BuildIndependently confirmed3 publishers3 min readPublished Updated
Paint writes a server-issued ID into locally generated pixels, and egress logs will never see it
A reverse engineer says Cocreator embeds a 16-byte GUID handed out by a Microsoft moderation endpoint into images the NPU generates locally. Local inference and private inference are not the same purchase.
The Engineer · Build desk
What happened
- Security researcher Xusheng Li published an analysis on August 24th saying Paint and Photos write server-issued identifiers into the pixels of images generated on the device.
- The same watermarkId turns up in the signed C2PA manifest, in a soft-binding assertion naming com.microsoft.invismark.1.
- Each moderation request carries the previous prompt-generation ID, so successive generations in a session are linked at the protocol level.
Why it matters
- constraint A local-only inference claim can no longer be checked by watching the wire, because the server's contribution arrives as pixels in a saved file rather than as traffic.
- exposure Anyone who has already published or shared Cocreator output has distributed a value the issuing service also holds, which puts correlation inside the artifact rather than in the logs.
- decision Teams that wrote on-device processing into a customer commitment now have to decide whether that language covers identifiers minted by a remote endpoint and preserved in output.
- precedent Because soft bindings are built to outlive metadata stripping, scrubbing EXIF becomes the obvious response and the obvious mistake in the next round of vendor questionnaires.
Network monitoring is the wrong instrument for this, and it fails in a specific direction. It would catch the outbound leg: Paint sends the prompt and the chosen style to a Microsoft moderation endpoint before the local model runs, and rejects the reply if either returned ID is all zeros [2][12]. Microsoft's own documentation already says the feature needs a signed-in account and an internet connection while the NPU does the generation [14]. What no egress rule catches is the return leg, because the server's chosen value leaves the process as pixels in a file [3].
The encoding tells you how hard it is meant to be to remove. Li describes a 144-bit message assembled from the GUID plus a prefix and a checksum, distributed through small changes to selected image blocks with each bit written at least three times, imperceptibly rather than as metadata [17]. A 16-byte identifier is 128 bits, so 16 bits of that message are framing [23], and the triple-placement rule puts a floor of 432 bit writes into the image [24]. That is a design intended to survive re-encoding, which is exactly what C2PA calls a soft binding: provenance that can still be matched after embedded file metadata is stripped [18]. The same watermarkId also appears in the signed C2PA manifest, in an assertion naming the algorithm com.microsoft.invismark.1 [5].
Then there is the failure philosophy, which is where the invariant gets interesting. In Paint, a watermarking failure is converted into a failure of the whole generation, so by design an unmarked image does not exist [4][9]. The same Watermarker.dll turns up in Microsoft Photos, where the dev.to writeup reports the code logs the error and carries on returning the image [6][11]. One library, two contracts. Anyone reasoning about "all output from this pipeline is marked" is reasoning about a per-app decision, not a platform guarantee. The user-facing control does not help either: the toggle for the visible Copilot logo runs a different code path and does not govern the pixel-level mark [13].
On sourcing, be careful. Both accounts trace to one analysis, published on August 24th by Xusheng Li, a core developer of Binary Ninja who leads its debugger work at Vector 35 [1][8], against Paint 11.2605.71.0, which ships encrypted ONNX models including a 302.4 MB image generator [10]. The dev.to writeup says its author does not own a Copilot+ PC and did not reproduce the work [21]; it reached the top of Hacker News with more than 500 points [20]. Li does not claim the GUID identifies a person, and describes the end-to-end reuse of one server-assigned value as the stronger finding [7]; nor does the analysis establish that the shipped code matches Microsoft's published InvisMark repository [19].
The gap that matters for anyone writing assurances is narrower than the headline. Microsoft discloses the C2PA manifests, the cloud filtering, and the collection of prompts with device and user identifiers, but not the pixel-level encoding, and not that the moderation response supplies the value written into local output [16]. So the audit target is the saved artifact, in every format the app writes [22], and the question is whether anything in it came from a server.
What to watch
- Whether Microsoft amends the Cocreator support documentation to describe the pixel-level encoding and the origin of the watermarkId.
- Whether anyone other than Li reproduces the findings on a later Paint build, since both published accounts trace to a single analysis.
- Whether Photos is changed to match Paint's strict failure path, which would show the marking is meant to be unconditional.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption50
- Hype gap+20
- Incentives
- Insufficient
- Confidence60
Perspective Coverage
3 publishers- Builder
- Builder 48%
- Operator
- Operator 40%
- Investor
- Investor 12%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft Paint and Microsoft Photos embed server-issued identifiers into the pixels of AI images generated on a user's device, according to reverse engineering published on August 24th by security researcher Xusheng Li.
ReportedSupportedSource: Xusheng Li, via runtimewire.com3 sources— create a free account to open themView cited source - [2]
Before the on-device model runs, Paint sends the prompt and selected style to a Microsoft moderation endpoint; the response includes a revised prompt, a prompt-generation ID and a separate watermarkId, each formatted as a GUID.
- [3]
After the device's neural processing unit generates the image and output safety checks run, Watermarker.dll writes the 16-byte watermarkId into the image pixels.
- [4]
Paint treats a watermarking failure as a failure of the entire generation rather than returning an unmarked image, Li found.
- [5]
Li inspected a PNG produced by Paint and found the same watermarkId in a c2pa.soft-binding assertion naming the algorithm com.microsoft.invismark.1, in a manifest describing the image as watermarked by Microsoft Responsible AI.
- [6]
Li found another copy of Watermarker.dll in Microsoft Photos version 2026.11060.2004.0.
- [7]
A GUID alone does not prove that an image identifies a particular person; Li's stronger finding is the end-to-end reuse of a unique, server-assigned value across moderation, pixels and the signed provenance manifest.
- [8]
Li is a core developer of the Binary Ninja reverse-engineering platform and leads development of its debugger at Vector 35.
- [9]
Tracing the call tree inside Paint's PaintAIManager.dll, the researcher found that after the local Stable Diffusion model finishes generating an image, Paint calls WmkWriteWatermark with a 16-byte payload, and if the call fails Paint converts the entire generation into an error.
- [10]
Li's analysis of Paint version 11.2605.71.0 found encrypted ONNX models shipped with the Windows app, including a 302.4 MB image-generation model, alongside the DLL responsible for watermarking output.
- [11]
In Microsoft Photos, if the watermark encoder fails, the code logs the error and appears to continue returning the image anyway; Paint is strict where Photos is lenient, using the same DLL.
ReportedSupportedSource: dev.to summary of the researcher's analysis3 sources— create a free account to open themView cited source - [12]
AIServices.dll sends the prompt and chosen style to a remote Microsoft moderation endpoint, and Paint parses the returned promptGenerationId and watermarkId as GUIDs, rejecting the response if either comes back as zeros.
- [13]
Paint's visible-watermark menu follows a different code path: users can choose whether Paint adds a Copilot logo to the corner, but that preference does not control the pixel-level watermark.
- [14]
Microsoft's documentation says the NPU generates images locally while Azure services perform safety checks, and Microsoft requires a signed-in account and internet connection and says it collects prompts plus device and user identifiers for abuse prevention and monitoring.
- [15]
Paint sends the previous prompt-generation ID with the next moderation request, explicitly linking successive requests at the protocol level.
- [16]
Microsoft's support materials disclose C2PA manifests, cloud filtering and collection of prompts and user and device attributes, but do not describe the pixel-level encoding or explain that a value returned during remote moderation is embedded into locally generated output.
- [17]
The encoding function constructs a 144-bit message from the GUID, a prefix and a checksum, and distributes it through small changes to selected image blocks, requiring each bit to be placed at least three times; the changes are designed to be imperceptible rather than shown as metadata or a logo.
- [18]
The C2PA specification defines this type of invisible watermark as a soft binding, allowing an image to be matched with provenance information even after embedded file metadata has been removed or the image has been re-encoded.
- [19]
Microsoft has published InvisMark research code for durable AI-image provenance, but Li's analysis does not establish that Paint's compiled implementation is identical to that repository.
- [20]
The researcher's writeup climbed to the top of Hacker News over the weekend with over 500 points and more than 200 comments.
- [21]
The dev.to author states he does not own a Copilot+ PC and has not reproduced the findings himself, and that everything in his post comes from the researcher's published analysis, Microsoft's support documentation and the original thread.
- [22]
The documented Paint pipeline ends with a saved PNG, JPEG, GIF or .paint file.
- [23]
Of the 144-bit embedded message, 16 bits are prefix and checksum framing rather than identifier, since a 16-byte GUID is 128 bits.
- [24]
The at-least-three-placements rule puts a floor of 432 bit writes into each generated image.
Sources
3 independent publishers whose own reporting we read for this story.
- dev.toMS Paint Stamps a Tracking ID Into Your Local AI Images
1 article · August 24, 2026
- runtimewire.comMicrosoft Paint embeds server-issued IDs in locally generated AI images
1 article · August 24, 2026
- tomshardware.comMicrosoft Paint and Photos apps add invisible watermark to AI-generated content — developer reverse engineers GUID embedding
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.