Ok, so that's tongue in cheek and we'd see some artifacts there but the general principle works. You could intercept the signal from the CCD, or just extract the signing key from the camera's ROM, etc etc.
That's an entirely different, and much easier problem. In the case of SSL you are not worried about an attacker obtaining a certificate for any host, just the ones you care about. E.g. an attacker getting a certificate for facebook.com would be catastrophic, but an attacker getting a certificate for a website that no one uses would be a non-issue.
For the case of avoiding deepfakes, you need to avoid the attacker extracting a key from any of the millions of cameras that are sold every year.
It shouldn't be easy to extract it and that's it. It's even less difficult than keeping the DVD/Blueray keys secure because each device has a separate key, so if a line of devices gets compromised easily it's easy to spot.
Then you put a legal framework around what can be presented by media, the requirement for signature collection and so. And one of problems with photo/video authenticity is essentially solved.
I think there is scope for a simple self regulation here to start us off. I would love to see Reuters or the BBC start to publish their raw footage with the hashes. It is a question of starting the ball rolling
It doesn't really seem likely at all to work in practice.
[0] https://lilianweng.github.io/lil-log/2021/07/11/diffusion-mo...
Any scheme like this would be eventually broken somehow, so it's altogether a bad idea imho
[0] Normally you accomplish this by taking several photos and combining them
Like I said, I don't think it's practical...
A. Writing my own software "camera" that does the same gyrations a real camera would do to sign its raw image, but applied to an arbitrary unverified image file on my computer?
or
B. Printing out an unverified picture and taking a picture of that picture (with good lighting etc so that it is not obvious), with a camera that makes it verified "real"?
B. seems like it would work.
1) Upload image with web-based user dashboard.
2) We strip existing metadata (for privacy and all of the reasons everyone else does).
3) Our API generates a unique identifier for the asset (UUIDv4 in hex).
4) The unique identifier is embedded in the image with XMP.
5) A SHA256 checksum of the entire file is generated.
6) Via the API the checksum is associated with the unique identifier (along with some other stuff).
7) (Optionally) the unique identifier and checksum are added as JSON to IPFS via a pinning service and (essentially) an NFT is minted for the JSON verification data on the Polygon blockchain.
8) The user gets sharable[1] and iframe embeddable[2] links and the ability to post directly to various social media networks, etc.
When the links are viewed our Javascript reads the unique id, fetches the stored checksum from the API, and generates a new checksum of the image in the browser. If the checksums match a clickable icon appears in the top right of the image with additional information about the image, links to the IPFS and blockchain links, etc. Users can change the additional metadata at anytime and it updates instantly.
Long term goals are hosted javascript verification library, browser extensions, mobile SDKs, potential browser/OS integrations, native plugins for popular authoring/editing applications, and so on.
Happy to answer any questions!
[1] https://share.tovera.com/preview/c65b0658ab6e4d89963b1e0a319...
[2] https://share.tovera.com/embed/c65b0658ab6e4d89963b1e0a319a1...
Then if there is an adversarial model built for that, we will just create a model to detect images that have been changed to hide the model they were built with.
Then we will build a model for the adversarial AI on top of that and so on.
Considering that training a model costs thousands of dollars, and that people reuse models instead of training from scratch, I somewhat disagree with this in general, for now.
But this specific technique implies the attacker sees the result, which means they can try different models, until one does not produce artifacts.