返回新闻
产品展示AI Understanding 简报

Tom’s Hardware 报告 Microsoft Paint 和 Photos AI 图像中存在不可见的 GUID 水印

Tom’s Hardware 报告称,Microsoft Paint 和 Photos 将不可见的服务器发布的 GUID 数据与 C2PA 凭证一起嵌入到 AI 生成的图像中。该发现来自开发者 Xusheng Li 的逆向工程,尚未得到 Microsoft 的独立证实。

5 min readRead the original reporting
Source-provided image accompanying Tom’s Hardware reports invisible GUID watermarks in Microsoft Paint and Photos AI images
归因报告来源记录
出版商
tomshardware.com
来源链接
tomshardware.comhttps://www.tomshardware.com/tech-industry/artificial-intelligence/microsoft-paint-and-photos-apps-add-invisible-watermark-to-ai-generated-content-developer-reverse-engineers-guid-embedding
来源类型
新闻媒体的报道——不是第一方文件。

我们无法独立确认的内容: 此声明归因于指定的商店。我们没有根据第一方文件对其进行验证。 (tomshardware.com)

背景60 秒内了解这一点

从这里开始

关键术语

API(应用程序编程接口)
一种软件系统向另一个系统发送请求并接收响应的结构化方式。
水印
在人工智能生成的文本或媒体中嵌入可检测信号,以便稍后将其识别为机器生成的。
嵌入
捕获文本、图像或其他数据语义的数字向量表示。
测试一下自己人工智能道德测验

发生了什么

Tom’s Hardware reports that developer Xusheng Li discovered previously undocumented behavior in Microsoft Paint and Photos when their AI image-generation features are used. The report says the apps apply both visible Copilot branding in some cases and an invisible watermark intended to identify or verify that AI participated in creating an image.

Tom’s Hardware reports that developer Xusheng Li investigated the AI features in Microsoft Paint on Windows 11 after finding that the app could call a remote image-generation API. The report says Li also found four apparent model files in the application path for local processing: one file resembling an ONNX model and three encrypted ONNX-like files. The article presents this discovery as the starting point for examining how Microsoft’s AI image features mark generated content.

According to Tom’s Hardware, Li found a file named watermarker.dll while probing the application. The report says Li initially believed the file handled only visible , including a Copilot logo placed in the lower-right corner of an image. The article says further analysis, assisted by an AI tool, identified a separate function called WmkWriteWatermark for invisible watermarking, in addition to the visible-watermark function AddPerceptibleWatermark.

Tom’s Hardware reports that the invisible process mixes a server-issued globally unique identifier, or GUID, into image pixels. The report also says Paint attaches C2PA Content Credentials to saved files, with code associated with ProvenanceHelper.dll and provenancesdk.dll. The source does not establish what the GUID specifically identifies, whether it maps to a prompt, account, session or other event, or whether Microsoft retains a corresponding record.

The article reports different failure behavior in Paint and Photos. In Paint, Tom’s Hardware says the watermark is mandatory for Stable Diffusion image-generation output and that image generation fails if WmkWriteWatermark cannot be written. In Photos, the report says the app still returns the image but logs an error when the process has a problem. Tom’s Hardware also reports that prompts from local image-generation workflows are sent to Microsoft servers for moderation. The article speculates that the processing may relate to Article 50 of the EU AI Act, whose transparency rules the report says took effect on August 2, 2026, while noting that the rules do not specifically call for a prompt-specific GUID. Microsoft’s response, if any, is not included in the supplied report.

来源详情: tomshardware.com ↗

为什么这很重要

The reported behavior could give users, platforms and investigators another way to identify AI-assisted images, but it also raises unanswered questions about what information is embedded, how it is linked to a user or request, and how long related data may be retained. The source does not independently confirm Microsoft’s implementation or explain its privacy safeguards.

If the report is accurate, Microsoft’s consumer-facing image tools are treating provenance as part of the generation pipeline rather than as an optional post-processing feature. That matters because an image can look ordinary to a viewer while carrying machine-readable information indicating that AI participated in its creation. C2PA credentials and pixel-level serve different technical roles, but the source does not provide enough detail to assess how they interact or how reliable either mechanism is in practice.

The reported distinction between visible and invisible marks is important for public understanding. A visible Copilot logo can signal AI involvement to a person looking at the image, while an invisible mark may be useful to software that processes large numbers of files. Tom’s Hardware does not report tests showing whether the hidden mark survives resizing, cropping, recompression, screenshots, format conversion or deliberate removal. Without those tests, the practical detection value remains uncertain.

The reported use of a server-issued GUID also creates a privacy question that the article does not resolve. A GUID could be designed only to support provenance verification, but its implications depend on what Microsoft associates with it and who can query or interpret that association. The source does not say whether the identifier is unique to a prompt, image, account, device, moderation request or generation event. It also does not report retention periods, access rules, user disclosures, or whether the identifier can be disconnected from personal information.

The story is therefore consequential mainly as a report about product behavior and accountability, not as proof that Microsoft has created a comprehensive tracking system. Tom’s Hardware attributes the technical findings to Li’s reverse engineering, and the supplied source contains no independent replication, Microsoft documentation, or Microsoft statement confirming the implementation. The report also does not establish that the mechanism is legally required, that it applies to every AI feature in Paint and Photos, or that it provides a dependable answer about an image’s origin.

Interactive Mechanism

互动机制:它实际上是如何运作的

以交互方式探索这一发展背后的基础技术。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
交互式概念检查+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

接下来看什么

The key next steps are Microsoft’s response, technical documentation, and clarification of which Paint and Photos versions are affected. Further scrutiny should establish whether the reported watermark survives common edits, what the server-issued GUID represents, how C2PA credentials are handled, and whether users receive meaningful notice or control.

Microsoft’s public response would help establish whether the reported functions are intentional, what versions of Paint and Photos contain them, and whether the behavior varies by region, account type or generation model. Documentation should clarify the relationship among the visible watermark, pixel-level GUID and C2PA credentials. It should also explain what information the GUID encodes and whether Microsoft maintains a lookup service or associated logs.

Independent technical testing is needed to determine the watermark’s real-world durability. Researchers should examine images produced through local and remote workflows and test ordinary editing operations, including cropping, resizing, compression and file-format changes. They should also compare Paint’s abort-on-failure behavior with Photos’ error-logging behavior to see whether both applications use the same implementation and whether failures are visible to users.

Privacy and user-control questions deserve particular attention. Users need clear notice when a supposedly local workflow sends a prompt to Microsoft servers for moderation, as reported by Tom’s Hardware. They also need to know whether saved files can be stripped of credentials, whether removing them affects functionality, and whether organizations can manage or audit the process. None of those controls or policies is described in the supplied source.

The legal and standards context remains unsettled. Tom’s Hardware links the behavior tentatively to Article 50 of the EU AI Act but explicitly notes that a prompt-specific GUID is not what the article says the rule requires. Future reporting should distinguish between legal compliance, voluntary provenance engineering and product-specific design choices. Until Microsoft or independent researchers provide more evidence, the scope, durability, identifiability and effectiveness of the reported should be treated as meaningful unknowns.

相关指南和测验

AI 伦理人工智能模型解释ChatGPT 与大语言模型测试你所知道的——尝试免费的人工智能测验在我们的词汇表中查找人工智能术语关注 AI 模型发布跟踪器
觉得这有用吗?