返回新聞
產品展示AI Understanding 簡報

Tom’s Hardware 報告 Microsoft Paint 和 Photos AI 影像中存在不可見的 GUID 浮水印

Tom’s Hardware 報告稱,Microsoft Paint 和 Photos 將不可見的伺服器發布的 GUID 資料與 C2PA 憑證一起嵌入到 AI 生成的圖像中。這項發現來自開發者 Xusheng Li 的逆向工程,尚未得到 Microsoft 的獨立證實。

5 min readRead the original reporting
Source-provided image accompanying Tom’s Hardware reports invisible GUID watermarks in Microsoft Paint and Photos AI images
歸因報告來源記錄
出版商
tomshardware.com
來源連結
tomshardware.comhttps://www.tomshardware.com/tech-industry/artificial-intelligence/microsoft-paint-and-photos-apps-add-invisible-watermark-to-ai-generated-content-developer-reverse-engineers-guid-embedding
來源類型
新聞媒體的報道-不是第一方文件。

我們無法獨立確認的內容: 此聲明歸因於指定的商店。我們沒有根據第一方文件對其進行驗證。 (tomshardware.com)

背景60 秒內了解這一點

從這裡開始

關鍵術語

API(應用程式介面)
一種軟體系統向另一個系統發送請求並接收回應的結構化方式。
水印
在人工智慧生成的文字或媒體中嵌入可偵測訊號,以便稍後將其識別為機器生成的。
嵌入
擷取文字、影像或其他資料語意的數位向量表示。
測試一下自己人工智慧道德測驗

發生了什麼事

Tom’s Hardware reports that developer Xusheng Li discovered previously undocumented behavior in Microsoft Paint and Photos when their AI image-generation features are used. The report says the apps apply both visible Copilot branding in some cases and an invisible watermark intended to identify or verify that AI participated in creating an image.

Tom’s Hardware reports that developer Xusheng Li investigated the AI features in Microsoft Paint on Windows 11 after finding that the app could call a remote image-generation API. The report says Li also found four apparent model files in the application path for local processing: one file resembling an ONNX model and three encrypted ONNX-like files. The article presents this discovery as the starting point for examining how Microsoft’s AI image features mark generated content.

According to Tom’s Hardware, Li found a file named watermarker.dll while probing the application. The report says Li initially believed the file handled only visible , including a Copilot logo placed in the lower-right corner of an image. The article says further analysis, assisted by an AI tool, identified a separate function called WmkWriteWatermark for invisible watermarking, in addition to the visible-watermark function AddPerceptibleWatermark.

Tom’s Hardware reports that the invisible process mixes a server-issued globally unique identifier, or GUID, into image pixels. The report also says Paint attaches C2PA Content Credentials to saved files, with code associated with ProvenanceHelper.dll and provenancesdk.dll. The source does not establish what the GUID specifically identifies, whether it maps to a prompt, account, session or other event, or whether Microsoft retains a corresponding record.

The article reports different failure behavior in Paint and Photos. In Paint, Tom’s Hardware says the watermark is mandatory for Stable Diffusion image-generation output and that image generation fails if WmkWriteWatermark cannot be written. In Photos, the report says the app still returns the image but logs an error when the process has a problem. Tom’s Hardware also reports that prompts from local image-generation workflows are sent to Microsoft servers for moderation. The article speculates that the processing may relate to Article 50 of the EU AI Act, whose transparency rules the report says took effect on August 2, 2026, while noting that the rules do not specifically call for a prompt-specific GUID. Microsoft’s response, if any, is not included in the supplied report.

來源詳情: tomshardware.com ↗

為什麼這很重要

The reported behavior could give users, platforms and investigators another way to identify AI-assisted images, but it also raises unanswered questions about what information is embedded, how it is linked to a user or request, and how long related data may be retained. The source does not independently confirm Microsoft’s implementation or explain its privacy safeguards.

If the report is accurate, Microsoft’s consumer-facing image tools are treating provenance as part of the generation pipeline rather than as an optional post-processing feature. That matters because an image can look ordinary to a viewer while carrying machine-readable information indicating that AI participated in its creation. C2PA credentials and pixel-level serve different technical roles, but the source does not provide enough detail to assess how they interact or how reliable either mechanism is in practice.

The reported distinction between visible and invisible marks is important for public understanding. A visible Copilot logo can signal AI involvement to a person looking at the image, while an invisible mark may be useful to software that processes large numbers of files. Tom’s Hardware does not report tests showing whether the hidden mark survives resizing, cropping, recompression, screenshots, format conversion or deliberate removal. Without those tests, the practical detection value remains uncertain.

The reported use of a server-issued GUID also creates a privacy question that the article does not resolve. A GUID could be designed only to support provenance verification, but its implications depend on what Microsoft associates with it and who can query or interpret that association. The source does not say whether the identifier is unique to a prompt, image, account, device, moderation request or generation event. It also does not report retention periods, access rules, user disclosures, or whether the identifier can be disconnected from personal information.

The story is therefore consequential mainly as a report about product behavior and accountability, not as proof that Microsoft has created a comprehensive tracking system. Tom’s Hardware attributes the technical findings to Li’s reverse engineering, and the supplied source contains no independent replication, Microsoft documentation, or Microsoft statement confirming the implementation. The report also does not establish that the mechanism is legally required, that it applies to every AI feature in Paint and Photos, or that it provides a dependable answer about an image’s origin.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

接下來看什麼

The key next steps are Microsoft’s response, technical documentation, and clarification of which Paint and Photos versions are affected. Further scrutiny should establish whether the reported watermark survives common edits, what the server-issued GUID represents, how C2PA credentials are handled, and whether users receive meaningful notice or control.

Microsoft’s public response would help establish whether the reported functions are intentional, what versions of Paint and Photos contain them, and whether the behavior varies by region, account type or generation model. Documentation should clarify the relationship among the visible watermark, pixel-level GUID and C2PA credentials. It should also explain what information the GUID encodes and whether Microsoft maintains a lookup service or associated logs.

Independent technical testing is needed to determine the watermark’s real-world durability. Researchers should examine images produced through local and remote workflows and test ordinary editing operations, including cropping, resizing, compression and file-format changes. They should also compare Paint’s abort-on-failure behavior with Photos’ error-logging behavior to see whether both applications use the same implementation and whether failures are visible to users.

Privacy and user-control questions deserve particular attention. Users need clear notice when a supposedly local workflow sends a prompt to Microsoft servers for moderation, as reported by Tom’s Hardware. They also need to know whether saved files can be stripped of credentials, whether removing them affects functionality, and whether organizations can manage or audit the process. None of those controls or policies is described in the supplied source.

The legal and standards context remains unsettled. Tom’s Hardware links the behavior tentatively to Article 50 of the EU AI Act but explicitly notes that a prompt-specific GUID is not what the article says the rule requires. Future reporting should distinguish between legal compliance, voluntary provenance engineering and product-specific design choices. Until Microsoft or independent researchers provide more evidence, the scope, durability, identifiability and effectiveness of the reported should be treated as meaningful unknowns.

相關指引和測驗

AI 倫理人工智慧模型解釋ChatGPT 與大型語言模型測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注 AI 模型發布追蹤器
覺得有用嗎?