Authenticated Contradictions from Desynchronized Provenance and Watermarking

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Nemecek, Alexander, He, Hengzhi, Cheng, Guang, Ayday, Erman
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917416856977408
author Nemecek, Alexander
He, Hengzhi
Cheng, Guang
Ayday, Erman
author_facet Nemecek, Alexander
He, Hengzhi
Cheng, Guang
Ayday, Erman
contents Cryptographic provenance standards such as C2PA and invisible watermarking are positioned as complementary defenses for content authentication, yet the two verification layers are technically independent: neither conditions on the output of the other. This work formalizes and empirically demonstrates the $\textit{Integrity Clash}$, a condition in which a digital asset carries a cryptographically valid C2PA manifest asserting human authorship while its pixels simultaneously carry a watermark identifying it as AI-generated, with both signals passing their respective verification checks in isolation. We construct metadata washing workflows that produce these authenticated fakes through standard editing pipelines, requiring no cryptographic compromise, only the semantic omission of a single assertion field permitted by the current C2PA specification. To close this gap, we propose a cross-layer audit protocol that jointly evaluates provenance metadata and watermark detection status, achieving 100% classification accuracy across 3,500 test images spanning four conflict-matrix states and three realistic perturbation conditions. Our results demonstrate that the gap between these verification layers is unnecessary and technically straightforward to close.
format Preprint
id arxiv_https___arxiv_org_abs_2603_02378
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Authenticated Contradictions from Desynchronized Provenance and Watermarking
Nemecek, Alexander
He, Hengzhi
Cheng, Guang
Ayday, Erman
Cryptography and Security
Computer Vision and Pattern Recognition
Multimedia
Image and Video Processing
Cryptographic provenance standards such as C2PA and invisible watermarking are positioned as complementary defenses for content authentication, yet the two verification layers are technically independent: neither conditions on the output of the other. This work formalizes and empirically demonstrates the $\textit{Integrity Clash}$, a condition in which a digital asset carries a cryptographically valid C2PA manifest asserting human authorship while its pixels simultaneously carry a watermark identifying it as AI-generated, with both signals passing their respective verification checks in isolation. We construct metadata washing workflows that produce these authenticated fakes through standard editing pipelines, requiring no cryptographic compromise, only the semantic omission of a single assertion field permitted by the current C2PA specification. To close this gap, we propose a cross-layer audit protocol that jointly evaluates provenance metadata and watermark detection status, achieving 100% classification accuracy across 3,500 test images spanning four conflict-matrix states and three realistic perturbation conditions. Our results demonstrate that the gap between these verification layers is unnecessary and technically straightforward to close.
title Authenticated Contradictions from Desynchronized Provenance and Watermarking
topic Cryptography and Security
Computer Vision and Pattern Recognition
Multimedia
Image and Video Processing
url https://arxiv.org/abs/2603.02378