upvote
They don't want you to know, because they're the baddies. Imagine how much money they can get from advertisers if they're able to identify every single piece of code, reddit thread, email, GitHub readme that you've ever written based on your secret ID. They're creaming themselves just thinking about it.

"Excellent work acquiring that outlook data Anat, now let's cross check the defunct company emails against YouTube videos edited with Google PrivateEditAIā„¢ to figure out what the social security number of this YouTube account is."

reply
Unfortunately this is the truth, no one can be given a benefit of the doubt because despite years of good grace they have been anti-user and enshittified everything they touch.
reply
> It's a real shame Google isn't more transparent about how it actually works

> classifying images in bulk or offline

You've described exactly the elements spammers and fraudsters need to be able to defeat this mechanism.

reply
Well it's not a very good mechanism then, is it.
reply
Is it possible to implement a very good mechanism?
reply
Not that I can think of, but you could have two watermarks, one detectable with an open-source classifier and the other proprietary.

Most AI images are either extremely low-effort or not actively trying to be deceptive, so defenders can still catch the majority. If someone is actively circumventing they'll probably circumvent both, anyway.

reply