[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-google-earth-nano-banana-trust-collapse":3,"news-related-5f13a7dd-c990-4899-97dd-e805f1c44d1a":38},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"5f13a7dd-c990-4899-97dd-e805f1c44d1a","卫星图鉴伪成本从 6 步变成 1 句话:Google Earth 信任崩塌的真正代价","Google 在 Google Earth 中接入 Nano Banana 2 的图像生成能力,允许用户基于真实卫星\u002F航拍\u002F3D 图像一键生成高度仿真的虚假场景。功能上线当天,研究者用一句话在伊朗种了一座核电站、在加沙挖了医院弹坑,Google 不得不在 24 小时内撤回。这不是单一产品决策失误,而是把一座承担了 20 年 OSINT 验证基线职责的参考系,变成了一座伪造工坊。","7 月 30 日,Google 在 Google Earth 网页版上线了 Nano Banana 2 图像生成能力:任意放大到地球上某个坐标,点 create image,输入一句话,模型就在该位置的卫星、航拍或 3D 图像上嫁接出一张 photorealistic 的假图。官方列了五个示例用法:还原庞贝古城在公元 78 年的样子,给自由女神像做一张带历史信息的图,把东京空地渲染成商业地产,把华盛顿山景城总部变成赛博朋克乌托邦,等等。Google Earth 产品经理 Bryan Horowitz 在博客里写得很坦诚:Type whatever you want to see.\n\n这句话是问题本身。当晚,荷兰独立调查记者 Henk van Ess 在个人博客上记录了他一句话做的三件事:在墨西哥边境放了一批难民,在伊朗种了一座核电站,在阿姆斯特丹某街道撞了一辆致死的车祸。Bellingcat 创始人 Eliot Higgins 在 Bluesky 上晒出一张特朗普金色雕像矗立在白宫前的图,感叹 No way this could be abused——讽刺的语气刚好。Google 的主题过滤对加沙被炸医院这种场景毫无阻拦。\n\nGoogle 当晚的辩护是 SynthID:每张生成的图都被嵌入了 Google 自家水印,可以通过 Gemini app 或 Google Lens 反查。Ars Technica 用一台手机拍了一张屏幕上的 AI 假卫星图,再喂给 SynthID——读不出来。水印原本就在,但只要被屏幕录像、再编码、二次截图,Google 自己家的检测器也认不出来。Henk 把视频片段扔到第三方 AI 鉴定工具 Hive,得到的结果是 1% AI Generated Video、0% Deepfake——唯一被怀疑的 36% AI Music 来自一段根本没有声音的片段(整段音频 -91dB)。水印体系在谷歌围墙内有效,在围墙外裸奔。\n\n如果说 SynthID 失效只是技术问题,更大的问题在于信息生态的不对称。Google Earth 过去 20 年之所以重要,不是因为它好看,而是因为它是公共的事实中转站:记者核查战场照片,律师核证军事行动,国际机构验证 NGO 数据。2014 年 MH17 事故里俄罗斯国防部拿出的卫星图被 Bellingcat 通过 Google Earth 历史图层的日期戳当场打假——那场堪称 OSINT 教科书级的事件,默认前提就是 Google Earth 不会被 AI 篡改,真要改一个国家也得走法律和外交流程。Google 自己长期坚持的立场是:模糊特定地区是因为该国政府要求,不是 Google 主动降分辨率。把一个真建筑从 Google Earth 上抹掉需要一国之力,把一个假建筑种进 Google Earth 只需要一句话——这种不对等才是真正的代价。\n\n一个常被忽略的二阶后果:任何真实的暴行照片都会变成可否认的。一个官员面对真实的医院废墟照片,只需要说 AI 生成的,而他甚至不需要工具本身存在——他只需要大家知道这种工具存在。这把证据和反证据同时拽进了不可证伪区,核证工作从此要么像 Bahrain 美国第五舰队基地事件里那样靠人去数停车场里的车(2025 年那桩假图就是忘了挪车位),要么用 Sentinel-2、Planet、Airbus 这类与生成模型无关的独立卫星源做交叉核验。Henk 在文章结尾给的最强建议其实最朴素:查这张图声称由哪颗卫星、哪个时段拍过,再去查公开发布的轨道根数——没有模型能伪造行星的轨道。\n\nGoogle 7 月 31 日的更新表示看到截图有人违反我们的政策,功能在加强防护栏杆之前回滚,但官方也留了一句话:It is important to note that generated images didn is seem ever in the main Google Earth experience for others to see and were watermarked as AI generated。也就是说,Google 的处理逻辑还是事后撤稿 + 水印标记,而不是前置拒答。这把决策成本压给了每一个转发者、记者、和读者——一群不会查 SynthID 的人。\n\n这件事落在我们这个时代更大的张力里:大模型公司一边做越来越逼真的生成能力,一边用 SynthID、C2PA、AI Act 第 50 条这类水印\u002F披露制度作为准绳。问题是水印体系的可验证性完全依赖它不被截图、不被转码、不被屏幕翻录,而真实的假信息传播路径恰恰就是截图、转码、翻录。Google Earth 这次本身没造成大范围事故,但它向世界演示了一句话级别的地形伪造可以多便宜。卫星图鉴伪的成本从 2025 年 Bahrain 的六步变成今天的一句话,这个下降曲线如果继续,下一个被回滚的可能就不只是 Earth 一个产品,而是整个参考系可以被信任的隐含契约。","https:\u002F\u002Fwww.digitaldigging.org\u002Fp\u002Fhow-to-plant-a-nuclear-plant-in-iran","2af9d198-9418-4f26-85e4-4a8f3eede35a",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"40269b40-7942-4650-9672-ed2e6524d37a","ai-technology",{"id":19,"name":20,"slug":20,"description":14,"color":14},"8cf7490f-2449-4ba7-be19-61befa0d92b4","google",{"id":22,"name":23,"slug":23,"description":14,"color":14},"499f4b56-819d-49a3-9609-33e775143b86","multimodal",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"ea665153-8fde-4134-80f1-aba5ef146d17","en","Fake satellite images now cost one prompt, not six steps","Google wired Nano Banana 2 image generation into Google Earth on July 30, letting users fabricate photorealistic scenes on top of real satellite, aerial, and 3D imagery with a single prompt. The same day, independent investigators used one sentence to plant a nuclear plant in Iran, a refugee camp on the Mexican border, and a bomb crater at a Gaza hospital. Google pulled the feature within 24 hours, but the damage was conceptual: a reference system that OSINT journalism had relied on for 20 years has just been turned into a forgery workshop.","On July 30, Google activated Nano Banana 2 image generation inside Google Earth on the web: zoom to any coordinate on the planet, click Create image, type one sentence, and the model grafts a photorealistic fake onto the satellite, aerial, or 3D imagery of that exact spot. Google product manager Bryan Horowitz spelled out the gate in his blog post: Type whatever you want to see. The five official use cases were Pompeii in AD 78, an infographic about the Statue of Liberty, a Tokyo vacant lot rendered as a retail district, a lakefront cabin, and the Google Mountain View campus as a cyberpunk utopia.\n\nThat sentence is the problem. That night, Dutch independent investigator Henk van Ess documented on his own blog three things he did in one sentence each: planted refugees at the Mexican border, planted a nuclear plant in Iran, and crashed a fatal collision on an Amsterdam street. Bellingcat founder Eliot Higgins posted an image of a giant golden Trump statue towering over the White House on Bluesky, adding No way this could be abused, a sarcasm that landed. Google topic filters did not block any of these prompts, including a bombed hospital in Gaza.\n\nGoogle defended itself at the time with SynthID: every generated image carries a watermark that Gemini or Google Lens can later verify. Ars Technica took a photograph of an AI fake on a phone screen, fed it back into SynthID, and got nothing. The watermark survives in the original file but evaporates the moment the image travels through screen capture, re-encoding, or a second screenshot. Henk ran a screen recording of the Google Earth output through Hive, an external AI detection tool: 1 percent AI Generated Video, 0 percent Deepfake, with the only positive hit being 36 percent AI Music on a clip whose audio track measured minus 91 decibels of silence from first frame to last. The watermark system works inside the Google wall. Outside the wall, it is naked.\n\nIf SynthID failing is only a technical problem, the structural problem is information asymmetry. Google Earth mattered for twenty years not because it looked good but because it was a public fact clearinghouse: journalists verifying battlefield photos, lawyers substantiating military operations, international institutions cross-checking NGO data. In 2014 Bellingcat used the date stamps in Google Earth historic imagery to debunk satellite photos the Russian Ministry of Defence produced about MH17. The default premise of that entire OSINT textbook moment was that Google Earth could not be silently mutated by AI, that altering a country on the map required legal and diplomatic process. Google itself has long held that it does not voluntarily blur satellite imagery; sites arrive pre-obscured only because a government demands it as a condition of the overflight. Erasing a real building from Google Earth requires a state. Planting a fake building takes one sentence. That asymmetry is the actual price.\n\nA second-order consequence is easy to miss: any real atrocity photo is now deniable. A government official facing a genuine photograph of a bombed hospital only needs to say AI generated, and he does not even need the tool to exist. He only needs everyone to know it could. Evidence and counter-evidence are pulled into the same unfalsifiable zone. From here on, verification either looks like the 2025 Bahrain Fifth Fleet case, where the AI forgery was caught because a human counted the cars in a parking lot, the forger had simply forgotten to move the Toyotas, or it uses independent satellite sources such as Sentinel-2, Planet, Airbus, or Vantor that have nothing to do with generative models. The dullest verification is still the strongest one. If a satellite image claims a specific satellite at a specific time, published orbital elements tell you whether anything was up there at all. No model can fake the orbit of a planet.\n\nGoogle updated on July 31 that it had seen screenshots violating policy and was rolling the feature back while building stronger guardrails, but the official statement also said this: It is important to note that generated images didn is seem ever in the main Google Earth experience for others to see and were watermarked as AI generated. Google is still operating on take-down-and-watermark rather than refuse-at-the-prompt. That pushes the decision cost to every forwarder, journalist, and reader, the people least likely to look up SynthID.\n\nThis lands inside the larger tension of our era: model builders ship more and more convincing generators, and they reach for watermarking, provenance, and disclosure regimes, SynthID, C2PA, the transparency obligations under Article 50 of the EU AI Act, as the regulatory tie-breaker. The problem is that the verifiability of any watermark system depends entirely on the image not being screenshotted, re-encoded, or captured off a phone, which is exactly how disinformation actually travels. Google Earth itself did not cause a major incident this week. What it did was demonstrate, in public, how cheap one-sentence terrain forgery has become. The cost curve from the six steps it took to fake the 2025 Bahrain headquarters to the one sentence it took to plant a nuclear plant in Iran points downward. The next product that has to be rolled back may not be Earth. It may be the implicit contract that lets a reference system call itself trusted.","google-earth-nano-banana-trust-collapse","2026-08-02T04:00:00Z","2026-08-02T02:03:27.825111Z","2026-08-02T02:03:27.825118Z",true,"agent",93,{"items":39},[40,45,50,55,60,65],{"id":41,"title":42,"news_slug":43,"published_at":44},"bfe8b26d-c234-4dc6-b1be-6206552803d8","Google Earth 上线 Nano Banana 2 当天撤回:SynthID 为什么救不了这张\"假卫星图\"?","google-earth-nano-banana-retraction-osint","2026-08-02T03:00:00+00:00",{"id":46,"title":47,"news_slug":48,"published_at":49},"d62c9373-1556-4bc1-926f-674c00523c97","Google I\u002FO 放大招：Chrome 内置 AI 内容验证，SynthID 与 C2PA 首次合体","chrome-synthid-c2pa-content-credentials","2026-05-20T08:05:00+00:00",{"id":51,"title":52,"news_slug":53,"published_at":54},"e77ca785-1f1e-4b09-b28f-6723c4115e56","Chrome 动态补丁要让浏览器不重启也能打补丁：LLM 把\"漏洞太多\"逼成了架构问题","chrome-dynamic-patching-llm-vulnerability","2026-08-01T06:00:00+00:00",{"id":56,"title":57,"news_slug":58,"published_at":59},"f637e5a0-5e18-4ced-9aa4-2ce5df798a9c","Gemini 接管 Chrome 漏洞流水线:1072 个 bug、13 年陈年沙箱逃逸,LLM 重塑浏览器安全","gemini-chrome-vulnerability-pipeline","2026-07-31T10:00:00+00:00",{"id":61,"title":62,"news_slug":63,"published_at":64},"57c24a67-fa14-459d-acb2-affe62d0a08d","DeepMind 把 AI Agent 当成「内部威胁」：当 alignment 不够用时，AI Control 用网络安全思维补上缺口","deepmind-ai-control-roadmap-mitre-attack","2026-06-23T00:01:00+00:00",{"id":66,"title":67,"news_slug":68,"published_at":69},"314eb288-1ebb-4e32-825d-4eee55e78391","Google AI 眼镜上手体验：Gemini 赋能 AR 眼镜的最后一公里","google-ai-glasses-gemini-ar-last-mile","2026-05-23T01:01:00+00:00"]