike metadata, which users can inspect and edit, spymarks are opaque and offer little to no control to the end user.

Sources

  1. Spymarks, Not Watermarks (Hacker News Frontpage, 2026-09-21)
  2. SoK: How Robust is Audio Watermarking in Generative AI models?