Rendered at 19:38:52 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jamienk 22 hours ago [-]
Hasn't this crossed over into being a philosophical question? You want to attest to reality or provenance. But then you start making lists of "acceptable" changes: file format; compression; color-correction; size; taking "medium" into account... It then slowly slides into "average human perceptibility"; "irrelevant details"; keeping the "spirit" of the image intact; judging the intention or motive of the user or of the viewer; aligning the image with "values"; appropriate/legal use... etc. Not sure what the end-game is?
We are trying to make images in the AI era be as reliable as they were pre-AI? But they were not reliable pre-AI, it was just more difficult to intentionally doctor them.
afavour 17 hours ago [-]
I feel like we were already in a weird gray area. Cellphone cameras use all kinds of programmatic tricks to make their output better than the exact information the lens captures. I think people just didn’t realize how much their phones were doing. Is that “fake”?
imagetic 3 hours ago [-]
Yes.
goodmythical 5 hours ago [-]
Any capturing device is only every going to offer a symbol of the light that traversed it's aperture.
Even a camera obscura with a strip of film inside contains some adjustment to the "actual" image. If I expose the film for longer/shorter or during differing weather conditions, or near a train, etc, the developed film is going to have an appearance that may tinge the viewers perception of the subject. A short exposure, slightly off tilt, during a partially cloudy day, and a 'proper' exposure, rightly aligned, during full sun at noon, both of the same subject, both taken as soon as the photographer could to meet the deadline, both published on the front page of a newpaper, will give readers wildly different tastes for the subject.
Even two different b/w films will have different brightness/contrast etc, and the color films vary even more, with some punching various red/blue/green levels.
That's all without necessary deliberate intervention of the photographer. Once you get in to artistic license, you've got an even wider range. Taken from a low angle to add gravitas, taken from a high angle to minimize chin and highlight chest, with special lights to deepen shadows, with/without normal/stage makeup to add anything from regality to poverty. Taken in one's very nicest clothing, with family that is never around, while everyone has a congenial expression. (Aww, look at this lovely family)(look at the grand barren desert monument off in the wild dunes that is clearly not littered with tourists and a short walk from downtown cairo) This is easily noticeable if you've seen both a wedding and it's final professional photos. The lights didn't look like that. Where'd the audience around their first dance go? Holy shit, she looked good, but not that good.
Many have often taken photography as if it offers a genuine view of a thing at a time. We even sometimes call historical representations "snapshots". But it's never been the case.
Not sure I'd really call any photo a fake per se, they're all just representations. I suppose the fakeness comes from outside the image: the framing. If one edits a picture of a park and says "come to Always Sunny Perfect Awesomeville Where it Never Rains and is Always Full of Butterflies", then one has lied as it definitely rains there and there's certainly not always butterflies. One producing a deepfake is doing the same: capturing something they'd like captured. If it is represented as a photograph, then, sure, there's a lie; there was no photograph. But both the image with the clothes on (with lighting, editting, and makeup) and without are the same "here's what I thought it should look like" rather than "here's an exact transcript of the actual arrangement of this particular band of the electromagnetic spectrum that would have met my eye at the time"
jamienk 2 hours ago [-]
This is so good. I think this is what Hegel meant by the "absolute" - not some final God's-eye view that he's often caricatured for, but the fact that every objective "substance" is and will always be wrought by "subject", by a POV, a mediation, a representation.
another-dave 21 hours ago [-]
I think for photojournalism it should be original raw image, as captured in camera — zero edits for colour correction/cropping/filesize etc — platforms can link a digital sig from a postprocessed version but you keep the provenance proof tied to a published original.
goodmythical 5 hours ago [-]
Are they allowed flash? What about studio lighting? What about commentary? Paid actors?
"Hey, do me a favor, wear this hoodie and go hand this plastic baggie with white powder in it to that guy over there, it's for an art project, he's going to act like he doesn't know you, and then you just run in the opposite direction to where you'll be payed"
Or "here's three photos of XYZ taken on three seperate days at his new favorite coffee shop, notably across from this elementary school. Read on for our take on why he likes this shop so much!"
Or even something as simple as positioning the camera just so that one national head appears shorter than another. Or, in an interview, adjusting lights on the 'hero' to make them look good and highlight the shadows on the 'villain' to make them look ominous.
Use a mirror set up to make it look to the 'villain' that they are making eye contact but are instead looking weirdly askance.
Limitations are the origin of creativity. Force publishing RAW would just force journalists to be more creative in their framing.
Also, no edits for filesize? Lossless RAWs are huge! Especially from professional cameras. You could end up loading a gig of data for a single article with 10 images, or even more for larger frames. The few who care enough to see the 'real' image (that is still tainted by photographer intent regardless of file size and editting) are motivated enough to click the lossy jpg for the raw. Those who do not care aren't going to sit waiting on the order of minutes to see the first image.
jamienk 2 hours ago [-]
Or what about: the photographer tries to hide so that they don't contaminate the real-life that they are watching, but then the person sort of hears a small sound from the photographer's direction -- they don't actually SEE the photographer, but they get interrupted.
Or: the CCTV is well hidden, but the people who installed it left behind some mud that got on someone's shoes and that made them late...
Gigachad 17 hours ago [-]
That's pretty much how the Apple one works. The raw sensor data is signed. But you have to process it because raw sensor data is unviewable.
Provide the raw original, and the exact processing steps used to get the presentable one.
112233 8 hours ago [-]
ok, point camera at a screen. let's counter that by also taking 360° image with secondary camera. Ok build some props, let's add gps into it. fake gps. let's add inertial tracking and self-destruct on tamper.
Ok, but we really need a fake image, here is our badge, give us signing keys for special use case...
You cannot replace honesty with tech.
iririririr 19 hours ago [-]
no no no you need to buy a new phone!
/s
pixelsort 14 hours ago [-]
If this ever became widespread, people would game the "verified real" checkmark using the analog gap.
1. Print AI photo
2. Point fancy expensive camera at printed photo
3. Take a "real" photo
Then you'd see more sensors and even more expensive cameras. Then you'd see miniatured virtual-production volumes.
So, this is not a solution. It's just an arms race disguised as one.
augunrik 14 hours ago [-]
Can you photograph a photo so it’s not really noticeable?
dexen 8 hours ago [-]
Yes to arbitrarily good degree with hobby grade tooling. The previous gen photo tech (b&w negative film, colour negative film) used device called enlarger† which is pretty much taking a photo of a photo.
I've been able to get some truly great digital copy of old analog printed photo using Google snapseed and a sub 1k€ smartphone and that was almost a decade ago, so I'm pretty sure anyone dedicated can.
ImHereToVote 14 hours ago [-]
This would make deepfakes more expensive because you would have to tightly control the chroma and illuminance of the display.
tacomagick 7 hours ago [-]
Something a calibration tool surely can do I assume.
AmazingEveryDay 20 hours ago [-]
I'm trying to think of recent real-world examples where the reality of the photo was of major importance. Photographs just don't seem to have the same significance, even as potential verification of their realness becomes more achievable.
Gigachad 17 hours ago [-]
An everyday scenario is Real estate photography and Facebook marketplace where people are having a field day AI faking photos.
Having a tick showing the photo is verified real would add a lot of trust to online platforms.
tosapple 16 hours ago [-]
[dead]
rerdavies 10 hours ago [-]
Entering photos as evidence in a legal proceeding is currently bizarrely complex. You actually have to admit an expert witness to testify that the software used to process a photograph will not introduce artifacts. Even if you are simply zooming in or cropping an image.
fwip 7 hours ago [-]
Makes sense - there's lots of ways to do it wrong. If you crop a jpeg and re-save it as a jpeg, you'll introduce artifacts.
avianlyric 13 hours ago [-]
There’s been a few, but it’s becoming so common people have stopped noticing, but here’s a few recent ones:
There’s now even a wiki article on the usage of AI generated images in American politics, mostly dealing with the obvious slop that Trump has produced, rather than insidious edits of real images
Zero-knowledge seems completely unnecessary. Surely the original image does not have any material content in it that is not made public by publishing a JPEG-compressed version.
Could this be simpler and more efficient without ZK?
progbits 5 hours ago [-]
It would be interesting if it could be made to work with arbitrary transform, such as redaction.
Imagine a photo with some blacked out rectangles, and a ZK proof that confirms it comes from an attested "real" photo + adding those rectangles, but no other modification.
sisuo30390 4 hours ago [-]
[flagged]
mvid 22 hours ago [-]
Tie this into the Apple/Android/Sony/Leica signed photos, and you get provenance from capture to publish
Retr0id 23 hours ago [-]
Interesting work.
> our tool can verify a large family of image transformations
Is this family large enough to transform real image A into arbitrary fake image B?
> ZK-JPEG can merge transparent or translucent layers into an image, useful for placing visual watermarks,
creating double exposures, or merging visual layers, potentially AI generated over portions of the image. In
our tool, the transparent layer is revealed, but anything beneath an opaque portion of the layer becomes
secret. Note that in the case of an AI generated layer, the layer itself is revealed, minimizing the dishonesty
in using generative AI (but not minimizing the dishonesty of stealing artwork to train the AI)
Seems like the answer to my question is "yes", so you have to carefully inspect the transformations to see if they look legit. (The parenthetical was a surprising inclusion in an academic context)
bawolff 21 hours ago [-]
Presumably in a real application there would be a list of acceptable operations.
Like first you have to show you can do everything necessary in the system which is what this paper does. Step 2 is coming up with a policy of what restrictions to place on allowed transformations
gblargg 22 hours ago [-]
Viewers could provide a way to see the original before transforms, and perhaps apply each one at a time to see how the end result is arrived at.
Retr0id 22 hours ago [-]
If you're preserving the original, then you don't need the ZKP. Part of the appeal of this approach is that you could apply redactions or make the file smaller, without invalidating the signature.
We are trying to make images in the AI era be as reliable as they were pre-AI? But they were not reliable pre-AI, it was just more difficult to intentionally doctor them.
Even a camera obscura with a strip of film inside contains some adjustment to the "actual" image. If I expose the film for longer/shorter or during differing weather conditions, or near a train, etc, the developed film is going to have an appearance that may tinge the viewers perception of the subject. A short exposure, slightly off tilt, during a partially cloudy day, and a 'proper' exposure, rightly aligned, during full sun at noon, both of the same subject, both taken as soon as the photographer could to meet the deadline, both published on the front page of a newpaper, will give readers wildly different tastes for the subject.
Even two different b/w films will have different brightness/contrast etc, and the color films vary even more, with some punching various red/blue/green levels.
That's all without necessary deliberate intervention of the photographer. Once you get in to artistic license, you've got an even wider range. Taken from a low angle to add gravitas, taken from a high angle to minimize chin and highlight chest, with special lights to deepen shadows, with/without normal/stage makeup to add anything from regality to poverty. Taken in one's very nicest clothing, with family that is never around, while everyone has a congenial expression. (Aww, look at this lovely family)(look at the grand barren desert monument off in the wild dunes that is clearly not littered with tourists and a short walk from downtown cairo) This is easily noticeable if you've seen both a wedding and it's final professional photos. The lights didn't look like that. Where'd the audience around their first dance go? Holy shit, she looked good, but not that good.
Many have often taken photography as if it offers a genuine view of a thing at a time. We even sometimes call historical representations "snapshots". But it's never been the case.
Not sure I'd really call any photo a fake per se, they're all just representations. I suppose the fakeness comes from outside the image: the framing. If one edits a picture of a park and says "come to Always Sunny Perfect Awesomeville Where it Never Rains and is Always Full of Butterflies", then one has lied as it definitely rains there and there's certainly not always butterflies. One producing a deepfake is doing the same: capturing something they'd like captured. If it is represented as a photograph, then, sure, there's a lie; there was no photograph. But both the image with the clothes on (with lighting, editting, and makeup) and without are the same "here's what I thought it should look like" rather than "here's an exact transcript of the actual arrangement of this particular band of the electromagnetic spectrum that would have met my eye at the time"
"Hey, do me a favor, wear this hoodie and go hand this plastic baggie with white powder in it to that guy over there, it's for an art project, he's going to act like he doesn't know you, and then you just run in the opposite direction to where you'll be payed"
Or "here's three photos of XYZ taken on three seperate days at his new favorite coffee shop, notably across from this elementary school. Read on for our take on why he likes this shop so much!"
Or even something as simple as positioning the camera just so that one national head appears shorter than another. Or, in an interview, adjusting lights on the 'hero' to make them look good and highlight the shadows on the 'villain' to make them look ominous.
Use a mirror set up to make it look to the 'villain' that they are making eye contact but are instead looking weirdly askance.
Limitations are the origin of creativity. Force publishing RAW would just force journalists to be more creative in their framing.
Also, no edits for filesize? Lossless RAWs are huge! Especially from professional cameras. You could end up loading a gig of data for a single article with 10 images, or even more for larger frames. The few who care enough to see the 'real' image (that is still tainted by photographer intent regardless of file size and editting) are motivated enough to click the lossy jpg for the raw. Those who do not care aren't going to sit waiting on the order of minutes to see the first image.
Or: the CCTV is well hidden, but the people who installed it left behind some mud that got on someone's shoes and that made them late...
Provide the raw original, and the exact processing steps used to get the presentable one.
You cannot replace honesty with tech.
/s
1. Print AI photo 2. Point fancy expensive camera at printed photo 3. Take a "real" photo
Then you'd see more sensors and even more expensive cameras. Then you'd see miniatured virtual-production volumes.
So, this is not a solution. It's just an arms race disguised as one.
† https://en.wikipedia.org/wiki/Enlarger
Having a tick showing the photo is verified real would add a lot of trust to online platforms.
https://www.bbc.co.uk/news/live/ce9yydgmzdvt?post=asset%3Aae...
https://www.france24.com/en/middle-east/20260417-press-assoc...
There’s now even a wiki article on the usage of AI generated images in American politics, mostly dealing with the obvious slop that Trump has produced, rather than insidious edits of real images
https://en.wikipedia.org/wiki/AI-generated_content_in_Americ...
Could this be simpler and more efficient without ZK?
Imagine a photo with some blacked out rectangles, and a ZK proof that confirms it comes from an attested "real" photo + adding those rectangles, but no other modification.
> our tool can verify a large family of image transformations
Is this family large enough to transform real image A into arbitrary fake image B?
> ZK-JPEG can merge transparent or translucent layers into an image, useful for placing visual watermarks, creating double exposures, or merging visual layers, potentially AI generated over portions of the image. In our tool, the transparent layer is revealed, but anything beneath an opaque portion of the layer becomes secret. Note that in the case of an AI generated layer, the layer itself is revealed, minimizing the dishonesty in using generative AI (but not minimizing the dishonesty of stealing artwork to train the AI)
Seems like the answer to my question is "yes", so you have to carefully inspect the transformations to see if they look legit. (The parenthetical was a surprising inclusion in an academic context)
Like first you have to show you can do everything necessary in the system which is what this paper does. Step 2 is coming up with a policy of what restrictions to place on allowed transformations