Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Media & Provenance · Provenance/truth confusion

    Inert Media Provenance Inspector

    The lab explicitly separates structural parsing from signature, certificate, revocation, and trust-list validation.

    Quick answer

    What does the Provenance Inspector show?

    The lab explicitly separates structural parsing from signature, certificate, revocation, and trust-list validation.

    Human visibility
    Embedded or stripped provenance fields
    Machine receiver
    Structural parser and verifier
    Robustness
    Container and transformation dependent

    Research boundary: this page uses bounded, inert data and fixed safe examples. It never executes decoded content, requests secrets, calls third-party services, or performs actions against external systems.

    FIRST RUN / THREE STEPS

    Start with the prepared, bounded workflow.

    Nothing runs automatically
    1. Choose one supported file

      The file stays in PHP’s temporary upload for this request and is not retained by the application.

    2. Run Inspect provenance structure

      Inspect the selected file as inert bytes and containers. No embedded content is executed.

    3. Scan before expanding

      Read the summary first, then scan findings and expand only the machine views you need.

    INPUT / CONTROL PLANE

    Prepare the input and choose one action.

    Laboratory status: Ready

    The recommended first run is separated from alternate analyses. Inputs and selected files stay on this host.

    Current input state No file selected yet

    Choose one supported local file, then run the recommended inspection. Browsers do not repopulate file selections after a reload.

    Maximum 4 MiB. The application does not call a remote verifier or retain the file.

    Maximum file size: 4 MiB. Accepted file types: PNG, JPG, JPEG.

    ACTION HIERARCHY

    Run the recommended first pass.

    Alternate actions remain available below, but the first pass is the clearest place to start.

    Inputs remain on this host. Text operations are size-limited; uploaded files are processed from PHP’s temporary upload and are not retained by the application.

    OUTPUT / MACHINE VIEWS

    Scan the result from summary to evidence.

    Run Inspect provenance structure to create the first result.

    Choose a supported file first. The output will lead with a summary and visible qualifications before the expandable machine views.

    SummaryFindingsMachine views
    Interpretation framework

    The same artifact can produce several valid observations.

    01

    Human view

    What a person naturally reads, sees, or hears.

    02

    Structural view

    What a parser, DOM, container reader, or metadata extractor exposes.

    03

    Decoder view

    What becomes meaningful only with a rule, key, tokenizer, model, or tool.

    04

    Defensive view

    What normalization, rendering, OCR, canonicalization, or policy changes.

    Evidence and decision boundary

    Use the result as bounded evidence, not as a universal verdict.

    The lab explicitly separates structural parsing from signature, certificate, revocation, and trust-list validation.

    LOCAL MODEImage metadata and provenance-token structural scan
    REVIEW DATE2026-08-26
    SOURCE BODYPreserved separately from implementation claims
    Computed locally

    Deterministic output produced by this bounded runtime.

    • Exact outer digest, supported image dimensions, PNG/JPEG structural metadata, and occurrences of selected provenance-related byte strings
    • Whether the uploaded file contained the specific allowlisted marker tokens searched by the lab
    • A clear structural-only result with no network call
    Bounded approximation

    Useful subset or model that does not establish full conformance.

    • String occurrence is not a conforming JUMBF, CBOR, COSE, claim, assertion, or hard-binding parser
    • Absence of selected strings does not prove absence of provenance, watermarking, or sidecar credentials
    • No perceptual fingerprint or invisible watermark detector runs in the public runtime
    Escalate for

    Claims that require an exact parser, trust system, model, or human review.

    • C2PA validation requires conforming manifest parsing, hard-binding checks, signature validation, certificate-chain and trust-list policy, timestamps, and revocation handling
    • Soft-binding resolution may require authorized remote repositories and privacy review
    • Truth, context, intent, and real-world accuracy always require independent evidence
    Interpretation rule

    Record the receiver and transformation.

    Machine-decodable is receiver-relative. Record the parser, preprocessing, codebook, tokenizer, key, model, and transformation path before generalizing from one result.

    Limitations

    What this page does not prove

    A structural container scan cannot establish signature validity, signer identity, certificate status, trust-list policy, watermark presence, or truth.

    Deterministic review material

    Download the exact benign fixtures used for the evidence boundary.

    These local files are supplied for repeatable inspection. The application does not fetch them automatically, execute their content, or treat a fixture result as external verification.

    Negative provenance PNG control

    Benign PNG metadata fixture expected to contain no verified C2PA claim; useful as a negative marker-scan control.

    Type
    PNG fixture
    Bytes
    9,527
    SHA-256
    f0873af15cf4eb188bdb…
    Download fixture