Invisible AI watermarks hidden in Paint and Photos apps reverse engineered


Featured image Invisible AI watermarks hidden in Paint and Photos apps reverse engineered

Behind the simple tools we use every day, like Microsoft Paint, there are hidden layers of complexity. A recent deep dive into the AI features of Windows 11’s creative suite has revealed a fascinating, and somewhat surprising, system of digital tracking embedded within generated images.

Developer Xusheng Li stumbled upon this mechanism purely out of curiosity while investigating the AI capabilities of the Paint app. What he discovered wasn’t just the expected functionality of image generation, but a sophisticated system of watermarking designed to identify the origin of digital art created with AI assistance.

Li uncovered two distinct types of watermarks: visible watermarks, like the familiar Copilot logo, and an entirely invisible one. This invisible mark is the true core of the revelation. It is an essential component of Microsoft’s process for embedding content provenance, ensuring that every AI-generated image carries a traceable digital signature.

The process is more intricate than simply stamping a logo. The system works by mixing a server-issued GUID into the actual pixels of the image. This method is bundled with C2PA Content Credentials, giving the resulting file a robust, machine-readable identity that confirms the image’s origin and history.

This critical information is managed by hidden files within the application path, specifically components like watermarker.dll and ProvenanceHelper.dll. These files are the backbone of the process, linking the visual output directly back to the AI generation source.

What makes this discovery particularly compelling is the built-in integrity check. Li found that the function responsible for embedding the invisible watermark, called WmkWriteWatermark, is mandatory. If this embedding process fails for any reason, the entire image generation sequence is aborted, ensuring that the tracking mechanism is never compromised.

This finding shifts the perspective on how AI content travels through mainstream software. It suggests that even when users engage in local image generation, the prompt and the resulting output are subject to mandatory, embedded identification protocols.

Ultimately, this system of hidden watermarking raises important questions about transparency and accountability in the age of artificial intelligence. It hints at a future where digital content carries indelible proof of its creation, aligning with global efforts to regulate AI-generated media and ensure trust in digital provenance.

You may also like: