Skip to content

BuildIndependently confirmed3 publishers3 min readPublished Updated

Paint writes a server-issued ID into locally generated pixels, and egress logs will never see it

A reverse engineer says Cocreator embeds a 16-byte GUID handed out by a Microsoft moderation endpoint into images the NPU generates locally. Local inference and private inference are not the same purchase.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Security researcher Xusheng Li published an analysis on August 24th saying Paint and Photos write server-issued identifiers into the pixels of images generated on the device.
  • The same watermarkId turns up in the signed C2PA manifest, in a soft-binding assertion naming com.microsoft.invismark.1.
  • Each moderation request carries the previous prompt-generation ID, so successive generations in a session are linked at the protocol level.

Why it matters

  • constraint A local-only inference claim can no longer be checked by watching the wire, because the server's contribution arrives as pixels in a saved file rather than as traffic.
  • exposure Anyone who has already published or shared Cocreator output has distributed a value the issuing service also holds, which puts correlation inside the artifact rather than in the logs.
  • decision Teams that wrote on-device processing into a customer commitment now have to decide whether that language covers identifiers minted by a remote endpoint and preserved in output.
  • precedent Because soft bindings are built to outlive metadata stripping, scrubbing EXIF becomes the obvious response and the obvious mistake in the next round of vendor questionnaires.

Network monitoring is the wrong instrument for this, and it fails in a specific direction. It would catch the outbound leg: Paint sends the prompt and the chosen style to a Microsoft moderation endpoint before the local model runs, and rejects the reply if either returned ID is all zeros [2][12]. Microsoft's own documentation already says the feature needs a signed-in account and an internet connection while the NPU does the generation [14]. What no egress rule catches is the return leg, because the server's chosen value leaves the process as pixels in a file [3].

The encoding tells you how hard it is meant to be to remove. Li describes a 144-bit message assembled from the GUID plus a prefix and a checksum, distributed through small changes to selected image blocks with each bit written at least three times, imperceptibly rather than as metadata [17]. A 16-byte identifier is 128 bits, so 16 bits of that message are framing [23], and the triple-placement rule puts a floor of 432 bit writes into the image [24]. That is a design intended to survive re-encoding, which is exactly what C2PA calls a soft binding: provenance that can still be matched after embedded file metadata is stripped [18]. The same watermarkId also appears in the signed C2PA manifest, in an assertion naming the algorithm com.microsoft.invismark.1 [5].

Then there is the failure philosophy, which is where the invariant gets interesting. In Paint, a watermarking failure is converted into a failure of the whole generation, so by design an unmarked image does not exist [4][9]. The same Watermarker.dll turns up in Microsoft Photos, where the dev.to writeup reports the code logs the error and carries on returning the image [6][11]. One library, two contracts. Anyone reasoning about "all output from this pipeline is marked" is reasoning about a per-app decision, not a platform guarantee. The user-facing control does not help either: the toggle for the visible Copilot logo runs a different code path and does not govern the pixel-level mark [13].

On sourcing, be careful. Both accounts trace to one analysis, published on August 24th by Xusheng Li, a core developer of Binary Ninja who leads its debugger work at Vector 35 [1][8], against Paint 11.2605.71.0, which ships encrypted ONNX models including a 302.4 MB image generator [10]. The dev.to writeup says its author does not own a Copilot+ PC and did not reproduce the work [21]; it reached the top of Hacker News with more than 500 points [20]. Li does not claim the GUID identifies a person, and describes the end-to-end reuse of one server-assigned value as the stronger finding [7]; nor does the analysis establish that the shipped code matches Microsoft's published InvisMark repository [19].

The gap that matters for anyone writing assurances is narrower than the headline. Microsoft discloses the C2PA manifests, the cloud filtering, and the collection of prompts with device and user identifiers, but not the pixel-level encoding, and not that the moderation response supplies the value written into local output [16]. So the audit target is the saved artifact, in every format the app writes [22], and the question is whether anything in it came from a server.

What to watch

  • Whether Microsoft amends the Cocreator support documentation to describe the pixel-level encoding and the origin of the watermarkId.
  • Whether anyone other than Li reproduces the findings on a later Paint build, since both published accounts trace to a single analysis.
  • Whether Photos is changed to match Paint's strict failure path, which would show the marking is meant to be unconditional.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption50
Hype gap+20
Incentives
Insufficient
Confidence60

Perspective Coverage

3 publishers
Builder
Builder 48%
Operator
Operator 40%
Investor
Investor 12%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Microsoft Paint and Microsoft Photos embed server-issued identifiers into the pixels of AI images generated on a user's device, according to reverse engineering published on August 24th by security researcher Xusheng Li.

    ReportedSupportedSource: Xusheng Li, via runtimewire.com3 sources— create a free account to open themView cited source
  2. [2]

    Before the on-device model runs, Paint sends the prompt and selected style to a Microsoft moderation endpoint; the response includes a revised prompt, a prompt-generation ID and a separate watermarkId, each formatted as a GUID.

  3. [3]

    After the device's neural processing unit generates the image and output safety checks run, Watermarker.dll writes the 16-byte watermarkId into the image pixels.

Sources

3 independent publishers whose own reporting we read for this story.

  1. dev.to

    1 article · August 24, 2026

    MS Paint Stamps a Tracking ID Into Your Local AI Images
  2. runtimewire.com

    1 article · August 24, 2026

    Microsoft Paint embeds server-issued IDs in locally generated AI images
  3. tomshardware.com

    1 article · August 26, 2026

    Microsoft Paint and Photos apps add invisible watermark to AI-generated content — developer reverse engineers GUID embedding

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories