ZK-JPEG: Zero-Knowledge Image Editing and Compression
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
ZK-JPEG: Zero-Knowledge Image Editing and Compression
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Retr0id · · focus · HN ↗
> our tool can verify a large family of image transformations
Is this family large enough to transform real image A into arbitrary fake image B?
gblargg · · focus · HN ↗
Retr0id · · focus · HN ↗
bawolff · · focus · HN ↗
Like first you have to show you can do everything necessary in the system which is what this paper does. Step 2 is coming up with a policy of what restrictions to place on allowed transformations
huflungdung · · focus · HN ↗
[dead]
jamienk · · focus · HN ↗
We are trying to make images in the AI era be as reliable as they were pre-AI? But they were not reliable pre-AI, it was just more difficult to intentionally doctor them.
another-dave · · focus · HN ↗
Gigachad · · focus · HN ↗
Provide the raw original, and the exact processing steps used to get the presentable one.
112233 · · focus · HN ↗
You cannot replace honesty with tech.
goodmythical · · focus · HN ↗
"Hey, do me a favor, wear this hoodie and go hand this plastic baggie with white powder in it to that guy over there, it's for an art project, he's going to act like he doesn't know you, and then you just run in the opposite direction to where you'll be payed"
Or "here's three photos of XYZ taken on three seperate days at his new favorite coffee shop, notably across from this elementary school. Read on for our take on why he likes this shop so much!"
Or even something as simple as positioning the camera just so that one national head appears shorter than another. Or, in an interview, adjusting lights on the 'hero' to make them look good and highlight the shadows on the 'villain' to make them look ominous.
Use a mirror set up to make it look to the 'villain' that they are making eye contact but are instead looking weirdly askance.
Limitations are the origin of creativity. Force publishing RAW would just force journalists to be more creative in their framing.
Also, no edits for filesize? Lossless RAWs are huge! Especially from professional cameras. You could end up loading a gig of data for a single article with 10 images, or even more for larger frames. The few who care enough to see the 'real' image (that is still tainted by photographer intent regardless of file size and editting) are motivated enough to click the lossy jpg for the raw. Those who do not care aren't going to sit waiting on the order of minutes to see the first image.
jamienk · · focus · HN ↗
Or: the CCTV is well hidden, but the people who installed it left behind some mud that got on someone's shoes and that made them late...
another-dave · · focus · HN ↗
what exactly is the 'threat model' that you're trying to protect against here? If you already don't trust John Doe as a credible source, of course then there's a million ways he can frame a scene to tell an unreliable story. That's always been the case.
But to me, what we're looking for now in the age of diffusion models is for someone to be able to say "here is the provenance of this image, it came from John Doe's camera" and that can survive being shared round the internet, provably.
> You could end up loading a gig of data for a single article with 10 images, or even more for larger frames.
I'm not suggesting that the _only_ thing that gets used is a raw image. I'm saying that if you go to the Wall Street Journal, then underneath the photo, beside the credit, they put a link out to some page that hosts the RAW file, the metadata of the camera used and a signature.
If you find the photo unbelievable and think it's bogus, you're able to regenerate the signature from the parts and see that it's valid. (and obviously if they link off to something that's massively different - that isn't just compression, white balance, etc - people hold them to account)
iririririr · · focus · HN ↗
/s
afavour · · focus · HN ↗
goodmythical · · focus · HN ↗
Even a camera obscura with a strip of film inside contains some adjustment to the "actual" image. If I expose the film for longer/shorter or during differing weather conditions, or near a train, etc, the developed film is going to have an appearance that may tinge the viewers perception of the subject. A short exposure, slightly off tilt, during a partially cloudy day, and a 'proper' exposure, rightly aligned, during full sun at noon, both of the same subject, both taken as soon as the photographer could to meet the deadline, both published on the front page of a newpaper, will give readers wildly different tastes for the subject.
Even two different b/w films will have different brightness/contrast etc, and the color films vary even more, with some punching various red/blue/green levels.
That's all without necessary deliberate intervention of the photographer. Once you get in to artistic license, you've got an even wider range. Taken from a low angle to add gravitas, taken from a high angle to minimize chin and highlight chest, with special lights to deepen shadows, with/without normal/stage makeup to add anything from regality to poverty. Taken in one's very nicest clothing, with family that is never around, while everyone has a congenial expression. (Aww, look at this lovely family)(look at the grand barren desert monument off in the wild dunes that is clearly not littered with tourists and a short walk from downtown cairo) This is easily noticeable if you've seen both a wedding and it's final professional photos. The lights didn't look like that. Where'd the audience around their first dance go? Holy shit, she looked good, but not that good.
Many have often taken photography as if it offers a genuine view of a thing at a time. We even sometimes call historical representations "snapshots". But it's never been the case.
Not sure I'd really call any photo a fake per se, they're all just representations. I suppose the fakeness comes from outside the image: the framing. If one edits a picture of a park and says "come to Always Sunny Perfect Awesomeville Where it Never Rains and is Always Full of Butterflies", then one has lied as it definitely rains there and there's certainly not always butterflies. One producing a deepfake is doing the same: capturing something they'd like captured. If it is represented as a photograph, then, sure, there's a lie; there was no photograph. But both the image with the clothes on (with lighting, editting, and makeup) and without are the same "here's what I thought it should look like" rather than "here's an exact transcript of the actual arrangement of this particular band of the electromagnetic spectrum that would have met my eye at the time"
jamienk · · focus · HN ↗
imagetic · · focus · HN ↗
tough · · focus · HN ↗
mvid · · focus · HN ↗
AmazingEveryDay · · focus · HN ↗
Gigachad · · focus · HN ↗
Having a tick showing the photo is verified real would add a lot of trust to online platforms.
tosapple · · focus · HN ↗
[dead]
avianlyric · · focus · HN ↗
<a href="https://www.bbc.co.uk/news/live/ce9yydgmzdvt" rel="nofollow">https://www.bbc.co.uk/news/live/ce9yydgmzdvt
<a href="https://www.france24.com/en/middle-east/20260417-press-association-israeli-army-use-ai-doctored-image-slain-journalist" rel="nofollow">https://www.france24.com/en/middle-east/20260417-press-assoc...
There’s now even a wiki article on the usage of AI generated images in American politics, mostly dealing with the obvious slop that Trump has produced, rather than insidious edits of real images
<a href="https://en.wikipedia.org/wiki/AI-generated_content_in_American_politics" rel="nofollow">https://en.wikipedia.org/wiki/AI-generated_content_in_Americ...
rerdavies · · focus · HN ↗
fwip · · focus · HN ↗
AmazingEveryDay · · focus · HN ↗
killingtime74 · · focus · HN ↗
pixelsort · · focus · HN ↗
1. Print AI photo 2. Point fancy expensive camera at printed photo 3. Take a "real" photo
Then you'd see more sensors and even more expensive cameras. Then you'd see miniatured virtual-production volumes.
So, this is not a solution. It's just an arms race disguised as one.
augunrik · · focus · HN ↗
dexen · · focus · HN ↗
† <a href="https://en.wikipedia.org/wiki/Enlarger" rel="nofollow">https://en.wikipedia.org/wiki/Enlarger
nolok · · focus · HN ↗
ImHereToVote · · focus · HN ↗
tacomagick · · focus · HN ↗
ImHereToVote · · focus · HN ↗
WorseIsBetter · · focus · HN ↗
[dead]
j2kun · · focus · HN ↗
Could this be simpler and more efficient without ZK?
progbits · · focus · HN ↗
Imagine a photo with some blacked out rectangles, and a ZK proof that confirms it comes from an attested "real" photo + adding those rectangles, but no other modification.
sisuo30390 · · focus · HN ↗
[dead]
nullc · · focus · HN ↗
The proof must be MUCH smaller than the whole computation or even the inputs (otherwise, just provide the uncompressed image!).
And the proof has to resist forgery.
So going for succinctness and at least computational soundness gets you to zero knowledge 'for free'.