幽灵字体
一种反AI字体,人类可以阅读,但主流AI模型却无法识别。在下方输入你的文字,然后下载并分享包含你信息的视频片段。
什么是幽灵字体?
幽灵字体是一种利用运动来书写信息的反AI字体。它结合了运动、视频、噪点和干扰元素,是一种与其他真实人类分享信息的独特方式。严格来说,它在技术上并非传统意义上的TTF字体文件。但幽灵字体是一次实验,旨在探索一种AI难以轻易理解的图形化文字交流格式。虽然它不如普通文字那样清晰易读,但人眼仍能立刻辨认出字母,而即使是主流AI模型也难以轻易破译。
视频 · 前往原文观看将使用幽灵字体生成的视频传递给像Claude Fable和GPT Sol 5.6 Ultra这样的主流AI模型。即使是这些具备编程能力的最新智能体,在未被提示具体查找技巧之前,也难以解码这段动态信息。


上面的演示区只是这个概念的一个原型。输入几个单词,字母就会显现出来,但这只是因为点的运动对人眼来说是可见的。
当视频暂停时,静态的点会融合在一起,仅凭查看单帧图像无法判断其中嵌入了什么信息。这意味着截取页面截图也无法揭示信息内容。
这个实验在本地运行——输入信息并实时预览,或下载视频进行分享和自行测试。数据不会共享或发送到任何服务器。
关于本项目
2013 年,设计师 Sang Mun 发布了一款名为 ZXX 的字体。这是一种包含四种字形的字体,设计初衷是让人类可读,但光学字符识别(OCR)软件无法识别。字母被噪声伪装、划掉,并埋藏在虚假标记之下。当时,这种字体被视为"防监控"字体——但快进到今天,现代 AI 智能体可以轻松读取用 ZXX 渲染的文字。

虽然这在 2013 年可能能击败 OCR 软件,但现代 AI 模型可以相当轻松地读取 ZXX 中的文字。我将这张图片复制到即时模式下的 ChatGPT 5.5 中,它仅通过一次提示词就能识别出文字,包括一些细微细节:

然而,对 Ghost Font 进行同样的处理就不会那么顺利了。Ghost Font 的单张截图只会生成一张完全静态的图像,没有任何可读文字。这是因为 Ghost Font 中的每个字母都由看起来与背景完全相同的点组成,因此视频中的任何单帧图像都不会透露任何关于信息的内容:

经过 19 分钟的分析,ChatGPT 5.5 Pro 产生了一段并不存在的模型幻觉信息。
然而,仅仅将信息隐藏在视频中并非完美解决方案。虽然在线模型环境可能无法从单帧中获取信息,但拥有本地代码执行环境的专用智能体仍然可以分析点的运动并解码信息。Ghost Font 通过另一种分层方式解决了这个问题:每次视频生成中都包含一条诱饵信息。
诱饵信息是对决心坚定的智能体的最后一道陷阱。当寻找隐藏信息时,它可能会先找到诱饵信息,并认为那就是视频中真正嵌入的信息。这就是 Ghost Font 能够将信息隐藏起来,甚至骗过 Fable 和 GPT Sol 5.6 Ultra 等最强推理模型的原因。
归根结底,真正隐藏信息的方法是使用加密或某种密钥。任何 AI 都无法读取需要只有人类才知道的特定密码才能解锁的消息。然而,这个项目探索的是,是否有可能创建一个包含视觉信息的可共享文件,而 AI 模型却难以轻易读取。
我们创建这个实验,是为了探索 AI 感知的极限,同时保留一些人类独有的东西。随着 AI 接管字体生成,我们希望人类能够继续拥有独特的创意声音。
下一步是什么?
我认为“幽灵字体”有一些值得继续探索的有趣应用。例如,将“幽灵字体”整合到验证码系统中会很有意思,因为目前大多数验证码系统都能被 AI 轻松破解。在视频中使用动态效果,可以让自动化的机器人更难解读,但对人类来说仍然相对容易阅读。
在视觉感知方面,“幽灵字体”也可能是一种衡量 AI 进展的有趣方式。目前,多模态模型是基于图像的,即使输入视频,它们通常也会将视频拆分成帧并逐帧分析。在不久的将来,我猜想会出现原生视频模型,能够直接读取其中的文字。
最后一个教训是,AI 确实变得非常强大了。虽然“幽灵字体”对 AI 来说难以阅读,但对人类来说也相当难读!差距正在不断缩小。看看未来 AI 感知和多模态模型会带来什么,将会非常有趣。
作为下一步,我计划将视频生成的代码作为开源项目发布——敬请期待!我也希望扩大规模,处理更长的文本字符串。希望你喜欢这个实验,我很乐意听到你的想法。你可以在 X 平台通过 @ericlu 找到我。
- Eric
Ghost Font
An anti-AI font that can be read by humans but not leading AI models. Type your text below, then download and share the video clip containing your message.
What is Ghost Font?
Ghost Font is an anti-AI font that writes a message using motion. Using a combination of motion, video, noise, and decoys, it's a unique way to share a message with other real humans. I suppose technically, it's not a font in the traditional sense of a TTF font file. But, Ghost Font is an experiment of a way to graphically communicate in writing in a format that AI cannot easily understand. While it's not as legible as regular text, the letters are still immediately readable to a human eye, but even leading AI models can't decipher it easily.
视频 · 前往原文观看Videos generated with Ghost Font were then passed to leading AI models like Claude Fable and GPT Sol 5.6 Ultra. Even these recent agents, with the ability to code, struggled to decode the moving message until prompted with the exact technique to look for.


The playground above is just a prototype of this concept. Type a few words and the letters appear but only because the motion of the dots is visible to a human eye.
When the video is paused, the static dots blend together, and it becomes impossible to tell just from looking at a single frame what message is embedded in the image. That means that screenshotting the page won't reveal the message.
This experiment works locally—type the message and preview it live, or download the video to share and test it out yourself. The data is not shared or sent to any server.
About this project
In 2013, designer Sang Mun released a font called ZXX. It was a typeface with four fonts designed to be readable by humans but not by optical character recognition (OCR) software. The letters were camouflaged with noise, crossed out, and buried under false marks. At the time, this font was deemed "surveillance-proof"—but fast forward to today, and modern AI agents can easily read text rendered in ZXX.

While this might have defeated OCR software in 2013, modern AI models can read the text in ZXX pretty easily. I copied this image into ChatGPT 5.5 on Instant mode, and it was still able to get the words including some small details as well in a single prompt:

However, the same process with Ghost Font won't work quite as easily. A single screenshot of Ghost Font will yield just a completely static image with no readable text. That's because every letter in Ghost Font is made up of dots that look exactly like the background, so any single image from the video will not reveal anything about the message:

After a 19-minute analysis, ChatGPT 5.5 Pro hallucinated a message that doesn't exist.
However, simply hiding a message in a video isn't a perfect solution. While an online model environment might not be able to get it from individual frames, a dedicated agent that has a local code execution environment can still analyze the motion of the dots and decode the message. Ghost Font solves this in another layered way: a decoy message is included in every video generation.
The decoy message serves as a final trick for a determined agent. When looking for a hidden message, it might first find the decoy message and think that that is the real embedded message in the video. That's how Ghost Font is able to hide a message even from the strongest thinking models like Fable and GPT Sol 5.6 Ultra.
Ultimately, the way to truly hide a message is to use encryption, or some sort of key. No AI will be able to read a message that requires a specific password to unlock that only humans know. However, this project explores whether it's possible to create a shareable file containing a visual message that can't be easily read by AI models.
We created this experiment as a way to explore the limits of AI perception while also preserving something human. As AI takes over font generation, our hope is that humans will continue to have a unique creative voice.
What's next?
There are certain implications for Ghost Font that I think would be interesting to continue to explore. For example, it would be interesting to incorporate Ghost Font into CAPTCHA systems, as most systems are easily solved by AI today. Using motion in a video would be a way to make it much more difficult for an automated bot to decipher but still relatively easy for a human to read.
Ghost Font might also be an interesting way to benchmark AI progress when it comes to visual perception. Right now, multimodal models are image-based, and even when passed a video, they usually split the video into frames and analyze individual frames. In the near future, I assume there will be a video-native model that will be able to read the text directly.
A final lesson is that AI is certainly getting really good. While Ghost Font is hard for AI to read, it's also pretty hard for humans to read! The gap continues to close. It will be interesting to see what the future holds when it comes to AI perception and multimodal models.
As a next step, I plan to release the code for the video generation as an open-source project—stay tuned for that! I also hope to expand the size and handle longer text strings. I hope you enjoyed this experiment and I would love to hear your thoughts. You can find me on X at @ericlu.
- Eric