A.I. News Microsoft AI watermarks in Paint and Photos are linked to user IDs

nicolaasjan

Level 6
Thread author
Verified
Well-known
May 29, 2023
224
1,827
469
The Netherlands
When Anthropic disclosed earlier this month that it would be applying a statistical word-choice watermark to its Claude text output, the company noted that at least 190 AI providers have agreed to abide by Europe's AI transparency rules.
One such company is Microsoft, which has been applying its own form of watermarking to images created with the assistance of AI in its Paint and Photos applications for Windows.

Xusheng Li, a software developer at Vector 35, recently published an analysis of Microsoft's approach, which the Windows biz previously disclosed in the Paint and Photos documentation but did not detail.
"Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images," Li explained in a LinkedIn post. "Your prompt is sent to Microsoft for moderation, and the returned GUID is encoded into the pixels."
Li notes that the invisible GUID watermark – a 16-byte integer – is distinct from the visible watermark option that Microsoft provides to users of its Paint software and Microsoft 365 AI features.
If Microsoft associates each prompt with the user who sent it, then the company could in theory identify users by referring to the watermark in an image. Long ago, manufacturers of laser printers implemented this sort of tracking and the practice alarmed privacy advocates when it came to light.
 
Important privacy distinction

A server-issued GUID embedded in an image would not, by itself, prove who created the image. It would function primarily as an identifier for a generation request. Microsoft could associate that identifier with a user, account, device, IP address, or other records only if it retains those relationships on its servers.

Based on the quoted article, the potential privacy concern is therefore the combination of:

  • The GUID embedded in the image
  • Microsoft’s server-side records connecting the GUID to a request
  • Any account, telemetry, or network information retained alongside that request

This is different from a visible watermark and also different from ordinary image metadata such as EXIF data. A pixel-level watermark may survive some routine edits, but its reliability after resizing, compression, cropping, screenshots, filtering, or re-encoding would depend on Microsoft’s specific encoding and detection method. The quoted material alone does not establish how robust the watermark is or how long the associated records are retained.

Users who are concerned should review Microsoft’s current privacy documentation and avoid treating removal of visible metadata or a visible watermark as proof that an image contains no provenance information. The key unanswered issue is Microsoft’s retention and access policy for the GUID-to-request association.
 
This is actually a serious issue, watermarking photos and text raises serious privacy concerns. A lot of students in the university/education sphere are going to get caught out. Even academics and researchers are going to get caught out. Cue the watermark removal software or services.