imgkeya reference
Image provenance & authenticity, explained plainly.
A static reference for understanding how digital images prove where they came from — and the standards, tools, and limits behind that proof. Built for journalists, engineers, lawyers, and anyone who needs to tell what's real in an era of synthetic media.
Start here if you're new: read Why image provenance matters, then Provenance vs. authentication vs. detection. Those two pages frame everything else.
Have an image in front of you? Go to How to tell if an image is AI-generated or How to view Content Credentials. Short answers are in the FAQ.
Looking for something specific? The index below lists every page. Every page is self-contained and citable.
01
Fundamentals
6 pages- 1.1Why image provenance matters nowThe collapse of visual trust, the deepfake curve since 2023, and why detection alone cannot keep up.
- 1.2Provenance vs. authentication vs. detectionThree concepts that are routinely conflated. Each answers a different question and has different limits.
- 1.3Threat models for image manipulationWho alters images, what they want, and where each provenance approach succeeds or fails against them.
- 1.4A short history of image manipulationFrom 19th-century darkroom retouching to GAN-era synthesis. Authentication is older than photography.
- 1.5What provenance cannot proveA credential confirms a claim was made — not that the camera was pointed at what the caption says.
- 1.6GlossaryAssertion, claim, manifest, hard binding, soft binding, durable credential, JUMBF, CBOR, and more.
02
C2PA & Content Credentials
10 pages- 2.1The C2PA standard: overviewThe coalition, the spec timeline from v1.0 to v2.4, and how Content Credentials relate to the broader CAI.
- 2.2How Content Credentials work, end to endA walkthrough from capture to display: hashing, signing, embedding, transmission, and verification.
- 2.3Inside a C2PA manifestJUMBF containers, CBOR encoding, claim signatures, the manifest store, and how validators traverse them.
- 2.4Assertions and claimsThe vocabulary of provenance: actions, ingredients, training-mining flags, AI generation, and custom assertions.
- 2.5Hard bindings vs. soft bindingsCryptographic hashes break on a single bit change; watermarks and fingerprints degrade gracefully. Both matter.
- 2.6Durable Content CredentialsSurviving social-media re-encoding: how watermarks and fingerprints recover stripped manifests from a repository.
- 2.7The C2PA trust list and certificate modelX.509 chains, the official Trust List, the Interim Trust List freeze in January 2026, and what "unknown source" means.
- 2.8Adoption status: cameras, phones, AI toolsInventory of shipping implementations: Leica M11-P, Canon EOS R1, Pixel 10, Sony α-series, Firefly, OpenAI, Gemini.
- 2.9How to view and inspect Content CredentialsContent Credentials Verify, Adobe Inspect, the CR label, and c2patool — and why "no credentials found" proves nothing.
- 2.10Reading and signing manifests with c2patoolInstalling c2patool, reading manifests as JSON, trust lists, signing with a manifest definition, and common errors.
03
Watermarking & Fingerprinting
4 pages- 3.1Invisible watermarking explainedFrequency-domain embedding, spread-spectrum techniques, capacity vs. robustness, and what "invisible" actually means.
- 3.2SynthID and AI-generator watermarksGoogle's SynthID, Meta's Stable Signature, OpenAI approaches, and the EU AI Act marking requirement.
- 3.3Perceptual hashing and fingerprintingpHash, dHash, PDQ, and how Meta and Microsoft use them. The math behind "same image, different file."
- 3.4Attacks on watermarksGeometric distortion, regeneration, paraphrasing attacks, and the academic record of what survives what.
04
Detection & Forensics
7 pages- 4.1AI image detection: methods and accuracyClassifier-based detection, frequency-spectrum tells, and why benchmark numbers don't survive the wild.
- 4.2Classical image forensicsError Level Analysis, noise residuals, JPEG ghosts, CFA artifacts, lighting and shadow consistency.
- 4.3Reverse image search workflowsGoogle Lens, TinEye, Yandex, Bing — what each one indexes well, and how to chain them for verification.
- 4.4Reading image metadataEXIF, XMP, IPTC, ICC profiles, thumbnails, and the maker-note fields that betray more than photographers expect.
- 4.5Visual indicators of AI generationA current (2026) field guide to what diffusion models still get wrong, and what they have stopped getting wrong.
- 4.6EXIF, IPTC, XMP, and C2PA comparedWho maintains each, where it lives in the file, which is signed, what survives upload, and ExifTool commands to read them.
- 4.7Removing image metadata: EXIF, GPS, and C2PAStripping EXIF, GPS, and C2PA on iPhone, Android, Windows, macOS, and ExifTool — and what removing a credential costs.
05
Verification in Practice
4 pages- 5.1How to verify an image: a workflowA repeatable checklist combining provenance inspection, metadata, reverse search, and forensic indicators.
- 5.2Verification tools, comparedContent Credentials Verify, FotoForensics, InVID, ExifTool, and what each tool does and doesn't tell you.
- 5.3Newsroom verification workflowsHow AP, Reuters, BBC Verify, and Bellingcat work in practice — desks, tooling, and decision criteria.
- 5.4How to tell if an image is AI-generatedA step-by-step check: Content Credentials, SynthID, IPTC source type, reverse search, visual tells, and detector error rates.
06
Policy & Regulation
3 pages- 6.1The EU AI Act and provenanceArticle 50, the August 2026 deadline (December 2026 for existing systems), machine-readable marking, and what "deepfake" means in the text.
- 6.2US laws affecting image provenanceCalifornia SB 942, Texas SB 751, Minnesota HF 1370, and the patchwork of election and intimate-imagery statutes.
- 6.3Platform policies and metadata handlingWhat Meta, X, TikTok, YouTube, and LinkedIn do to C2PA manifests on upload — and which read or display them.
07
Use Cases
3 pages- 7.1Provenance for journalismProject Origin, BBC Verify, the Reuters and AFP pilots, and editorial workflows for credentialed news photography.
- 7.2Provenance for legal evidenceChain of custody, Federal Rules of Evidence 901 and 902, how C2PA fits the authentication framework, and proposed Rule 707.
- 7.3Provenance and privacyIdentity assertions, the surveillance risk of always-on signing, and what the C2PA spec deliberately leaves out.
08
Reference
3 pages- 8.1Specifications indexDirect links to primary documents: C2PA spec versions, JPEG Trust (ISO/IEC 21617), IPTC standards, JUMBF (ISO/IEC 19566-5).
- 8.2Further readingA curated bibliography: papers, books, court opinions, and reporting that shaped the current landscape.
- 8.3Image provenance FAQTwenty short answers: C2PA, the CR icon, SynthID, metadata stripping, platform handling, and whether detectors can be trusted.