Hi... ActivityPub co-editor here. I linked to it elsewhere in the spec, but my paper at Rebooting Web of Trust addresses some of this: https://github.com/WebOfTrustInfo/rebooting-the-web-of-trust...
Currently ActivityPub servers in practice use HTTP Signatures and Linked Data Signatures, so there's a certain amount of proof of the origin of messages there. But in moving towards a much more peer to peer system, we can do even better by stripping out SSL Certificate Authorities and DNS altogether. The paper linked above discusses one path to accomplishing that in ActivityPub using DIDs. Hope that's interesting to you!