mirror of
https://github.com/wiltodelta/remove-ai-watermarks.git
synced 2026-09-04 19:26:34 +02:00
Stop double-counting a named forensic mark as SynthID provenance
A manifest that names its own forensic soft-binding algorithm carries that vendor's mark; the generic watermark-action vendor-token inference must not add a second, differently-attributed invisible watermark from the same bytes. Microsoft Designer manifests triggered exactly that: signed by Microsoft, watermarked by InvisMark, with the generation agent named "Azure OpenAI ImageGen" - the OpenAI issuer token inside that service name plus the InvisMark watermarked action satisfied the OpenAI SynthID-evidence rule, and identify reported one forensic mark as two paid pixel watermarks. Three changes, one rule at every inference site (the verdict-scan comment's own lesson: a rule that lives in only one copy is a rule the others silently lack): - c2pa.py structured path: SynthID evidence now scopes to the signer/generator identity strings only (signature issuer, claim generator), never the raw chain, and is suppressed entirely when a soft-binding algorithm is named. - c2pa.py byte fallback and metadata.py synthid_source: suppressed when the scan names a soft-binding algorithm. - identify.py verdict scan: same suppression. Gemini and ChatGPT originals keep their provenance-asserted SynthID strings; the Designer regression is pinned by test_designer_synthid_suppression.py (agent name alone is not the vendor's provenance, and a named soft binding suppresses the inference).
This commit is contained in:
@@ -1273,7 +1273,19 @@ def _identify_from_evidence(
|
||||
# reusing the derived `has_c2pa` / `source_kind` above, which are broader:
|
||||
# the file path's answer must not move.
|
||||
trained_source = b"trainedAlgorithmicMedia" in head or b"TrainedAlgorithmicMedia" in head
|
||||
if not synthid and trained_source and c2pa_marker_in(head) and (vendors := synthid_evidence_vendors_in(region)):
|
||||
# Same suppression as every other inference site: bytes that name their own
|
||||
# forensic soft-binding algorithm carry that vendor's mark, and the generic
|
||||
# vendor-token inference must not add a second, differently-attributed
|
||||
# invisible watermark (Microsoft Designer: "Azure OpenAI ImageGen" agent +
|
||||
# the InvisMark watermarked action read as "SynthID per OpenAI").
|
||||
|
||||
if (
|
||||
not synthid
|
||||
and trained_source
|
||||
and c2pa_marker_in(head)
|
||||
and not soft_binding_vendors_in(region)
|
||||
and (vendors := synthid_evidence_vendors_in(region))
|
||||
):
|
||||
synthid = synthid_verdict(", ".join(vendors))
|
||||
if synthid:
|
||||
watermarks.append(
|
||||
|
||||
Reference in New Issue
Block a user