UBIQS

Content provenance starts in the sensor

Detectors guess whether pixels look synthetic. Provenance asks who vouches for them, and the answer has to start in the sensor, with a key that cannot be copied.

Share LinkedIn X Email

Detection is an arms race, and detectors are the slow side

An AI image detector is a classifier trained on yesterday's generators, while the next generator is trained, in part, to get past it. Detection also fails in both directions: it misses new fakes, and it flags real photos, which teaches people to doubt true evidence. Even when it works, it can only offer a probability, never a record anyone can check.

The question "does this look synthetic?" has no stable answer. A better question is "who vouches for these pixels, and why should anyone believe them?"

Provenance asks a different question

Provenance starts at capture. The device signs the image at the moment it is made, and anyone can later check the signature instead of guessing from the pixels. An image with a valid signature has a known origin. An image without one is simply unverified, which is not the same as fake.

The approach is only as strong as the key behind the signature. If the signing key lives in software, it can be pulled off a phone and used to sign anything, and a signed fake is worse than an unsigned image because it carries borrowed credibility. So the real design question is where the key lives and whether it can be copied.

How a silicon identity answers "which device made this?"

Every chip carries tiny manufacturing variations that no other chip shares. UBIQS derives a device identity from that variation, so there is no stored key to extract and nothing to clone. The key exists only at the moment of signing.

At capture, the device signs a receipt that binds three things: a hash of the image data, the capture details such as time and settings, and the identity of the chip that did the signing. Anyone can check the receipt and learn which enrolled device produced the image and that the pixels have not changed since.

This closes the two gaps that sink most signing schemes. Malware that lifts a file off the phone gets no key it can reuse to sign a synthetic image somewhere else. And an image generated on a server has no enrolled chip behind it, so it cannot produce a valid receipt at all.

The closer to the sensor the signing happens, the fewer steps remain in which pixels could be swapped before they are signed. When an image is edited, the editing device signs a new receipt that points back to the original, so the history shows each hand that touched it.

How this compares with Apple's Reference Image

Apple's iPhone 18 Pro feature is not a detector. Reference Image is a provenance feature: the camera signs sensor data at capture, and Apple's cloud develops it into a verifiable reference image. It is a real step, and the first at consumer scale. Its limits are about reach and trust anchor, not intent.

Apple Reference ImageSilicon-identity provenance (UBIQS approach)
What it answersDid these pixels come from this iPhone's sensor, within a bounded time window?Which enrolled device made this image, and has it changed since?
Where trust anchorsApple's sensor, Secure Enclave and Private Cloud ComputeThe silicon identity of the capturing device
Devices coverediPhone 18 Pro and Pro MaxAny device with enrolled silicon, from any maker
Who verifiesApple's pipelineAnyone holding the receipt
StandardsNo C2PA mentioned in the coverage reviewed; SynthID is supported separatelyDesigned to carry a receipt a verifier can check independently
AvailabilityNot in China; EU users can view but not initially captureDepends on enrollment by device makers
Does not proveEdits after capture, or images from other sourcesWhether the scene itself is genuine

Apple has shipping hardware, distribution and a trusted brand, which a new approach does not. What a single-vendor feature cannot give is a record that works across phones, cameras, dashcams and sensors from different makers, and that a stranger can check without going through one company's service.

Sources: Gizmodo, Stuff.

What provenance can and cannot prove

A valid receipt proves which device signed the image and that the pixels are unchanged since. It does not prove the scene was real. A genuine camera pointed at a screen showing a fake will sign the fake, and a staged scene is still a staged scene. Provenance narrows the problem to the capture, and the capture still needs judgment.

It also does not prove that an unsigned image is fake. Most images in the world today carry no receipt, and a system that treats "unsigned" as "false" would punish every older photo. The honest result for those is "unverified."

Finally, coverage depends on adoption. A receipt only helps if devices sign, platforms preserve the receipt when images are shared, and viewers can see it. Each of those is a separate problem that no single chip can solve.

Questions to ask any content provenance system

  1. Where does the signing key live, and can it be copied off the device?
  2. Does verification depend on one vendor's cloud, and does it work for devices from other makers?
  3. What does a viewer see after an image is cropped, compressed or edited?
  4. What does the system say about an image with no signature: unknown, or fake?
  5. What does a verifier learn about the photographer, and who decides?

A system that answers all five is offering evidence. One that cannot is offering a badge.

Keep reading

Related

Working on hardware provenance you need to prove?

We're talking with teams building verifiable, component-level trust into infrastructure and devices.