P22 · CASE 0015 · POPULATED EVIDENCE RECORD
How Can We Distinguish Real Evidence from Synthetic Media?
OPENCOMPLETE_CLAIMS_SOURCES_ADVERSARIAL
No single detector, watermark or metadata field can prove that media is real. A defensible conclusion requires layered verification.
18sources
15claims
10framework dimensions
15adversarial tests
Canonical source basis:
CP1_OBSERVATORY_P22_CASE0015_SOURCE_MAP_AND_EVIDENCE_MATRIX_V0_1_20260731.xlsx
Claims
Claims retain their original research-state labels. A status is not a probability of truth.
| ID | State | Claim | Support refs |
|---|---|---|---|
| C01 | STRONG SUPPORT | No single detector, watermark or metadata field can prove that media is real. | S01–S12 |
| C02 | STRONG SUPPORT | Valid provenance can support origin and edit history without proving event truth. | S01–S03; S15–S16 |
| C03 | STRONG SUPPORT | Absence of credentials or watermark does not prove human creation. | S02–S03; S09–S12; S15–S18 |
| C04 | PROVISIONAL SUPPORT | Original assets preserve more useful evidence than screenshots and recompressed reposts. | S01–S08; S15–S16 |
| C05 | STRONG SUPPORT | Forensic detector performance is model-, dataset- and transformation-dependent. | S04–S08 |
| C06 | PROVISIONAL SUPPORT | Watermarks can provide useful generator-specific evidence. | S09–S12; S18 |
| C07 | STRONG SUPPORT | Authentic media can still be used with false context. | S04; S13–S17 |
| C08 | PROVISIONAL SUPPORT | Independent corroboration is required for consequential event claims. | S04–S08; S13 |
| C09 | STRONG SUPPORT | Multiple copies from one upload do not create independent evidence. | S01–S08 |
| C10 | PROVISIONAL SUPPORT | Disclosure and consent reduce deception and rights risks but do not verify factual claims. | S13–S18 |
| C11 | STRONG SUPPORT | Metadata is useful but editable and must be corroborated. | S01–S08; S15–S16 |
| C12 | OPEN | Positive detector agreement may not be independent. | S04–S08 |
| C13 | STRONG SUPPORT | Hybrid and partial edits complicate binary real/fake classification. | S01–S18 |
| C14 | STRONG SUPPORT | High-consequence classification requires accountable human review. | S04–S08; S13–S14 |
| C15 | OPEN | No current universal media-authenticity score is justified. | S01–S18 |
Sources · 18 serialized
| ID | Source | Research status |
|---|---|---|
| S01 | C2PA Technical Specification 2.4 | ACCEPTED TECHNICAL |
| S02 | C2PA Security Considerations 2.4 | ACCEPTED TECHNICAL |
| S03 | C2PA Explainer and FAQs | ACCEPTED CONTEXT |
| S04 | NIST — Reducing Risks Posed by Synthetic Content | ACCEPTED EVIDENCE |
| S05 | NIST Open Media Forensics Challenge | ACCEPTED EVIDENCE |
| S06 | NIST — Evaluating Analytic Systems Against AI-Generated Deepfakes | ACCEPTED EVIDENCE |
| S07 | NIST GenAI Pilot Evaluation Plan for Image Generators | ACCEPTED METHOD |
| S08 | NIST AI 600-1 — Generative AI Profile | ACCEPTED METHOD |
| S09 | Google DeepMind — SynthID | ACCEPTED DISCLOSURE |
| S10 | Google DeepMind — SynthID Detector | ACCEPTED IMPLEMENTATION |
| S11 | OpenAI — Verify OpenAI-generated images | ACCEPTED IMPLEMENTATION |
| S12 | OpenAI — Advancing content provenance | ACCEPTED DISCLOSURE |
| S13 | Partnership on AI — Responsible Practices for Synthetic Media | ACCEPTED GOVERNANCE |
| S14 | European Union AI Act — Regulation (EU) 2024/1689 | ACCEPTED LEGAL CONTEXT |
| S15 | Content Authenticity Initiative — How it works | ACCEPTED CONTEXT |
| S16 | Adobe Content Authenticity — Inspect | ACCEPTED IMPLEMENTATION |
| S17 | Meta — Labeling AI-generated content | ACCEPTED PLATFORM CONTEXT |
| S18 | Google DeepMind — AI image verification in Gemini | ACCEPTED IMPLEMENTATION |
Tests / adversarial controls · 15
| ID | Failure mode / test | State | Required control |
|---|---|---|---|
| A01 | Absence-of-label fallacy | ACTIVE | Report negative result as inconclusive. |
| A02 | Provenance-is-truth fallacy | ACTIVE | Verify the represented event independently. |
| A03 | Detector absolutism | ACTIVE | Record tool, version, threshold and uncertainty. |
| A04 | Screenshot laundering | ACTIVE | Seek earliest file and source path. |
| A05 | Metadata absolutism | ACTIVE | Corroborate metadata externally. |
| A06 | Compression confusion | ACTIVE | Use matched forensic controls. |
| A07 | False context | ACTIVE | Use temporal and geospatial verification. |
| A08 | Partial-edit concealment | ACTIVE | Use segment-level analysis and ingredient history. |
| A09 | Cross-detector pseudo-consensus | ACTIVE | Document detector dependency. |
| A10 | Source spoofing | ACTIVE | Verify publication path and signatures. |
| A11 | Credential stripping | ACTIVE | Use durable lookup or soft binding where available. |
| A12 | Watermark transfer | ACTIVE | Localize the signal and inspect ingredient structure. |
| A13 | Disclosure ambiguity | ACTIVE | Define materiality and edit scope. |
| A14 | Human reviewer laundering | ACTIVE | Specify reviewer competence and checks. |
| A15 | Model drift | ACTIVE | Version-lock and reassess regularly. |
Serialization boundary
This interface does not complete missing research by inference. The current record is COMPLETE_CLAIMS_SOURCES_ADVERSARIAL. Missing source-level or bilingual object-level fields remain absent until they are read from a canonical Observatory artifact.