In short
- Short definitions, written to be quoted.
- Each term has its own anchor for linking.
Terms
ManifestThe C2PA data structure holding assertions (what happened) and a claim signature (who says so).
Hard bindingA cryptographic hash of the image data inside the manifest. Any pixel change breaks it.
Soft bindingA watermark or fingerprint that can locate a manifest even when the manifest is gone.
PayloadHow many bits a watermark can carry. 0 bits means present or not; about 100 bits is enough for an identifier.
PSNRPeak signal-to-noise ratio, in dB. Above about 40 dB a watermark is invisible to nearly everyone.
False positive rateHow often a detector says marked on an unmarked image. Internet-scale systems target well under 1%.
Regeneration attackPassing an image through a generative autoencoder so the pixels are re-synthesised, washing out post-hoc marks.
Perceptual fingerprintA compact hash of how an image looks, robust to small edits. Not embedded; computed and stored.
Durable credentialA C2PA credential backed by soft bindings, so it can be recovered after the metadata is stripped.
Disclosure markA watermark a generator adds to say an image is AI-generated. SynthID is one. A statement about how an image was made, not who owns it.
Definitions follow the C2PA specification and the Content Authenticity Initiative's documentation where those define the term.1,2
Sources
- C2PA FAQ, Linux Foundation
- Durable Content Credentials, Content Authenticity Initiative