logo
UW researchers figured out how to bypass anti-deepfake markers on AI images

UW researchers figured out how to bypass anti-deepfake markers on AI images

CBC23-07-2025
University of Waterloo researchers have built a tool that can quickly remove watermarks identifying content as artificially generated — and they say it proves that global efforts to combat deepfakes are most likely on the wrong track.
Academia and industry have focused on watermarking as the best way to fight deepfakes and "basically abandoned all other approaches," said Andre Kassis, a PhD candidate in computer science who led the research.
At a White House event in 2023, the leading AI companies — including OpenAI, Meta, Google and Amazon — pledged to implement mechanisms such as watermarking to clearly identify AI-generated content.
AI companies' systems embed a watermark, which is a hidden signature or pattern that isn't visible to a person but can be identified by another system, Kassis explained.
He said the research shows the use of watermarks is most likely not a viable shield against the hazards posed by AI content.
"It tells us that the danger of deepfakes is something that we don't even have the tools to start tackling at this point," he said.
The tool developed at the University of Waterloo, called UnMarker, follows other academic research on removing watermarks. That includes work at the University of Maryland, a collaboration between researchers at the University of California and Carnegie Mellon, and work at ETH Zurich.
Kassis said his research goes further than earlier efforts and is the "first to expose a systemic vulnerability that undermines the very premise of watermarking as a defence against deepfakes."
In a follow-up email statement, he said that "what sets UnMarker apart is that it requires no knowledge of the watermarking algorithm, no access to internal parameters, and no interaction with the detector at all."
When tested, the tool worked more than 50 per cent of the time on different AI models, a university press release said.
AI systems can be misused to create deepfakes, spread misinformation and perpetrate scams — creating a need for a reliable way to identify content as AI-generated, Kassis said.
WATCH | How to spot a deepfake:
How to spot a deepfake
4 months ago
AI-generated videos have sprung up all over social media. Recently, a scam has been using deepfakes of CBC's David Cochrane and Prime Minister Justin Trudeau. A deepfake of U.S. President Donald Trump and Elon Musk made headlines last week that involved feet. Here are some ways to detect them.
After AI tools became too advanced for AI detectors to work well, attention turned to watermarking.
The idea is that if we cannot "post facto understand or detect what's real and what's not," it's possible to inject "some
kind of hidden signature or some kind of hidden pattern" earlier on, when the content is created, Kassis said.
The European Union's AI Act requires providers of systems that put out large quantities of synthetic content to implement techniques and methods to make AI-generated or manipulated content identifiable, such as watermarks.
In Canada, a voluntary code of conduct launched by the federal government in 2023 requires those behind AI systems to develop and implement "a reliable and freely available method to detect content generated by the system, with a near term focus on audio-visual content (e.g., watermarking)."
Watermark removed 'within 2 minutes max'
Kassis said UnMarker can remove watermarks without knowing anything about the system that generated it, or anything about the watermark itself.
"We can just apply this tool and within two minutes max, it will output an image that is visually identical to the watermark image" which can then be distributed, he said.
"It kind of is ironic that there's billions that are being poured into this technology and then, just with two buttons that you
press, you can just get an image that is watermark-free."
Kassis said that while the major AI players are racing to implement watermarking technology, more effort should be put into finding alternative solutions.
Watermarks have "been declared as the de facto standard for future defence against these systems," he said.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Canada's first quantum computing hub boots up in southern Alberta
Canada's first quantum computing hub boots up in southern Alberta

CBC

time4 hours ago

  • CBC

Canada's first quantum computing hub boots up in southern Alberta

Social Sharing Businesses in southern Alberta are getting the chance to try out a publicly accessible supercomputer. A quantum computing hub, created by SuperQ Quantum Computing, recently opened at the Tecconnect innovation centre at Economic Development Lethbridge. SuperQ founder Muhammad Khan says the platform called Super is web-based and, similarly to ChatGPT, allows users to ask about complex real-world problems in plain English, and comes up with all possible solutions simultaneously. Problems could include supply chain bottlenecks or manufacturing inefficiencies. "The way it does it is by combining classical computing with quantum computing, and doing all the complexity stuff under the hood," Khan told The Canadian Press in a recent interview. "Classical computing is what we use everyday on our computers, on our laptops. "Classical computing would take one route, and if it fails, it comes back and takes another route. Whereas quantum computing takes all the possible routes at the same time. And as a result, it is able to figure out the maze a lot faster." Businesses in the city southeast of Calgary can trial the technology by asking questions like how to find efficient delivery routes or how to schedule staff to minimize overtime, Khan said. Super is to eventually be made available to the broader public by licence. The Lethbridge Super hub is the first in a series of planned networks worldwide. Other locations are set to be established elsewhere in Canada, the United States, Europe, India and the United Arab Emirates. Khan said setting up the platform's nucleus in Lethbridge is a full-circle moment. "I have a deep affection for Tecconnect as my entrepreneurial journey started there," Khan said, adding the centre has helped facilitate emerging technologies in Alberta and Canada. "That appetite to promote emerging technologies with a business focus is something that is not very common. And if you go to the big centres, it's hard to bring about these programs." Renae Barlow, vice-president of entrepreneurship and innovation at Economic Development Lethbridge, said emerging technologies, such as Tecconnect, can keep businesses competitive. Local teams are offering workshops and training to help companies learn more about the platform, she said. "Having businesses understand why it's important for them to integrate this [technology] and to be on the leading edge and to really create that competitive advantage is what we wanted for our southern Alberta businesses," Barlow said. "To understand that this actually puts them ahead." Khan said some businesses in telehealth have also reached out about using the platform to build artificial intelligence doctors. "Their human doctors couldn't keep up with the demand," he said. "So that was done, but then the question was, 'How do you increase the accuracy of those AI clinicians?' And this is where we came in, and the Super platform came in to take those AI models to the next level." Barlow said there's been other interest in things like understanding global markets and even determining nutritional values for cattle. The hub is also getting noticed by government officials. Nate Glubish, Alberta's minister of technology and innovation, highlighted the hub on social media. "Alberta tech is booming," he said.

‘Tech is booming': Canada's first quantum computing hub boots up in southern Alberta
‘Tech is booming': Canada's first quantum computing hub boots up in southern Alberta

CTV News

time7 hours ago

  • CTV News

‘Tech is booming': Canada's first quantum computing hub boots up in southern Alberta

A new quantum super hub launched by Economic Development Lethbridge is helping to make Lethbridge a national leader in advanced computing. Businesses in southern Alberta are getting the chance to try out a publicly accessible supercomputer. A quantum computing hub, created by SuperQ Quantum Computing, recently opened at the Tecconnect innovation centre at Economic Development Lethbridge. SuperQ founder Muhammad Khan says the platform called Super is web-based and, similarly to ChatGPT, allows users to ask about complex real-world problems in plain English and come up with all possible solutions simultaneously. Problems could include supply chain bottlenecks or manufacturing inefficiencies. 'The way it does it is by combining classical computing with quantum computing and doing all the complexity stuff under the hood,' Khan told The Canadian Press in a recent interview. 'Classical computing is what we use everyday on our computers, on our laptops. 'Classical computing would take one route, and if it fails, it comes back and takes another route. Whereas quantum computing takes all the possible routes at the same time. And as a result, it is able to figure out the maze a lot faster.' Businesses in the city southwest of Calgary can trial the technology by asking questions like how to find efficient delivery routes or how to schedule staff to minimize overtime, Khan said. Super is to eventually be made available to the broader public by licence. The Lethbridge Super hub is the first in a series of planned networks worldwide. Other locations are set to be established elsewhere in Canada, the United States, Europe, India and the United Arab Emirates. Khan said setting up the platform's nucleus in Lethbridge is a full-circle moment. 'I have a deep affection for Tecconnect as my entrepreneurial journey started there,' Khan said, adding the centre has helped facilitate emerging technologies in Alberta and Canada. 'That appetite to promote emerging technologies with a business focus is something that is not very common. And if you go to the big centres, it's hard to bring about these programs.' Renae Barlow, vice-president of entrepreneurship and innovation at Economic Development Lethbridge, said emerging technologies, such as Tecconnect, can keep businesses competitive. Local teams are offering workshops and training to help companies learn more about the platform, she said. 'Having businesses understand why it's important for them to integrate this (technology) and to be on the leading edge and to really create that competitive advantage is what we wanted for our southern Alberta businesses,' Barlow said. 'To understand that this actually puts them ahead.' Khan said some businesses in telehealth have also reached out about using the platform to build artificial intelligence doctors. 'Their human doctors couldn't keep up with the demand,' he said. 'So that was done, but then the question was, 'How do you increase the accuracy of those AI clinicians?' And this is where we came in, and the Super platform came in to take those AI models to the next level.' Barlow said there's been other interest in things like understanding global markets and even determining nutritional values for cattle. The hub is also getting noticed by government officials. Nate Glubish, Alberta's minister of technology and innovation, highlighted the hub on social media. 'Alberta tech is booming,' he said. This report by The Canadian Press was first published Aug. 2, 2025. — By Aaron Sousa in Edmonton

Digging deeper: Saskatchewan producers look for greener way to mine lithium
Digging deeper: Saskatchewan producers look for greener way to mine lithium

CBC

time10 hours ago

  • CBC

Digging deeper: Saskatchewan producers look for greener way to mine lithium

Saskatchewan is home to large lithium deposits and a handful of the province's mining companies are betting on a green approach to take them global. Lithium is the main element in batteries, powering everything from smartphones to electric vehicles (EVs), which made up 17 per cent of all new cars sold in Canada in 2024. According to the United States Geological Survey, the global demand for lithium was up by nearly 18 per cent last year. "Demand is expected to continue to grow and that's coming mainly in the form of EVs," said Paul Schubach, chief operating officer for EMP Metals Corporation. He said there's a strong international interest in lithium, of which nearly 95 per cent of the metal comes from countries like Australia, Chile, China and Argentina. The majority of the mineral is then processed in China, which dominates the manufacturing of electric vehicle batteries. Schubach said Canada is far behind when it comes to producing lithium. " There's a lot of attention right now on North America and the EV boom that was expected to be there just hasn't quite taken off yet," he said. Environmental concerns around mining lithium There are many ways that lithium can be mined, but not all of them are environmentally safe. For instance, in South America, lithium is mined through expansive salt pools that hold salty water containing metals and minerals. In places like Chile, Bolivia and Argentina, the salty water is pumped to the surface, where it sits in massive pools to naturally evaporate, separating lithium from the other minerals. However, the extraction of brine has been found to reduce water levels in these areas, which can contaminate water sources with dangerous materials, becoming a danger to humans and animals who depend on it. The other common way of getting lithium is strip mining, or open pit mining, where lithium is removed by digging into hard rock below the ground. This can cause groundwater to dry up in nearby lakes, rivers and streams. There's also toxic chemicals used that can leak into water sources if not properly managed. With so many risks, some experts say that while extracting lithium is important, it shouldn't be thought of as a magic solution to climate change just because it powers the EV industry. What does that mean for Saskatchewan? It's no secret to Saskatchewan producers that lithium production can pose a harm to the environment. That's why a handful of companies in the province are looking to change that by pioneering a new way of getting the mineral out of the ground. Benjamin Sparrow, CEO of Saltworks Technologies, said instead of using traditional methods like hard rock mining or strip mining, more producers are now using direct lithium extraction (DLE), which takes it right out of the ground, separates out the lithium and recycles the groundwater. "It's underway and specifically underway in Canada," Sparrow said. He said DLE has the smallest environmental footprint and a "very small" land footprint for wells, electricity and water. Evaporation ponds are often not using a freshwater resource. Instead, Sparrow said they use a brine that is not intended for farming, drinking or other means because it's low-quality water. "The environmental footprint is largely associated with the ponds themselves, and as long as the ponds and the geotech is done right, there should not be any environmental concerns," he said. Teresa Kramarz, a mining expert at the University of Toronto, cautions this type of technology is still being tested and has yet to be tried on a large commercial scale in Saskatchewan. She said while in theory it uses less water and land, it needs to be studied further. There's not a lot of research to demonstrate whether direct extraction uses less water than the salt ponds in South America, Kramarz said. She said the potential for the technology is promising, but it remains to be seen if it will be cost effective and widely used. What's stopping Saskatchewan's lithium industry from starting commercial production? Sparrow said what stands out about Saskatchewan's resource is there's a high concentration of lithium and it's close to the surface, so it's very cost effective to extract. Areas like Kindersley and Estevan, both have large reserves of an underground brine, or water, that contains lithium. Additionally, Sparrow points to the province's infrastructure and labour available from the oil and gas industry, which isn't the case for other regions. At the same time, the current cost for lithium is $8,000 to $10,000 a ton. Sparrow said while the low cost makes DLE technology not the most economic, that hasn't put a damper on the Saskatchewan mining industry. "Innovation can change the cost equation," Sparrow said. "And that's exactly the work that's underway in Saskatchewan to drive the cost down below today's market price." Saskatchewan mining companies are betting the demand for lithium will quickly outpace supply. Schubach said he is confident that will happen.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store