Digital watermarks are meant to help identify images made by AI. But research led by University of Maryland computer science professor Soheil Feizi found that the methods it examined could be defeated: watermarks could be removed from AI-generated images and added to human-generated ones, creating false positives.
The findings complicate hopes that watermarking can reliably identify manipulated media. They also leave a practical question: whether a tool that can be fooled still helps when combined with other ways to check an image.
How watermarks are meant to help
A digital watermark is designed to record an image’s origin, much as a physical watermark can help authenticate paper money or stamps. If a system can detect that mark, it may help people recognize AI-generated material, including images used in deepfaked videos.
Interest in the approach has grown alongside concern about misinformation. OpenAI, Alphabet, Meta, Amazon, and several other major AI players pledged to develop watermarking technology. Google’s DeepMind released a beta version of SynthID, a tool intended to mark content as it is generated.
The appeal is straightforward: add a signal at creation, then check for that signal later. But the study examined what happens when someone deliberately tries to interfere with it, rather than treating the mark as a permanent label.
Removal and false alarms
Feizi and his coauthors tested two broad approaches. One uses low-perturbation marks, which are invisible to the naked eye. The other uses high-perturbation marks that are visible. The researchers reported ways to wash out watermarks and also to place marks on images made by people.
Those two weaknesses create different problems. If a watermark is removed, an AI-generated image may no longer be identified by that method. If a mark is planted on a human-made image, a detector may incorrectly label that image as AI-generated. A watermark check, on its own, therefore cannot guarantee where an image came from.
The paper was released as a preprint and had not yet been peer-reviewed. Its results nevertheless add to earlier work: researchers from the University of California, Santa Barbara and Carnegie Mellon had also reported that invisible watermarks were vulnerable to attacks.
Researchers disagree about what follows
Feizi is sharply skeptical, saying the study broke the watermarking methods it tested. Hany Farid, a professor at the UC Berkeley School of Information, also recognizes that watermarks can be attacked, but argues that they may still contribute to a broader detection effort.
Other researchers make a similar case for limited usefulness. Yuxin Wen, a University of Maryland PhD student who coauthored a paper proposing a watermarking technique, says the results should prompt a reassessment of expectations rather than rule out watermarking as one authentication tool. Computer science professor Tom Goldstein says a system that catches some cases can still help reduce harm, even if sophisticated actors can evade it.
That distinction matters. A watermark does not need to stop every attempt at deception to offer some value, but it should not be treated as proof that an image is authentic or artificial. DeepMind’s announcement of SynthID likewise described the tool as not foolproof and not perfect.
A signal, not a guarantee
The study’s broader message is that watermarking faces a difficult technical challenge. A useful mark must remain detectable while an image is changed or attacked, and a detector must avoid treating a planted mark as reliable evidence of origin. The researchers’ paper says designing a robust watermark is challenging, but not necessarily impossible.
For readers, the findings point to caution when interpreting labels attached to images. A detected watermark may be one clue, while its absence does not settle whether AI was involved. Researchers who see a future for the technology argue that it should work alongside other detection methods, rather than carry the full burden of identifying fakes.
That leaves no simple promise of reliable identification. The debate is now less about whether watermarks can be useful at all, and more about what level of protection they can provide when removal and forgery are possible.