How SynthID works
SynthID is applied by Google to outputs from Gemini, Imagen and related models. Instead of writing information into metadata, it nudges pixel values by a tiny amount following a pattern only the detector knows. The detector is not looking for a reference image: it computes a correlation between the image it receives and the pattern it expects.
That is what makes the mark robust. Cropping shifts the pattern but does not destroy its structure; the detector realigns. Lowering JPEG quality adds noise but leaves the correlation well above threshold. A light blur, a contrast change, an Instagram filter: the pattern stays readable.
The fake fixes
- Stripping metadata: good for privacy, no effect on SynthID, which does not live in metadata.
- Taking a screenshot: it reproduces the pixels, so it reproduces the pattern.
- Cropping 10%: the detector realigns on whatever is left.
- Re-saving as JPEG quality 60: adds noise, does not break the correlation.
- Running it through another AI tool "to clean it": if that tool is itself generative and marked, you inherit its watermark.
What actually breaks SynthID
Only one approach is known to be reliable: regenerating the image. A diffusion model repaints it (image-to-image, ControlNet to keep the composition, masks to protect important areas). The output pixels are entirely new, so the original pattern no longer exists.
The cost is real: several gigabytes of models, a GPU, a pipeline to configure, and a result that is no longer exactly your image. This is what the ComfyUI projects circulating on GitHub do. It cannot run in a browser tab, and it cannot run without sending your image somewhere.
What a local tool can honestly do
The realistic strategy has two parts. First, desynchronise: a crop of a few percent combined with sub-degree rotation and resampling stops the detector from recovering the exact alignment of the pattern. Second, rebuild the detail layer: separate the structure of the image (the shapes) from its fine grain (where the watermark lives), then replace that grain with fresh noise.
Measuring the high-frequency carrier correlation after realignment, we go from 0.99 on the original image to about 0.01 on the Maximum profile, and to zero or negative on Extreme. That is a huge drop in signal — but it is not proof that Google's detector will fail, since it remains the only judge and does not publish its threshold.
The price rises with intensity: from the Strong profile onwards, softening becomes visible on fine textures, and a cleaned PNG can end up heavier than the original.
What to do in practice
- If your goal is privacy (not exposing the prompt, the software, the geolocation): clean metadata and C2PA — done, and verifiable.
- If your goal is to pass a SynthID check: test with Google's SynthID Detector after cleaning, on Maximum then Extreme, and judge for yourself.
- If the render must stay pristine: avoid the high profiles and accept that the watermark remains.
- If a chatbot tells you "this image looks AI-generated": check whether it is reading a watermark or just the look of the image — in the second case no cleaning will change its answer.
Frequently asked questions
Can SynthID be removed for free online?
The signal can be reduced substantially, for free and locally, but no online or in-browser tool can guarantee Google's detector will no longer recognise the image. Be wary of services that claim otherwise while asking you to upload your file.
Is cropping enough to remove SynthID?
No. SynthID was designed to survive cropping: the detector realigns on the remaining portion. Cropping only helps when combined with sub-degree rotation and resampling, and even then it merely desynchronises the pattern.
Is SynthID stored in the image metadata?
No. Google often adds metadata and a C2PA manifest as well, and those are removable, but SynthID itself is written into the pixel values.
Clean your file or your text
Detection and cleaning inside your browser: no upload, no account, no quota. Your files never leave your device.
Open the studio