Zero Knowledge · Zero Knowledge Podcast

How ZK inspired AI Watermarking with Miranda Christ

August 6, 2025·1 hr 12 min·6 clips
Miranda Christ reveals how zero-knowledge techniques are being adapted to create undetectable watermarks for AI-generated text and images.
Watermarking sounds simple until it gets mixed into generation. Anna Rose sets up the problem: prove content came from an AI model, but keep the mark hidden from whoever consumes it. Miranda Christ brings the research side, walking through how AI watermarking systems work, where they break down, and why models that keep changing make the job messier. Then the image case makes it click. Detection can work by moving backward toward latents, the step before the visible image. That matters because a watermark is not harmless just because people cannot see it. If the system keeps using the same sign vector, it can push outputs in one direction instead of staying tucked away. Brightness is the clean example. Force one component positive often enough and generated images can skew, which means the watermark has changed the distribution. So the answer leans on randomness. Miranda describes schemes that choose many vectors that look independently random, while still allowing someone with a master secret key to detect the mark. That is where the cryptography enters. The object she names is a pseudorandom code, tied to her paper with Sam Gunn. Tarun catches the ZK-adjacent thread fast. He points to succinct proofs and asks whether PRCs are the part that feels closest to familiar zero-knowledge machinery. The discussion stays practical: public verifier or not, whether a verifier exists at all, and what detection runs against after an image has been transformed. The ending lands on the overlap. Watermarking comes off as theory work with real bite, using tools Zero Knowledge listeners already know from cryptography.

As heard by us

A clear link between ZK thinking and the hard problem of watermarking AI output.

Zero Knowledge treats AI watermarking as a practical systems problem, with Anna Rose and Tarun speaking with Miranda Christ about how to prove content came from an AI model without making that proof visible to the person consuming it.

Read the full review in PlayNext →

Why you'd press play

Want the ZK lens on AI watermarking without the fluff?

Read the full recommendation in PlayNext →
Listen to the show on