started · updated
Microsoft Paint and Photos embed traceable AI watermarks, researcher finds
Security researcher Xusheng Li has discovered that Microsoft Paint and Photos embed invisible watermarks into AI-generated images that could potentially be used to trace content back to specific user accounts.
Through reverse engineering, Li found that these applications use a 128-bit Globally Unique Identifier (GUID) issued by Microsoft servers. Even when image generation appears to occur locally, the software sends user prompts to Microsoft servers for moderation. The servers then return a GUID that is encoded directly into the image pixels via a component identified as 'Watermarker.dll'.
This invisible GUID is linked to the prompt generation ID, allowing multiple generated images to be connected. While Microsoft utilizes C2PA (Coalition for Content Provenance and Authenticity) metadata to describe image origins, Li notes that the company has not explicitly disclosed that these C2PA credentials contain a soft-binding value linking the pixel-level watermark to the server-issued identifier. This mechanism provides a way to potentially map specific AI-generated content back to the original user prompt and account.
Entities
C2PA · Microsoft · Xusheng Li