started · updated
Microsoft Paint embeds invisible GUID watermarks in AI images
Security researcher Xusheng Li has revealed that Microsoft Paint and Photos applications embed invisible, server-issued watermarks into AI-generated images. Even when images are generated locally on a device, the process requires an internet connection to send prompts to Microsoft Azure servers for moderation.
Upon moderation, the server returns a 16-byte Globally Unique Identifier (GUID) which is then distributed across the image pixels. This invisible watermark is distinct from the visible Copilot logo option and is not explicitly disclosed in Microsoft's documentation. The identifier is also linked to the C2PA manifest as a ‘soft binding’ value.
Technical analysis suggests that Microsoft may be able to link successive user requests, as the application sends the previous generation's ID back to the server during subsequent moderation requests. This mechanism could potentially allow the company to reconstruct a history of user interactions, raising significant privacy and digital rights concerns regarding how AI-generated content is tracked and identified.
Entities
Azure · Microsoft · Vector 35 · Windows 11 · Xusheng Li