Thursday, July 30, 2026

News

Ghost Font Hides Text From AI Using Moving Dots

ResearchPatryk Raba
Ghost Font Hides Text From AI Using Moving Dots
Fot. Vivek Yadav, Pexels (Pexels License)

Former Google product manager Eric Lu has created an experimental system called Ghost Font that hides short messages in an animation of hundreds of moving dots, readable to the human eye but hard for Claude Fable and GPT-5.6 Sol Ultra to decode.

Contents
  1. How motion-based hiding works
  2. Why AI struggles with it
  3. Limitations and criticism
  4. What it means for users and creators

Eric Lu, a former product manager at Google, has published an experimental project called Ghost Font, designed to hide short text messages from artificial intelligence systems while keeping them readable to humans. The message is formed from hundreds of moving dots in a short video animation, rather than from the conventional contrast between letters and background.

How motion-based hiding works

Users type a short message, and Ghost Font overlays it onto a field of hundreds of tiny dots displayed in an animation. The dots that make up the letters move in one direction, for example upward on the screen, while the remaining background dots move in the opposite direction. The human brain naturally groups elements that move together, so the letters become visible as a coherent pattern in motion.

Pausing the animation on a single frame makes the message disappear into visual noise. The letters are only recognizable while the dots are moving, not in a static image. An additional safeguard is a fake, motionless text embedded in the file, intended to mislead systems that try to analyze individual video frames.

Why AI struggles with it

Multimodal AI models analyze video as a sequence of separate frames, much like a flipbook made of still images, rather than as continuous motion perceived by sight. Since the letters aren't visible in any single frame, the model has nothing to extract text from, unless it's instructed to look for the specific direction in which the dots are shifting.

Eric Lu tested Ghost Font on Anthropic's Claude Fable and OpenAI's GPT-5.6 Sol Ultra. Neither model could read the hidden message until given a hint about exactly which mechanism to look for. Once prompted, the models had little trouble decoding the text, showing that the advantage over AI is temporary and depends on the model not knowing the method.

I was annoyed by how much AI was intruding into our private conversation, so I started looking for ways to communicate without having everything read by AI - Eric Lu, creator of Ghost Font

Limitations and criticism

The author himself stresses that Ghost Font is not a cure for AI-related problems and isn't meant to replace encryption or other data protection methods. The project only works for very short messages, strains the eyes when watching the animation for longer periods, and may be inaccessible to people with visual impairments.

Lu openly admits the solution could lose its effectiveness once AI models learn to analyze video using optical flow methods instead of single frames. He points to the example of the ZXX font from 2013, which at launch was considered resistant to automated reading and surveillance, but which modern AI models now handle with ease.

What it means for users and creators

Ghost Font is part of a growing wave of projects responding to the mass collection of internet data by AI companies and automated bots, done without content creators' consent. It's not the first, and likely not the last, attempt to find a gap between human perception and the way machine models interpret image and motion.

For Polish content creators and data protection companies, the project is primarily a proof of concept rather than a ready-to-deploy tool. Still, it points to a way of thinking in which differences between human and machine perception can be temporarily exploited to limit automated content scraping, before the next generation of models closes the gap.

The story of the ZXX font from over a decade ago shows that this kind of advantage has a short shelf life. Creators of similar solutions should assume that any method based on the current limitations of AI models will sooner or later be neutralized by newer versions of those systems.

Share: