Research notes

Can you remove a SynthID watermark? What we measured

What the papers report, what our own runs showed at each setting, and why a pass on Gemini’s check is evidence rather than a guarantee.

Updated 24 September 2026

The gentlest redraw we tried failed. One step stronger passed. On one heavily marked close-up photo, that small step decided whether Gemini’s provenance check still recognised the image as Google’s, and it is the most useful thing we learned about removing SynthID: the working band is narrow. These are our notes from testing, set against what the published research says.

One thing up front, because the rest depends on it. No public detector reads production SynthID, so every “pass” below means Gemini’s provenance check (a classifier judgment, not Google’s production detector) no longer said the image came from Google AI. That is evidence. It is not proof.

Edits that leave the mark in place

Cropping, JPEG re-saves, blur, added noise, filters and resizing are what SynthID was trained to survive. Google’s SynthID-Image paper tests 30 such transformations, and the Gemini help page accepts screenshots as input. Independent research points the same way for strong watermarks in general. In the UnMarker paper’s baseline tests, StegaStamp, one of the hardest open watermarks, was still detected on 100% of images after a 10% crop (with about 94% of its bits read back correctly), and so was a second scheme, TRW.

Metadata removal does nothing here either. ExifTool, and the lossless cleaning our tool runs on your device before either wipe mode, delete Content Credentials and EXIF data and leave every pixel as it was. A screenshot drops the metadata too, but it copies the picture, and the picture is where SynthID lives. The comparison of ExifTool, screenshots and WipeTheAI shows what each of those actually removes.

Stacking helps. A little. The SynthID paper itself reports lower detection for its worst combination of edits than for any single one, but not low enough to call the mark gone.

What the literature says works

  • Regeneration. Zhao and colleagues (NeurIPS 2024) showed that adding noise to an image and letting a generative model rebuild it provably removes watermarks whose changes are small in pixel terms. Their own caveat: marks tied to the image’s content hold up better.
  • Rinsing, meaning regeneration repeated. The WAVES benchmark found two rounds gave the best balance of low detection and image quality on the Tree-Ring watermark.
  • UnMarker (IEEE S&P 2025), which disturbs the image’s spectrum instead of redrawing it. It cut detection on StegaStamp to 43% and TRW to 40% at an LPIPS distance of 0.15 or less. Its lead author told IEEE Spectrum it removed 79% of SynthID marks in his tests; Google DeepMind disputed that figure, and the paper’s own tables cover only open schemes.
  • The NeurIPS 2024 “Erasing the Invisible” competition, whose winners used caption-guided img2img regeneration in the black-box track and reached about 95.7% removal on the benchmark watermarks. SynthID wasn’t among them.

Read those numbers for what they are: results on open watermarks that researchers can decode themselves. None of them is a measurement against production SynthID, because nobody outside Google has its decoder.

What we ran, and what happened

Our test set was three kinds of image that fail in different ways: a portrait with a small face, a text-heavy profile image, and a close-up gym photo with a large face and, going by how hard it was to shift, a heavy mark. Every variant was judged the same way, by asking Gemini whether the output was made with Google AI.

Watermark tests on our three image classes, judged by Gemini's provenance check, September 2026
What we triedResultWhat it did to the picture
A published spectral attack, no redrawFailedClose to untouched
Redrawn, then the original’s tone, colour or fine texture pulled back inEvery variant failedLooked better, which was the point; the original pixels brought the mark back
The two lightest redraws we triedFailed on the gym photoThe smallest change to the picture
The redraw we kept (Maximum disruption)Passed on all threeSmall text garbles; fine texture shifts
A much heavier redrawPassedReads as re-rendered
The same redraw, steered harder by the modelPassedChanged the person: lighter skin, softer face

The redraw we kept is the lightest one that passed on all three images. How firmly the model is steered mattered more than we expected: pushed harder, the model’s idea of a flattering face took over, so we kept it loose enough to leave the person as they were.

The pull-back failures taught us the most. Every attempt to copy the original’s colour or texture back over a regenerated image, even partly, returned it to a fail. That rules out the obvious way to make regeneration invisible, and it is why we are suspicious of any tool that shows a pixel-perfect result and claims the watermark is gone.

Faces are the one place we bring some of your original back, and only when the face is small in the frame. The watermark is image-wide, so a small restored area doesn’t carry enough of it back. On large close-up faces we skip that step, and the face is redrawn with everything else. The story of the recipe we dropped covers why the first, gentler approach was abandoned.

What you give up

Small printed text (labels, captions on packaging) can come out garbled. Knitwear and similar fine texture shifts a little, and on close-up faces pores and droplets are re-imagined rather than kept. Each result shows a similarity score and a before and after slider so you can judge it on your own image, and a run takes about one to two minutes. Maximum disruption uploads your image to our servers to do this; the tool warns before it does.

How far a pass goes

Our recipe passed Gemini’s check on our test images. Results vary per image, and we don’t promise removal. We haven’t tested illustrations, flat graphics or images made by OpenAI’s SynthID-marked models against Gemini, and we have had no access to Google’s SynthID Detector portal, so we can’t say how its verdict would compare.

Tools that promise “undetectable” results with less change to the picture than ours are, as far as we can tell, reporting images that happened to pass or tests they haven’t published. Our own gentler settings looked better and failed on the gym photo.

A single before and after pair proves very little.

Sources

  1. Gowal et al., SynthID-Image (arXiv 2510.09263)
  2. Zhao et al., Invisible image watermarks are provably removable using generative AI (arXiv 2306.01953)
  3. An et al., WAVES: Benchmarking the robustness of image watermarks (arXiv 2401.08573)
  4. Kassis and Hengartner, UnMarker (IEEE S&P 2025)
  5. IEEE Spectrum: AI watermark remover defeats top techniques (updated 15 August 2025)
  6. NeurIPS 2024 Erasing the Invisible competition report (arXiv 2508.21072)
  7. Gemini Help: check if an image was made with Google AI