AIPWN / PROVENANCE METHODS
C2PA declarations, signatures and trust: three different checks
A provenance claim, a valid signature and a trusted signer answer different questions. Treating them as one 'AI detector' result can mislead an investigation.
01 / INTERPRET
Ask what each check actually establishes
| Check | Supported conclusion | Unsupported conclusion |
|---|---|---|
| Declaration found | The file carries a C2PA manifest or IPTC source type. | The claim is true, the signature is valid, or the image was necessarily AI-made. |
| Signature valid | Local C2PA validation finds the signature consistent with protected content. | The signer is on a trusted list, or the depicted event is real. |
| Signer trusted | Local validation recognizes a trusted root. | Every real-world claim in the content is true. |
| No declaration | These provenance fields were not found in this file. | The image is authentic, unedited, or non-AI. |
02 / WORKFLOW
How to check with AIPwn
- Select the original file in the browser-local inspector. Record absent, unreadable or present separately from Trusted, Valid, Invalid or Unknown. Image bytes stay in the browser.
- If you need a shareable digest-bound report, use the cloud image endpoint. It reads C2PA/IPTC declarations and binds the result to the file SHA-256, but does not verify signatures server-side.
- For missing claims or indeterminate signatures, retain the original file and source chain and gather independent evidence. Do not turn 'not found' into 'not AI'.
03 / EVIDENCE
Implementation evidence and limits
The cloud reader is provenance-1.0.0. Development regressions use synthetic cases for C2PA declarations in JPEG, PNG and WebP, XMP/IPTC-only declarations, no declaration and truncated files. They check parsing behavior, not real-world detection accuracy; the fixtures are not currently a public dataset. You can check signature states locally with images you have permission to use.
Metadata can be stripped. The cloud endpoint does not build a signature trust chain. Even a trusted signature cannot independently establish that the depicted event happened.
C2PA specification ↗IPTC source type definition ↗Data handling →