Rendered at 16:35:56 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jamienk 19 hours ago [-]
Hasn't this crossed over into being a philosophical question? You want to attest to reality or provenance. But then you start making lists of "acceptable" changes: file format; compression; color-correction; size; taking "medium" into account... It then slowly slides into "average human perceptibility"; "irrelevant details"; keeping the "spirit" of the image intact; judging the intention or motive of the user or of the viewer; aligning the image with "values"; appropriate/legal use... etc. Not sure what the end-game is?
We are trying to make images in the AI era be as reliable as they were pre-AI? But they were not reliable pre-AI, it was just more difficult to intentionally doctor them.
afavour 13 hours ago [-]
I feel like we were already in a weird gray area. Cellphone cameras use all kinds of programmatic tricks to make their output better than the exact information the lens captures. I think people just didn’t realize how much their phones were doing. Is that “fake”?
goodmythical 2 hours ago [-]
Any capturing device is only every going to offer a symbol of the light that traversed it's aperture.
Even a camera obscura with a strip of film inside contains some adjustment to the "actual" image. If I expose the film for longer/shorter or during differing weather conditions, or near a train, etc, the developed film is going to have an appearance that may tinge the viewers perception of the subject. A short exposure, slightly off tilt, during a partially cloudy day, and a 'proper' exposure, rightly aligned, during full sun at noon, both of the same subject, both taken as soon as the photographer could to meet the deadline, both published on the front page of a newpaper, will give readers wildly different tastes for the subject.
Even two different b/w films will have different brightness/contrast etc, and the color films vary even more, with some punching various red/blue/green levels.
That's all without necessary deliberate intervention of the photographer. Once you get in to artistic license, you've got an even wider range. Taken from a low angle to add gravitas, taken from a high angle to minimize chin and highlight chest, with special lights to deepen shadows, with/without normal/stage makeup to add anything from regality to poverty. Taken in one's very nicest clothing, with family that is never around, while everyone has a congenial expression. (Aww, look at this lovely family)(look at the grand barren desert monument off in the wild dunes that is clearly not littered with tourists and a short walk from downtown cairo) This is easily noticeable if you've seen both a wedding and it's final professional photos. The lights didn't look like that. Where'd the audience around their first dance go? Holy shit, she looked good, but not that good.
Many have often taken photography as if it offers a genuine view of a thing at a time. We even sometimes call historical representations "snapshots". But it's never been the case.
Not sure I'd really call any photo a fake per se, they're all just representations. I suppose the fakeness comes from outside the image: the framing. If one edits a picture of a park and says "come to Always Sunny Perfect Awesomeville Where it Never Rains and is Always Full of Butterflies", then one has lied as it definitely rains there and there's certainly not always butterflies. One producing a deepfake is doing the same: capturing something they'd like captured. If it is represented as a photograph, then, sure, there's a lie; there was no photograph. But both the image with the clothes on (with lighting, editting, and makeup) and without are the same "here's what I thought it should look like" rather than "here's an exact transcript of the actual arrangement of this particular band of the electromagnetic spectrum that would have met my eye at the time"
another-dave 18 hours ago [-]
I think for photojournalism it should be original raw image, as captured in camera — zero edits for colour correction/cropping/filesize etc — platforms can link a digital sig from a postprocessed version but you keep the provenance proof tied to a published original.
goodmythical 1 hours ago [-]
Are they allowed flash? What about studio lighting? What about commentary? Paid actors?
"Hey, do me a favor, wear this hoodie and go hand this plastic baggie with white powder in it to that guy over there, it's for an art project, he's going to act like he doesn't know you, and then you just run in the opposite direction to where you'll be payed"
Or "here's three photos of XYZ taken on three seperate days at his new favorite coffee shop, notably across from this elementary school. Read on for our take on why he likes this shop so much!"
Or even something as simple as positioning the camera just so that one national head appears shorter than another. Or, in an interview, adjusting lights on the 'hero' to make them look good and highlight the shadows on the 'villain' to make them look ominous.
Use a mirror set up to make it look to the 'villain' that they are making eye contact but are instead looking weirdly askance.
Limitations are the origin of creativity. Force publishing RAW would just force journalists to be more creative in their framing.
Also, no edits for filesize? Lossless RAWs are huge! Especially from professional cameras. You could end up loading a gig of data for a single article with 10 images, or even more for larger frames. The few who care enough to see the 'real' image (that is still tainted by photographer intent regardless of file size and editting) are motivated enough to click the lossy jpg for the raw. Those who do not care aren't going to sit waiting on the order of minutes to see the first image.
Gigachad 14 hours ago [-]
That's pretty much how the Apple one works. The raw sensor data is signed. But you have to process it because raw sensor data is unviewable.
Provide the raw original, and the exact processing steps used to get the presentable one.
112233 5 hours ago [-]
ok, point camera at a screen. let's counter that by also taking 360° image with secondary camera. Ok build some props, let's add gps into it. fake gps. let's add inertial tracking and self-destruct on tamper.
Ok, but we really need a fake image, here is our badge, give us signing keys for special use case...
You cannot replace honesty with tech.
iririririr 16 hours ago [-]
no no no you need to buy a new phone!
/s
pixelsort 11 hours ago [-]
If this ever became widespread, people would game the "verified real" checkmark using the analog gap.
1. Print AI photo
2. Point fancy expensive camera at printed photo
3. Take a "real" photo
Then you'd see more sensors and even more expensive cameras. Then you'd see miniatured virtual-production volumes.
So, this is not a solution. It's just an arms race disguised as one.
augunrik 11 hours ago [-]
Can you photograph a photo so it’s not really noticeable?
nolok 50 minutes ago [-]
I've been able to get some truly great digital copy of old analog printed photo using Google snapseed and a sub 1k€ smartphone and that was almost a decade ago, so I'm pretty sure anyone dedicated can.
dexen 5 hours ago [-]
Yes to arbitrarily good degree with hobby grade tooling. The previous gen photo tech (b&w negative film, colour negative film) used device called enlarger† which is pretty much taking a photo of a photo.
This would make deepfakes more expensive because you would have to tightly control the chroma and illuminance of the display.
tacomagick 4 hours ago [-]
Something a calibration tool surely can do I assume.
j2kun 2 hours ago [-]
Zero-knowledge seems completely unnecessary. Surely the original image does not have any material content in it that is not made public by publishing a JPEG-compressed version.
Could this be simpler and more efficient without ZK?
progbits 2 hours ago [-]
It would be interesting if it could be made to work with arbitrary transform, such as redaction.
Imagine a photo with some blacked out rectangles, and a ZK proof that confirms it comes from an attested "real" photo + adding those rectangles, but no other modification.
sisuo30390 1 hours ago [-]
[flagged]
AmazingEveryDay 17 hours ago [-]
I'm trying to think of recent real-world examples where the reality of the photo was of major importance. Photographs just don't seem to have the same significance, even as potential verification of their realness becomes more achievable.
Gigachad 14 hours ago [-]
An everyday scenario is Real estate photography and Facebook marketplace where people are having a field day AI faking photos.
Having a tick showing the photo is verified real would add a lot of trust to online platforms.
tosapple 13 hours ago [-]
[dead]
rerdavies 7 hours ago [-]
Entering photos as evidence in a legal proceeding is currently bizarrely complex. You actually have to admit an expert witness to testify that the software used to process a photograph will not introduce artifacts. Even if you are simply zooming in or cropping an image.
fwip 4 hours ago [-]
Makes sense - there's lots of ways to do it wrong. If you crop a jpeg and re-save it as a jpeg, you'll introduce artifacts.
avianlyric 10 hours ago [-]
There’s been a few, but it’s becoming so common people have stopped noticing, but here’s a few recent ones:
There’s now even a wiki article on the usage of AI generated images in American politics, mostly dealing with the obvious slop that Trump has produced, rather than insidious edits of real images
Tie this into the Apple/Android/Sony/Leica signed photos, and you get provenance from capture to publish
Retr0id 20 hours ago [-]
Interesting work.
> our tool can verify a large family of image transformations
Is this family large enough to transform real image A into arbitrary fake image B?
> ZK-JPEG can merge transparent or translucent layers into an image, useful for placing visual watermarks,
creating double exposures, or merging visual layers, potentially AI generated over portions of the image. In
our tool, the transparent layer is revealed, but anything beneath an opaque portion of the layer becomes
secret. Note that in the case of an AI generated layer, the layer itself is revealed, minimizing the dishonesty
in using generative AI (but not minimizing the dishonesty of stealing artwork to train the AI)
Seems like the answer to my question is "yes", so you have to carefully inspect the transformations to see if they look legit. (The parenthetical was a surprising inclusion in an academic context)
bawolff 18 hours ago [-]
Presumably in a real application there would be a list of acceptable operations.
Like first you have to show you can do everything necessary in the system which is what this paper does. Step 2 is coming up with a policy of what restrictions to place on allowed transformations
gblargg 19 hours ago [-]
Viewers could provide a way to see the original before transforms, and perhaps apply each one at a time to see how the end result is arrived at.
Retr0id 19 hours ago [-]
If you're preserving the original, then you don't need the ZKP. Part of the appeal of this approach is that you could apply redactions or make the file smaller, without invalidating the signature.
We are trying to make images in the AI era be as reliable as they were pre-AI? But they were not reliable pre-AI, it was just more difficult to intentionally doctor them.
Even a camera obscura with a strip of film inside contains some adjustment to the "actual" image. If I expose the film for longer/shorter or during differing weather conditions, or near a train, etc, the developed film is going to have an appearance that may tinge the viewers perception of the subject. A short exposure, slightly off tilt, during a partially cloudy day, and a 'proper' exposure, rightly aligned, during full sun at noon, both of the same subject, both taken as soon as the photographer could to meet the deadline, both published on the front page of a newpaper, will give readers wildly different tastes for the subject.
Even two different b/w films will have different brightness/contrast etc, and the color films vary even more, with some punching various red/blue/green levels.
That's all without necessary deliberate intervention of the photographer. Once you get in to artistic license, you've got an even wider range. Taken from a low angle to add gravitas, taken from a high angle to minimize chin and highlight chest, with special lights to deepen shadows, with/without normal/stage makeup to add anything from regality to poverty. Taken in one's very nicest clothing, with family that is never around, while everyone has a congenial expression. (Aww, look at this lovely family)(look at the grand barren desert monument off in the wild dunes that is clearly not littered with tourists and a short walk from downtown cairo) This is easily noticeable if you've seen both a wedding and it's final professional photos. The lights didn't look like that. Where'd the audience around their first dance go? Holy shit, she looked good, but not that good.
Many have often taken photography as if it offers a genuine view of a thing at a time. We even sometimes call historical representations "snapshots". But it's never been the case.
Not sure I'd really call any photo a fake per se, they're all just representations. I suppose the fakeness comes from outside the image: the framing. If one edits a picture of a park and says "come to Always Sunny Perfect Awesomeville Where it Never Rains and is Always Full of Butterflies", then one has lied as it definitely rains there and there's certainly not always butterflies. One producing a deepfake is doing the same: capturing something they'd like captured. If it is represented as a photograph, then, sure, there's a lie; there was no photograph. But both the image with the clothes on (with lighting, editting, and makeup) and without are the same "here's what I thought it should look like" rather than "here's an exact transcript of the actual arrangement of this particular band of the electromagnetic spectrum that would have met my eye at the time"
"Hey, do me a favor, wear this hoodie and go hand this plastic baggie with white powder in it to that guy over there, it's for an art project, he's going to act like he doesn't know you, and then you just run in the opposite direction to where you'll be payed"
Or "here's three photos of XYZ taken on three seperate days at his new favorite coffee shop, notably across from this elementary school. Read on for our take on why he likes this shop so much!"
Or even something as simple as positioning the camera just so that one national head appears shorter than another. Or, in an interview, adjusting lights on the 'hero' to make them look good and highlight the shadows on the 'villain' to make them look ominous.
Use a mirror set up to make it look to the 'villain' that they are making eye contact but are instead looking weirdly askance.
Limitations are the origin of creativity. Force publishing RAW would just force journalists to be more creative in their framing.
Also, no edits for filesize? Lossless RAWs are huge! Especially from professional cameras. You could end up loading a gig of data for a single article with 10 images, or even more for larger frames. The few who care enough to see the 'real' image (that is still tainted by photographer intent regardless of file size and editting) are motivated enough to click the lossy jpg for the raw. Those who do not care aren't going to sit waiting on the order of minutes to see the first image.
Provide the raw original, and the exact processing steps used to get the presentable one.
You cannot replace honesty with tech.
/s
1. Print AI photo 2. Point fancy expensive camera at printed photo 3. Take a "real" photo
Then you'd see more sensors and even more expensive cameras. Then you'd see miniatured virtual-production volumes.
So, this is not a solution. It's just an arms race disguised as one.
† https://en.wikipedia.org/wiki/Enlarger
Could this be simpler and more efficient without ZK?
Imagine a photo with some blacked out rectangles, and a ZK proof that confirms it comes from an attested "real" photo + adding those rectangles, but no other modification.
Having a tick showing the photo is verified real would add a lot of trust to online platforms.
https://www.bbc.co.uk/news/live/ce9yydgmzdvt?post=asset%3Aae...
https://www.france24.com/en/middle-east/20260417-press-assoc...
There’s now even a wiki article on the usage of AI generated images in American politics, mostly dealing with the obvious slop that Trump has produced, rather than insidious edits of real images
https://en.wikipedia.org/wiki/AI-generated_content_in_Americ...
> our tool can verify a large family of image transformations
Is this family large enough to transform real image A into arbitrary fake image B?
> ZK-JPEG can merge transparent or translucent layers into an image, useful for placing visual watermarks, creating double exposures, or merging visual layers, potentially AI generated over portions of the image. In our tool, the transparent layer is revealed, but anything beneath an opaque portion of the layer becomes secret. Note that in the case of an AI generated layer, the layer itself is revealed, minimizing the dishonesty in using generative AI (but not minimizing the dishonesty of stealing artwork to train the AI)
Seems like the answer to my question is "yes", so you have to carefully inspect the transformations to see if they look legit. (The parenthetical was a surprising inclusion in an academic context)
Like first you have to show you can do everything necessary in the system which is what this paper does. Step 2 is coming up with a policy of what restrictions to place on allowed transformations