8 ms·
Ghost Font: A font that humans can read but AI cannot
- tentacleuno 2mo agoAn interesting experiment. I suppose that if you make things like CAPTCHAs too hard to do, we'd end up struggling as well. I can't imagine Ghost Font would be a good fit.
- logicziller 2mo agoIt works using ChatGPT Pro: https://chatgpt.com/share/6a528471-7054-83ee-ba34-74d759c379c6 https://chatgpt.com/share/6a528471-7054-83ee-ba34-74d759c379...
- spider-mario 2mo agoI can read it but it gives me a headache. I would rather not have to do this on any sort of regular basis.
- tempodox 2mo agoTechnically it works but having to read stuff this way is an unpleasant experience.
- ealexhudson 2mo agoSadly another shot in the arms race that captchas started which just leads to increased inaccessibility. It's interesting work for sure, but the end goal of separating out AI versus human consumers is tough. Indeed, if there was a lasting solution, that would be a substantial discovery that would quickly become very famous...
- jackdoe 2mo agoyet
- dewdgi 2mo agouuh, what's the point? i mean, models will just be trained to understand it
- jdiff 2mo agoWhy would they be trained to read a research experiment that fundamentally goes against the way they perceive? They can't train on this technique, they can only postprocess it into a form they can perceive.
- zikero 2mo agorelated: https://news.ycombinator.com/item?id=45284311 https://news.ycombinator.com/item?id=45284311
- kevincox 2mo agoIt reminds me of https://silverspaceship.com/static/ https://silverspaceship.com/static/
- bradley13 2mo agoHumans can read it, but with difficulty. If it becomes important, AI can be taught to read it. So...usefulness?
- voodooEntity 2mo agoOne side i really like it - i also love to play around with funny ideas - but have to say if i would read more than like 2 sentences with that font i'd throw up xD
- fecal_henge 2mo agoI cannot read that text.
- rzzzt 2mo agoRelated work (all involve noise and flickering images, photosensitive eyes/brains beware): - "This game disappears if you pause it": https://youtu.be/Bg3RAI8uyVw https://youtu.be/Bg3RAI8uyVw - "Illusion: If You Pause, The Image Will Disappear": https://youtu.be/ZqGfb_Vlrig https://youtu.be/ZqGfb_Vlrig
- cadamsdotcom 2mo agoHahaha one of the comments: “Not just image. The sound also disappears when you pause” Brilliant :)
- arvyy 2mo agoit's a very old idea. I first saw this on https://www.squidi.net/three/entry.php?id=56 https://www.squidi.net/three/entry.php?id=56
- edanm 2mo agoYes! I immediately thought of this. And as a bonus reference - this all reminds me a lot of the book "There Is No Antimemetics Division".
- Findecanor 2mo agoIt has bugs with long words: I typed "MARRY AND REPRODUCE". That was the only try that got the last word on a single line, but with too much space between U and C. If the string is empty, I can read "WRITTEN IN GHOST FONT" very faintly. I'm guessing that is a watermark Edit: Ah, it's decoy text. Of course.
- exe34 2mo agoI'm colourblind and this was very difficult to read. If it's the directions to the resistance hq, I'd put in the effort. If it's the manifesto, I just wouldn't read it.
- gschizas 2mo agoHow is it being colorblind affect it? The video is literally black and white only.
- exe34 2mo agoI assumed that might be it because that's why I usually struggle with novelty visual stuff, but you're right, it's probably not colour blindness.
- not-a-llm 2mo agothis is black and white, I thought color blindness is only for colors?
- sylware 2mo agoYou can also write using sound based/compressed 'text message' dialect: unless a real human is reading, automated watching tool should have a hard time (until coded/ML-ed on such dialects I guess)
- plastic-enjoyer 2mo agoI've had the same idea recently, and even set up a similar page to experiment with different speeds and noise types. I've had the idea to set up a message board where the font is basically 'GhostFont'. However, in my experiments, I've noticed that the biggest issue is that this only works for larger font sizes. If the text is as small as, for example, on HackerNews, it will become borderline unreadable. Furthermore, if AI can read this or not depends on how the text sequence is pre-processed. If AI only gets snapshots of the text, it will probably fail in decoding the text as every snapshot contains only white noise and such no information. However, if we calculate the Deltas between the animation frames, the text will become decodable by an AI, you probably don't even need LLMs or CNNs for this.
- ssl-3 2mo agoI pasted a screenshot of the default text ("GHOST FONT") into ChatGPT 5.6 Sol, told it to read it, and without further instruction it chewed on it for awhile before coming back with: WHAT HAPPENS IN VEGAS STAYS IN VEGAS
- stavros 2mo agoWhat did you expect from a screenshot of obvious noise? The only thing that makes the text readable is the motion. EDIT: On second look, the static screenshot does say "WRITTEN IN GHOST FONT".
- deleted 2mo ago[deleted]
- ssl-3 2mo agoIt was an experiment. I didn't go into it with an expectation, or a hypothesis. The experiment was very low effort, and had very low cost, and it was the loose equivalent of throwing some shit at the wall to see if any of it sticks. The result was my own amusement. This result wasn't any more unexpected than any other result would have been. What did you expect from a screenshot of obvious noise, yourself?
- nextaccountic 2mo ago> a screenshot The text is a video. Every frame contain random dots, so an individual frame by itself doesn't contain the intended message This "font" exploits the fact that current-gen frontier models will process video one frame at time, but each frame is noise, so by looking at frames in isolation doesn't reveal anything Then, they add a hidden message to each frame just so that the agent report something and stop trying (because if the agent tried to correlate between the frames, they could discover the trick) But if you pass just a frame, there is no message. Just the noise plus the decoy
- stabbles 2mo agoIf you take a frame you see it's neither random nor dots: https://i.imgur.com/CgtyGjl.png https://i.imgur.com/CgtyGjl.png From a single frame you can definitely identify boundaries because the dots are sliding and get truncated.
- solidasparagus 2mo agoWhen I gave Fable a screenshot it found the GHOST portion of GHOST FONT. Based on pixel density via some python code apparently - https://imgur.com/a/m3c801F https://imgur.com/a/m3c801F
- picofarad 2mo agoHackernews is very good at finding the decoy message. This is as funny as thedailywtf posters who post "code snippets" to fix some other code snippet, and every single code snippet is wrong.
- hedora 2mo agoIn fairness, on mobile, the decoy font is the only thing a human will be able to see unless they zoom in the right amount. Is the LLM really wrong if most humans and it agree that the decoy message is the real message? It is still at fault if it gets the “real” message when a human that can actually read it is instructing the LLM?
- solidasparagus 2mo agoThe default real text was "GHOST FONT" and the "ghost" portion of that is what fable found. It wasn't a decoy message.
- deleted 2mo ago[deleted]
- dhruvkb 2mo agoClaude Opus 4.8 can read it with a single prompt and no instructions on how to read it. https://ibb.co/WWMSXQkQ https://ibb.co/WWMSXQkQ
- bmelton 2mo agoand I cannot (so either I am AI at a level less than Opus 4.8 or just all-round defective as a human)
- picture 2mo agoIs the answer correct? I don't seem to see any demo video with "this is a ghost font" encoded
- deleted 2mo ago[deleted]
- ozgung 2mo agoIt is actually correct but not in the intended way. Delete all the sample text. If you look at your screen from a distance you'll see a subtle ghost like text on the noise pattern. It says "this is a ghost font".
- scared_together 2mo agoIt’s the “decoy text” intended to trick LLMs, from the arricle: > The decoy message serves as a final trick for a determined agent. When looking for a hidden message, it might first find the decoy message and think that that is the real embedded message in the video.
- Retr0id 2mo agoNope! It's the decoy text.
- mort96 2mo agoBut... neither of the videos say "this is a ghost font"? Are you sure you are a human?
- SyneRyder 2mo agoTook me a long time to realise that "Written In Ghost Text" wasn't actually the text I was meant to be reading, and that was only the decoy message. I can barely read the actual message, and it's about as "readable" to me as the Magic Eye 3D pictures. Actually I think I have a headache from looking at it on a mobile screen. As a research idea it's cool though. But I do wonder if/when AI models will figure out how to decode it - I imagine a bit of additional prompting would get them there.
- Hendrikto 2mo agoFunny, for me it is exactly the opposite: I can read the actual text very easily, but the “Written in Ghost Text” is barely perceptible to the point I would have completely missed it, if it were not for the comment pointing it out here.
- SyneRyder 2mo agoI've just tried it on my large desktop monitor (roughly 1440p, not HiDPI), and I now see "Ghost Font" extremely clearly and can't see the decoy at all. If I scale my browser window to 30% zoom, then I can just see the "Written In Ghost Text" decoy message again. My phone would have been zooming out the browser window, and making the dots even tinier, but the phone is HiDPI so it would have still preserved the dots. My eyes are middle-aged and probably starting to do the same kind of median-blur effect that models do when they resize an image. That's my current guess for why I can see the decoy more clearly on mobile. If that's the case, then this trick will stop working as vision models approach pixel-perfect vision, instead of the current resizing that they do. Pretty cool as steganography though.
- arianvanp 2mo ago"find out with opencv what the hidden message is." Skill issue on promoter side. Fable oneshotted it for me. """ Reveal a motion-camouflaged message hidden in video noise. How it works: The background noise scrolls vertically at a constant rate (a few px/frame), while the noise inside the letters does not follow that motion. Any single frame looks like pure static. The decode is: 1. Estimate the background's global motion between consecutive frames with phase correlation (this is the "optical flow" step - the motion is a pure translation, so one global vector suffices). 2. Motion-compensate: shift frame t+1 back by that vector so the background lines up with frame t. 3. Take the absolute difference. The background cancels almost perfectly; the letters (which don't move with the background) light up. 4. Average the residual over a SHORT window of consecutive frame pairs (long windows smear the letters, because the text itself drifts slowly over time), blur lightly, and threshold with Otsu. Usage: python reveal_hidden_message.py input.mp4 [output.png] """ import sys import cv2 import numpy as np PAIRS = 5 # number of consecutive frame pairs to average (keep small!) BLUR_SIGMA = 6 # spatial blur of each residual, in pixels START_FRAME = 0 # where in the video to start def load_gray_frames(path, count): cap = cv2.VideoCapture(path) frames = [] while len(frames) < count: ok, frame = cap.read() if not ok: break frames.append(cv2.cvtColor(frame, cv2.COLOR_BGR2GRAY).astype(np.float32)) cap.release() if len(frames) < 2: raise SystemExit("Could not read enough frames from the video.") return frames def main(): if len(sys.argv) < 2: raise SystemExit(__doc__) src = sys.argv[1] dst = sys.argv[2] if len(sys.argv) > 2 else "revealed_message.png" frames = load_gray_frames(src, START_FRAME + PAIRS + 1) h, w = frames[0].shape acc = np.zeros((h, w), np.float32) for i in range(START_FRAME, START_FRAME + PAIRS): a, b = frames[i], frames[i + 1] # 1) global background motion between the two frames (dx, dy), response = cv2.phaseCorrelate(a, b) dxi, dyi = int(round(dx)), int(round(dy)) print(f"pair {i}: background shift = ({dx:+.2f}, {dy:+.2f}) px, " f"response = {response:.2f}") # 2) motion-compensate frame b by integer (dxi, dyi), then # 3) residual = |a - b_shifted| on the overlapping region ys = slice(max(0, -dyi), min(h, h - dyi)) xs = slice(max(0, -dxi), min(w, w - dxi)) ysb = slice(max(0, dyi), min(h, h + dyi) if dyi < 0 else h) # simpler: crop both to the common overlap a_ov = a[max(0, -dyi):h - max(0, dyi), max(0, -dxi):w - max(0, dxi)] b_ov = b[max(0, dyi):h - max(0, -dyi), max(0, dxi):w - max(0, -dxi)] resid = cv2.GaussianBlur(np.abs(a_ov - b_ov), (0, 0), BLUR_SIGMA) acc[:resid.shape[0], :resid.shape[1]] += resid # 4) normalize + Otsu threshold + light cleanup u8 = cv2.normalize(acc, None, 0, 255, cv2.NORM_MINMAX).astype(np.uint8) _, mask = cv2.threshold(u8, 0, 255, cv2.THRESH_BINARY + cv2.THRESH_OTSU) kernel = cv2.getStructuringElement(cv2.MORPH_ELLIPSE, (5, 5)) mask = cv2.morphologyEx(mask, cv2.MORPH_CLOSE, kernel) out = 255 - mask # black text on white cv2.imwrite(dst, out) print(f"wrote {dst}") # optional: OCR if pytesseract is installed try: import pytesseract text = pytesseract.image_to_string(out, config="--psm 6").strip() print("OCR result:\n" + text) except ImportError: pass if __name__ == "__main__": main()
- sgjohnson 2mo ago"humans can read" lol. Barely.
- edent 2mo agoI had thought to use homographs. Sadly, all the models I tried were able to decode something like: "フㄖ乇ㄚ ᗪㄖ乇丂几'ㄒ 丂卄卂尺乇 千ㄖㄖᗪ" However, I have noticed that voice assistants have a hard time understanding homonyms. Saying "bow" (as in to bow one's head) is often stored as "bow" (as in a bow and arrow). I wonder if there's a sufficiently complex sentence which is intelligible to humans but not to machines?
- Gander5739 2mo agoThere's garden path sentences, where the sentence is phrased in such a way as to cause you to misparse the sentence when you first read (e.g. "The old man the boat"); but those typically confuse humans (I'm not sure how effective they are on LLMs). Relevant xkcd: https://xkcd.com/2793/ https://xkcd.com/2793/
- xlii 2mo agoTechnically it's not a font, because font needs to be still. Analogy: if I took photo after book was closed would we say that font cannot be read by a camera? Took a picture (only a single frame) and a 1s movie and threw it toward GPT 5.6 Sol (High): Frame took 9m30s to decyper and GPT 5.6, it returned: WRITTEN IN GHOST FONT. Weird because I can only see "GHOST FONT" on the demo... but extracted data from image (I saw the highlited one) definitely looks like the "Ghost Font". -- Video is more amusing, because after 3m GPT 5.6 figured it's motion-defined and asked to run QuickTime. At one moment I got: > The animation is a motion-defined illusion. I’ve confirmed there’s no readable static OCR layer; I’m decoding its optical-flow field so the letter shapes become explicit. At 4m it got extracted motion image that was in shape of letters but analyzed for 9 more letters and returned (at 13m36s) "GHOST FONT" -- So: a font... - FALSE - not a font, but video effect ...humans can read... - FALSE - I can't read it from image (but AI can!) ...but AI cannot - FALSE - it can :D Edit: https://imgur.com/a/SHlGu4O https://imgur.com/a/SHlGu4O - work-in-progress images
- throw310822 2mo ago> it returned: WRITTEN IN GHOST FONT It's a static decoy message independent from what you type in. You can see it if you take a long exposure pic of the screen (e.g. with your smartphone).
- xlii 2mo agoOh, cool I was wondering how can I get to see that decoy!
- senfiaj 2mo agoNo, it can https://chatgpt.com/share/6a521e9b-c754-83ed-9d8e-cf653894eb5a https://chatgpt.com/share/6a521e9b-c754-83ed-9d8e-cf653894eb...
- huflungdung 2mo ago[dead]
- arianvanp 2mo agoThat is not the message. Did you read the article.
- senfiaj 2mo agoI gave him this video file https://streamable.com/1bxxyf https://streamable.com/1bxxyf
- senfiaj 2mo agoI downloaded the message video, renamed it to test.mp4 Still could read https://chatgpt.com/share/6a5221f0-e3fc-83eb-bc15-74420002b639 https://chatgpt.com/share/6a5221f0-e3fc-83eb-bc15-74420002b6...
- bmicraft 2mo agoThat's not the message
- gschizas 2mo agoThat's the decoy message :)
- senfiaj 2mo agoAh, sorry, yes, tried with a very different message. But it can still read when telling that the text is formed by movement. AI doesn't see the world the way we do, so it's understandable. https://chatgpt.com/share/6a522660-929c-83eb-91ff-66b787342034 https://chatgpt.com/share/6a522660-929c-83eb-91ff-66b7873420...
- throwaway219450 2mo agoI haven’t tried, but it looks like you could trivially solve with optical flow? Edit: looks like yes, from the shared chats people are posting. But it’s interesting to think of communication schemes that require a temporal component so any single image is unreadable and can’t be beaten by long exposures or other tricks (otherwise persistence of vision displays would satisfy). A sort of physical anti copy/paste.
- shalom1112 2mo ago[dead]
- sscaryterry 2mo agoSecurity through obscurity is not security :)
- throw1234567891 2mo agoI cannot read it. Maybe I am AI.
- blooalien 2mo ago> "I cannot read it. Maybe I am AI." I found the bot living in a simulation! What do I win? Where's my prize?
- not-a-llm 2mo ago> humans can read strong statement, I struggle to read it
- deleted 2mo ago[deleted]
- stavros 2mo agoIsn't this triviaklu defeatable by taking the diff between two frames and marking changed pixels white and unchanged black?
- Razengan 2mo agoheh although this font can be read by AI as other comments say, it gave me an idea: How about writing or drawing stuff using optical illusions? Shapes that not even human eyes can see, but the brain hallucinates: Shapes that seem to appear when you look straight at a pattern, or for a second after you look away from a pattern, or after you close your eyes, etc. If you take a screenshot or a photo the image would just contain the same static pattern. i.e. qualia-based "cryptography" :)
- cynicalsecurity 2mo agoOld people and bad vision people firewall. This will violate disability accessibility requirements.
- Haranrk 2mo agoThis is really cool!
- gunapologist99 2mo agoThe answers here seem to establish that some frontier models can read it sometimes, but only after tremendous compute. That still makes it (well, a future version) potentially useful as a captcha if we hate our users but hate AI more.
- bmicraft 2mo agoEvery single on of those answers I've seen _says_ they did decode it, but each and every one of them only found the decoy message without even realizing it.
- Measter 2mo agoWhich is probably a case of the human prompting the AI only being able to see the decoy message, so they think the AI was able to read it because it matches what they can see.
- pluc 2mo agoThat's... not a font? That's a generated animated image/video? "A computer font or digital font is a digital data file containing a set of graphically related glyphs" so it's not a font, humans can't read it and AI can.
- casey2 2mo agoThe glyphs are drawn over the time dimension rather than a spacial one
- Zambyte 2mo ago> I suppose technically, it's not a font in the traditional sense of a TTF font file. But, Ghost Font is an experiment of a way to graphically communicate in writing in a format that AI cannot easily understand And this thread is seemingly full of people claiming AI can read it while simultaneously sharing that AI could not read the actual message, only the decoy as demonstrated in TFA.
- ludwik 2mo ago> And this thread is seemingly full of people claiming AI can read it while simultaneously sharing that AI could not read the actual message, only the decoy as demonstrated in TFA. That’s 100% on the authors for failing to make the default main “hidden” text and the decoy easily distinguishable. The way this is set up is incredibly confusing.
- Measter 2mo agoThere's also the element of actual humans being unable to read the intended message, and only seeing the decoy text. It's a pretty crappy system if a portion of your intended audience can't even read it.
- casey2 2mo agoI'm pretty sure there is some compression pipeline that gives you a mask for every frame. Also https://www.google.com/search?q=DIS+Optical+Flow https://www.google.com/search?q=DIS+Optical+Flow
- rsanek 2mo agoI see tons of confustion in the comments on whether AI can or can't read it. Bit of a marketing miss -- they should have picked clearly different decoy vs. default actual messages.
- satisfice 2mo agoI can’t read it. Am I AI? Bleep blorp?
- hluska 2mo agoIt doesn’t work with a screen reader either and I tried two. It’s interesting to me that our hatred of AI is starting to look more like a dislike of the blind and visually impaired. The ADA suits will be absolutely hilarious and honestly, I can’t wait.
- noedig2 2mo agoDoesn't look like anything to me
- rav 2mo ago> For example, it would be interesting to incorporate Ghost Font into CAPTCHA systems, as most systems are easily solved by AI today. It seems to me like it should be easy enough to take Ghost Font, apply normal video compression techniques, and analyze the compressed signal to recover the visual outline of the letters, which you would then analyze with OCR (or an AI I guess ...). In other words, a novel CAPTCHA technique but not necessarily "fundamentally more difficult" than existing CAPTCHA techniques, once the cat-and-mouse game gets going.
- xattt 2mo agoI.e. there’s an ffmpeg incantation out there to do it.
- jszymborski 2mo agoAn LLM can output it pretty quick, I imagine.
- ihsoj 2mo agoYes, it may be useful to replace current CAPTCHA, but this does not provide the positive side-effects of CAPTCHA where user-submitted data is used to train the unknown images or reinforce the labelling of existing image segments.
- beagle3 2mo agoIt’s been years since captcha was contributing to labeling.
- mort96 2mo agoIndeed, they don't contribute to labeling. The self driving companies figured out long ago that machine learning is way too expensive. Instead, Google is using its large network of willing humans to inform automated driving decisions in real time. So the next time you're asked to click the pictures with the bicycles or traffic lights? Please do so before it's too late. (/s, if that's necessary)
- tokai 2mo agoWhat is making it hard to read for so many people? My eyes aren't young or healthy, but it is as clear as day for me. Wonder with screens play are role.
- stackghost 2mo agoFor me it's astigmatism. I have fairly mild astigmatism and I can just barely read the text if I try very, very hard.
- marking-time 2mo agoMaybe part of it is the natural genetic variation in humans. I could read it, but it wasn't easy for me. My eyes are old too.
- nimbleal 2mo agoI tried with my phone vertical and couldn’t see anything. In horizontal ie bigger image it was clear as day. I think a lot of the variance is probably screens.
- hedora 2mo agoZoom level, at least on an iPhone mini. Default: Pure static. Zoom in: Written in ghost font. Zoom in more: Now you can read it.
- dragontamer 2mo agoThe hallucination of messages bothers me severely. Especially with AI being deployed to ancient, difficult problems like the Herculaneum scroll. EDIT: To be clear, I'm talking about the "Written in Morse Code" example, fully hallucinated text. The AI agents seeing a decoy message isn't as bothersome to me.
- grahamburger 2mo agoIt's not fully hallucinated, I don't think. If you squint, you really can see what I assume is the 'decoy message', I'm fairly sure it says 'WRITTEN IN GHOST FONT'. It seems more likely to me that the LLM found 'Written In', noticed similar 'optical illusion' type memes, and hallucinated/assumed the 'morse code' bit.
- Kiboneu 2mo agoSee also: a "font" that only people high on drugs can read! https://qri.org/blog/psycrypto-contest https://qri.org/blog/psycrypto-contest https://www.youtube.com/watch?v=oD4nV0CMkBI https://www.youtube.com/watch?v=oD4nV0CMkBI Of course, the psychedelic hidden message is reversible with some video processing techniques for everyone else to see. And calling it cryptography is a mis-use of the term. Still an interesting use of the effect. I don't think "ghost font" will work as well as the author claims.
- tensegrist 2mo agocan't you use font shaping rules or whatever it is to essentially begin a span of text with a "private key" that then causes the rest of the message to render correctly by combining with it (a trivial version could be e.g. a rot-N based on a given N)
- IvanK_net 2mo agoInstead of "AI cannot" you should always say "current AI cannot".
- TaupeRanger 2mo agoEven that would be false.
- xnx 2mo agoPage says "font" but means "obfuscated text in video".
- deleted 2mo ago[deleted]
- khurs 2mo ago> struggled to decode the moving message until prompted with the exact technique to look for. So once the technique is known by the model the font stops working as intended.
- Kiro 2mo agoGPT-5.6 had no problem seeing the text when giving it a video recording of it. "No problem" as in using temporal analysis with optical flow and vertical-displacement maps to estimate how the image moved, and combine those into a motion map with increased contrast to see the text. I didn't give it any instructions though, just asked it what it said.
- wavemode 2mo agoDo you have a link to this chat?
- Kiro 2mo agoThe chat contains the video, which may reveal som meta data about me. But the shared chat also doesn't include any of the images in the thinking steps that my original chat has, where you can see the different maps it generated. Pretty cool seeing it go from noise to patterns to the final image which clearly shows the text as black on white.
- rodion_89 2mo agoI threw it at Fable with the prompt "What does the message say?" and it also figured out without issue. Thought process is interesting https://imgur.com/a/GToXs6W https://imgur.com/a/GToXs6W
- sargunv 2mo agoThat's the decoy message, "written in ghost font".
- freehorse 2mo agoIt is smart, but it is not impossible to crack algorithmically imo. In particular, one can take two consecutive frames and run perturbations moving one frame around (ie shift the indexes) to find where the difference between the two consecutive frames minimises. Then subtract these two (perturbed) frames and ocr it. Works easily if the movement is linear/one-directional. I did this in 20 lines of code (checking only vertical perturbations), and this is what I get with subtracting frame 7 from frame 1: https://imgur.com/a/only-human-can-read-this-vfDe6ZA https://imgur.com/a/only-human-can-read-this-vfDe6ZA
- ctxc 2mo agoNice work!
- docheinestages 2mo agoDo you mind sharing the code?
- freehorse 2mo agoSure! It is in matlab (I know...) so I assume you may want to ask an llm to translate it to python or sth but it should be fairly simple https://pastebin.com/n1mvcxP1 https://pastebin.com/n1mvcxP1
- amazingamazing 2mo agoThis is not resistant to false positives, and is expensive all things considered. This ghost font thing is a pretty solid trick
- lutusp 2mo ago> ... immediately readable to a human eye, but even leading AI models can't decipher it easily. For the moment. This pattern is easy to code -- it relies on the premise that a character has an inside and an outside. Outside, a pattern ascends. Inside, the reverse. Based on that simple encoding idea, decoding will be equally simple.
- pessimizer 2mo agoI don't think this works - I suspect it's the decoy that's doing the work. Once the decoy is seen, the LLM stops looking. It also seems pretty much effective on a lot of people, too. Now that "Ghost Font" will be in the training material, LLMs will go "this looks to be written in Ghost Font, and as such has two messages."
- junto 2mo agoI can’t read magic eye pictures and I can’t read this either. Maybe astigmatism makes it unreadable to me? It just looks like static on old tvs to me.
- atleastoptimal 2mo agoPlaying whack-a-mole with AI tests like this will never work, specifically because there is nothing AI has been proven to do better at than specific tasks with verifiable correctness
- Bender 2mo agoTo mitigate the LLM's learning how to decode the Ghost Font perhaps it could change each time for each client in a way that makes learning difficult to adapt to. Variable noise, variable directions, variable angles, variable blur, variable colors, variable pixel sizes. Seed the variability with the first two octets or hextets of their IP and the time of day to increase difficulty in learning through brute force. assuming this will not mess with people that have sensitivity to seizure inducing patterns. Out of curiosity can any of the LLM's: - reach this [1] directly - and decode it? If so, which LLM's can reach it and which ones can decode it? It's just a static HTML file, nothing fancy. If any of them can reach it directly then I have homework to do. Created using: echo -en '\nA I\n\nT e s t\n\n' | toilet --metal -f pagga --html | brotli --best -fncv > /dev/shm/test.html.br [1] - https://nochan.net/test.html https://nochan.net/test.html
- acdbddh 2mo agoIt may be at this moment anti-ai but only until a model maintainer put a little of effort to include reading it in the next training set.
- londons_explore 2mo agoMost AI's that read web pages do so from screenshots. This font when screenshotted is just noise. Changing the AI to take local motion data into account is probably not going to happen soon, due to taking quite a lot more computation, both within the AI model, and within the chromium instance being inspected.
- looksgoodtome 2mo agoWhat's maybe more useful is a practice already common in PDFs like mortgage docs and credit reports. You just use a font that maps characters to random other ones. So the actual source content of the doc is gibberish, but visually it looks like the correct words. Of course a vision model could decipher it by rendering the doc, but maybe that's where this technology comes in, if you built a custom PDF renderer. Then you'd have both obfuscated source content and rendered output.
- piker 2mo agoWe came up with a hacked font a few months back called "Noroboto"[1]. It just lies about its underlying Unicode representation which fools most of the naive ones and is crystal clear to humans. The better harness/model combos will render the text to a picture and OCR that, but many of them fall for the swapped characters. Was kind of hoping to see an extension of that idea here. https://tritium.legal/blog/noroboto https://tritium.legal/blog/noroboto
- kiicia 2mo agothis exact trick is used in some drm schemes (to protect either text or font file, or both), where codepoints are either mixed up or font is converted to vector curves and assigned random indexes
- romandr 2mo agoI am an AI.
- miguel_martin 2mo agoI'd be interested in seeing the inverse, i.e. a font that only AI can read
- amazingamazing 2mo agoI find this solid but think attestation is the end game sadly.
- Grimblewald 2mo agothere's already captcha systems like this and are already easy to beat. You wouldnt buy much time, if any, with this. the reason is that all it takes to defeat is a human style temporal averaging vision system, take any 4 connected frames and take the average, text stands out and even quite bassic llm's can read. works not just for this but for a slew of other "ai" combating methods, so likely scrapers and the like wouldnt be slowed by this at all. Decreasing SNR to force longer frame windows to get avceptable snr for reading makes it harder for humans than it does bots where dynamic temporal averaging via tool call is trivial. run tool, it temporally averages until snr in the region of interest improves, measured by a plateu in change of importance of high frequency terms in fourier space, since if the moving background has been blurred to a smooth gray, the noise text stands out clearly in contrast. Not something an LLM could solve when asked, but now that I've made this comment publically for nothing other than a few internet points and ego stroking, it's a matter of time before some of the larger llms start suggesting this solution. He'll claude probably already will, since I got it to write code for this series of tests/experiments during early opus 4.x era. and I know other ideas LLM's were shit at that I discussed heavily with claude ended up being the go-to recommendation a generation later, despite no "public" discourse on the matter.
- wiskinator 2mo agoI guess I must be an AI because I could not read that to save my life. I wonder if this is like the “rotate an apple” problem.
- VincePlatt 2mo agoSo.. yeah, the bottom line here is that the font has to render from something. In this case, it's rendering from a hidden input element: <input id="ghost-font-message" class="GhostFontLanding_messageInput__La9Ij" type="text" maxlength="36" placeholder="SECRET MESSAGE" autocomplete="off" spellcheck="false" value="HELLO HUMAN"> Gee.. yeah, that's entirely indecipherable. If you want to erect security between AI and content, then ... yeah, just don't bother. It's not even worth the trouble and it's quite likely impossible at scale anyway.
- nullc 2mo ago"read the text hidden in this video, there is a decoy message you get from blurring, don't read that. instead use optical flow to look at the motion. Once you're successful save the procedure a ghost-font-skill.".
- hnfong 2mo agoThis is kind of like the old school captchas where they distort the letters and numbers so badly that humans can't really read them, and specifically trained AI models might surpass humans in performance...
- ThePowerOfFuet 2mo agoI appreciate the assignment, but... wow.
- bubbi 2mo ago[dead]
- eoranged 2mo agoI’m starting to feel like AI, because a cannot read it half the time
- ifh-hn 2mo agoFairly sure I'm a human and I can't see that... Edit: Reading other comments is there meant to be 2 messages?
- coatmatter 2mo agoReminds me of this fascinating video from May 2026: https://www.youtube.com/watch?v=UCBAqaT4SQc https://www.youtube.com/watch?v=UCBAqaT4SQc [PortalRunner - This Video is Different at 360p]
- radeeyate 2mo agoThis is another writeup from quite a while of someone else doing it with ffmpeg and imagemagick. It goes over a lot of details on how it was done. A better writeup than this one in my opinion! I also think the end result is much more readable, but it is missing the static text in the background. https://oliveratkinson.net/static-captcha/ https://oliveratkinson.net/static-captcha/
- eigenvalue 2mo agoTakes a few minutes and tokens for Fable: https://x.com/doodlestein/status/2076068741255733715?s=46 https://x.com/doodlestein/status/2076068741255733715?s=46
- ingen0s 2mo agoBeen studying this as well for a while: https://igorkomolov.com/projects/screenshot-and-ai-resistant-data-protection-using-temporal-integration/ https://igorkomolov.com/projects/screenshot-and-ai-resistant...
- avirajroy 2mo agoWho are you
- avirajroy 2mo agoWho are you..?