Just like https certificate authorities, the only way to fight all the AI slop will be “trusted” camera firmware that signs every image with a full chain of trust that the output was a real physical video taken will a real device at a real location.
In order for this to work, the private key used for signing has to be on the camera, and would have to be kept secret from the camera’s owner. This is not possible. You can make it more difficult, use all sort of tricks to hide the key, but in the end, once somebody knows how you hide the key on their device, they’ll always be able to find it. And once they have found the key, they can sign whatever false picture they want.
Okay, I will use such a camera then to film/photographs a huge monitor showing a manipulated/ai generated video/image then, near the location of the real event. The camera will then produce a signed and trusted video with fake information.
What is your next step then? Only verified and trusted people are allowed to use cameras?
And that is in addition to that Certificates and such can’t provide authenticity, we see that again and again with signed code/programs.
In most places (for example outdoors), it would be extremely obvious that you are filming a monitor.
If you had some sort of closed box setup to minimize external light sources and produce a realistic image, then it would be pretty impractical to carry that around. And perhaps illegal (in OP’s theoretical world)
A lot of people talk about how terrible this is for privacy but personally I completely agree with OP for public videos. The leader of a country (or province/state/city/whatever) is going to give a speech?
I would like to be able to verify it’s legitimate and accurate. Because we are already seeing political AI videos of made by the opposition of a candidate saying something they didn’t actually say.
Now I actually think any videos badmouthing an opponent shouldn’t be allowed. All political videos should be on a given candidate’s platform and how that will help the people they represent, and can’t discuss the opponent at all, but that’s just not how it works right now.
I’ll also add I have no idea how that certificate chain can be validated in a way by me that the government can’t just up and change something. They control the camera. They control the root cert, I assume. They can issue new certs whenever they want. I have no way of validating the original footage was from that camera with that cert in any way that I can think of. Not to mention another poster called out any editinf software you use will need to re-sign it. But maybe there’s a way to take smaller clips from a public speech and still ensure they are signed by a given certificate the larger one was.
You don’t need certified hardware or remote attestation for things like politician speechs. Just have the production company sign the video. Now their reputation is on the line if it’s faked.
Counterpoint: this will kill all whistleblowing and investigative journalism. All sources revealed in an instant. We already had it bad with the printers.
If AI is a concern mandatory AI fingerprinting as currently implemented is better.
People can always retrain their own fingerprints free models. AI fingerprinting is only a valid strategy if you assume all AI models are Claude and ChatGPT and answer to a single legislative body to enforce it. Otherwise, there will always be massive loopholes.
This is a terrible idea. So of course it already exists https://c2pa.org/
It’s already being exploited https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html
We need a solution but that’s not it.
I assume that scheme is part of a long-term effort from Google to reinforce the idea that nobody but them should be allowed to have root on their phones, and is therefore working as intended.
That would be my guess as well.
The article criticizes software Attestation which is valid criticism but if the Attestation happened in the camera chip itself and not at OS level then even a rooted system would not be able to cheat a certificate
A rooted phone could not, but anyone with a bottle of acid and a microscope could. Or as I’ve said, a nice optics setup and a high quality projector.
My point being that trusting the camera chip does not help much. But, of course, it would block the easiest software attacks like we have seen so far.
Oh neat, i had no idea it was a thing already. What is a better idea?
C2PA on the Android platform is broken
Neat - so maybe point and click devices get to make a comeback, or the CCD itself could sign.
I’m not a researcher in this field, so I don’t have anything substantial to suggest. My opinion is that it is unsolvable.
No matter what you try, sufficiently powerful entities will be able to modify the sensor to sign images of anything they want to pass as real (or just use a very high quality projector)
It might be better that we are all always weary of an image being AI at this point.
It’s the same thing as with “watermarking” music files - it’s a bunch of hot air, anybody anywhere can just play them back and recapture the analog, and if the watermark survives that then it’s absolutely going to be audible.
That does exist
The problem us that it makes proprietary software mandatory
How quickly we forget PGP signing.
If you want to prove something is really from you, sign it with a key.
If you want to prove something isn’t AI, you can’t. You need to trust the person publishing it. And if you can trust the person publishing it, you need to trust it came from that person, which is why you signed it with your PGP key.
PGP can’t easily sign a image
Also it is rather cumbersome compared to x509 certificates
This is terrible for privacy, and can be exploited by bad actors in a multitude of ways far worse than AI slop. A better option would be the ability to load your own cryptographic key into a device and “sign” images with an open standardized protocol in such a way that you can prove you took the image with x camera, and have the option to publicly attest that it was signed by your key at the moment of creation, but the camera images can’t be cross referenced to a specific individual or camera otherwise. If someone is posting unmodified content to social media, it’s in their interests to sign and attest that authenticity. You could also give users the choice to hide everything not attested.
This is how software is signed and released by (not shit) developers currently. It’s also optional, so you can write and release code anonymously if you choose.
If someone is posting unmodified content to social media, it’s in their interests to sign and attest that authenticity.
Why is it in their interests?
Later, they may find copies of their original content, with trivial edits and others’ signatures attesting to the authenticity of “their” work, even though “they” didn’t travel to Antarctica and spend the winter to get that photo of the emperors incubating their eggs…
Can’t work
#BLOCKCHAIN #WEDDING #PHOTOGRAPHY
I think this comment was meant to be ironic, but I think you just quintupled the market value of my wedding photos, so I’m going to call that a win.
👍
If your camera can’t connect to the internet, the images on it can’t be stolen. Same for editing software.
Surely there are ways to block software from sending copies of your photographs to their servers.
Not using cloud services is probably the easiest way to keep them from stealing your images.
Most cloud services say in the terms and services that you agree for them to have ownership of your files you upload. So just don’t use cloud services.
Even though solid state hard drives have doubled in prices, you can still find the hard drive disk drives that are decent prices.
I just got a Seagate 4tb for $200. Store all your stuff on your drive. And don’t use windows. Because they steal everything you have up on your monitor. They literally take screenshots.
You can try turning off WiFi while you edit photos. Idk if that will fix it or not. Ask someone who would know if that does anything. Maybe it just sends it all once it connects. ?
OP is talking about watermarking real photos so help curate an authentic feed, not protect your media from theft. Cool pictures make the internet a better place
There are ways to poison images so they can’t be used for AI. And of course you can always add an overlay watermark in any basic graphic software that has layers and transparency settings.
There are ways to poison images so they can’t be used for AI.
They’re about as effective as ‘AI detectors’ and will last only as long as the current model generation hasn’t been counter trained on them.
It’s true they have to evolve constantly. Doesn’t mean it’s not worth trying. But yes, it has limitations.
Navigating Adobe is like walking through a minefield nowadays. Thankfully they’re nice enough to include a little AI badge that turns on when you hit an AI setting, but I’ll just be working along and accidentally hit “Denoise” rather than “Manual Denoise” and bam, AI.
I wish apps would at least give you the option to disable AI. Honestly, it should be a legal requirement like GDPR
(Before the OSS recs come in, I’m unfortunately stuck on Adobe. There’s a high chance I’ve used it anyways)




