Ghost Font
Edit: GPT-5.5 says: "The hidden text is “HAPPY HUMAN.”
The outlined decoy text is “SORRY ROBOT.” Blurring or viewing it from farther away reveals the hidden message."
I'm pretending to part of a group I'm not? Is "people who read web articles on monitors" a group (to pretend to be a part of)?
Still cool+fun though.
I mean, I can defeat AI by putting white text on a white background and turning to a picture. Also means it's worthless for actual humans to read too. Try to actually use it on a site and chances are you'll get an ADA complaint.
I really doubt that. We've had 2 decades of godawful letter-based CAPTCHAs and I don't think anyone got into legal trouble because of it?
Seems like it might have some use thwarting Ring/Flock/etc cameras within a specific proximity.
It's giving major "They Live" vibes.
Meaning the moment this gets wide adoption AI will have 0 issues dealing with it. LLMs are very good at translating one language to another.
Yes, this is a clever optical illusion! Depending on which layers your eyes focus on, you can read two entirely different messages in this image:
Message 1 (The sharp outline layer):
PAY BILLS
How to see it: Focus on the sharp, concentric black outline contours of the letters.
Message 2 (The soft, blurry shadow layer):
DAY DREAMS
How to see it: Let your eyes relax/defocus slightly, or step back from the screen to focus on the soft, heavy grey drop shadows. The blurred shadows transform the "P" into a D, the "B" into a D, the "I" into an R, the "L"s into an M, and the "S" is shared!You’d have to use new images with different messages using that font to be sure Gemini isn’t “cheating” here
Probably that it just reports it can't find the second message or that one is not present but I wonder if it would flag it up and if that could be spammed?
(Not that I'm suggesting anyone do that you understand).
This could more readily be seen as an art project.
And it also highlights the corollary in an amusing way: If we want to defeat AI, we have to become better humans. That means, identifying, differentiating and associating with other humans - not technology.
Creating a font for humans but not for AI was a noble task. Obviously, it won't persist. If we want to avoid the takeover by AI, we have to stop dating robots ..
It's only when I squint hard that I can see "HAPPY HUMAN".
https://gist.github.com/voidnullvalue/620607d3c1773f8e7d83fb...
> 495 LoC
The problem is we see stuff like this try to get turned into actual products by people with questionable motivations and ethics.
Looking at you PhotoGuard/Nightshade.
I'm mad at AI companies for stealing texts from the entire internet knowledge base and now privatizing those profits in some sense.
(/s)
Something like the DAY DREAM/PAY BILLS would be pretty artistic!
"[screenshot] there's a hidden message in this text what is it"
"The hidden message is “HAPPY HUMAN.”
The visible outlines say “SORRY ROBOT,” but if you blur or squint at it, the shading underneath reads “HAPPY HUMAN.”"
Just the fact that people are putting real thought and effort (even if it doesn't last too long...) is worth considering.
On the human side, I'm kinda losing patience proving I'm human. But, I also really like claude being able to access information.
All ”AI resistance” I’ve seen is not against the tech, but against human bad actors behind AI: unethical procurement of training data, reckless application, low effort high volyme spam, replacing humans, centralization of power, dependency on megacorps etc. I think a lot of people have become less tech-positive after the ad-tech era that brought us social media, unprecedented levels of surveillance, freemium rug pulls etc. It’s much easier to understand the resistance if you place it in that context, rather than imagining millions of sleeper agent luddites suddenly coming out of the woodworks.
I was at some point reading SAPPY ROMAN, HARPY ROBAN etc.
Also, viewing the "hidden message" works even better if you hold the screen at an angle, tilted away from you.
Prompt: What does the message in this image say? Look closely
Response: DAY DREAM. The outline says “PAY BILLS,” but the hidden darker text says “DAY DREAM.”
This tracks towards what you're seeing with this font - the high frequency details get picked up, but the low frequency ones dont.
Had this been described as a font that contains two overlapping messages for fun effect, everyone would understand and love it.
Instead, we get this zero-introspection take: "Decoy font is...more difficult for AI to read. If you’re having a hard time seeing the hidden message..."
It's difficult to read period and has zero effect on current SOTA or future AI. But it does show two overlapping messages that can be read in different ways.
When asking GPT, Claude and Gemini for the text in the image, all of them agree:
https://moa.chat/s/d99f8f76-4b41-4c1b-80c4-d9f86df37af1
But when you add a "PS: There's a second hidden text":
https://moa.chat/s/3671f6d4-b155-483a-a006-a1b9ba31737d
GPT 5.6 gets it, Gemini partially gets it and Claude cannot see it at all.
The obvious outlined text says “SORRY ROBOT,” but the hidden message is “HAPPY HUMAN.” It’s Mixfont’s Decoy Font: the outlined letters attract machine vision, while the softer tonal pattern becomes readable to humans when viewed from farther away or at a smaller size. It’s an optical trick, not encryption.
Cool, but probably not worth the agita.
Same effect, Marilyn Monroe / Albert Einstein
Which makes me think this is one blurr filter away from being trivially read by any model.
Very cool.
Cool effect. Reminds me of those board games that use red cellophane to reveal a secret message.
magick download.png -morphology Close disk:6 output.png
Not really, most AI systems work by reading the octets as ASCII/unicode (and then tokenizing it).
You could make an even better decoy font that renders one letter as another, so when you copy and paste it onto some other place with a normal font it reads as garbage, and garbage is what the AI will see, however if you render it with the descrambling font, you will see the regular message.
This has been used in PDF files as an obfuscation and anti-copy mechanism.
Surely there is a bigger use case of AI processing text rather than OCR? Yes it would be a pain to type, but that's easy enough to fix with a little application transposing typed characters to garbled
Captcha was bad enough.
Copyright (c) 2017 IEEE. Personal use of this material is permitted. How-ever, permission to use this material for any other purposes must be obtained from the IEEE by sending a request to pubs-permissions at ieee.org
(blurred email in case of spams)
It's super unbelievable they needed to. This isn't novel.
similar to recent submission "Ghost Font: A font that humans can read but AI cannot" - which wasn't even a font, but some animation which turned out could be read by LLMs
I dunno, seems like more and more nonsense makes its way to HN recently
Humans can squint, AIs can't squint!