I feel like there’s some security engineering calculus that would be useful here?
You can’t definitively prove the absence of a watermark. You can only prove the watermark is there. Once you do prove it’s there, the thing that carries the watermark changes in some way — it is “burned” or tainted?
There must be value in having a visible vs an invisible watermark, or in declaring that a work is watermarked without revealing the hidden mark, or having two marks — one that is publicly verifiable and another that is hidden?
If the process itself can be defeated through adding entropy (or more generally by revealing the watermark algorithm) then is that not security through obscurity, which is to say it is a one-shot rather than a general system that is doomed to become obsolete over time?
Something feels off about a technology based on being hidden but whose only value is in being revealed but I feel dumb for not being able to be more specific about what feels wrong! It could simply be that anyone who can verify the presence of the watermark also now has a tool to tell them when they’ve successfully scrubbed the watermark off the work, so the verify tool has to be kept secret which in turn limits its usefulness.
If you think SynthID-Image can be easily defeated by adding entropy I invite you to give it a try.
I spent half a day messing around with it and I was very impressed by how robust it is. I couldn't get OpenAI to stop detecting their own SynthID without completely trashing the image.