PhotoProof: Cryptographic Image Authentication for Any Set of Permissible Transformations
Assa Naveh, Eran Tromer
Abstract
Since the invention of the camera, photos have been used to document reality and to supply proof of events. Yet today it is easy to fabricate realistic images depicting events that never happened. Thus, dozens of papers strive to develop methods for authenticating images. While some commercial cameras already attach digital signatures to photographs, the images often undergo subsequent transformations (cropping, rotation, compression, and so forth), which do not detract from their authenticity, but do change the image data and thus invalidate the signature. Existing methods address this by signing derived image properties that are invariant to some set of transformations. However, these are limited in the supported transformations, and often offer weak security guarantees. We present PhotoProof, a novel approach to image authentication based on cryptographic proofs. It can be configured, according to application requirements, to allow any permissible set of (efficiently computable) transformations. Starting with a signed image, our scheme attaches, to each legitimately derived image, a succinct proof of computational integrity attesting that the transformation was permissible. Anyone can verify these proofs, and generate updated proofs when applying further permissible transformations. Moreover, the proofs are zeroknowledge so that, for example, an authenticated cropped image reveals nothing about the cropped-out regions. PhotoProof is based on Proof-Carrying Data (PCD), a cryptographic primitive for secure execution of distributed computations. We describe the new construction, prove its security, and demonstrate a working prototype supporting a variety of permissible transformations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d54cd5c7-d590-4a2b-89bb-eadeee7c01b8Cited by top-tier papers17
- Doubly-Efficient zkSNARKs Without Trusted SetupRiad S. Wahby, Ioanna Tzialla, Abhi Shelat, Justin Thaler et al.S&P 2018 · 356 citations
- DIZK: A Distributed Zero Knowledge Proof SystemHoward Wu, Wenting Zheng, Alessandro Chiesa, Raluca Ada Popa et al.USENIX Security 2018 · 152 citations
- Full Accounting for Verifiable OutsourcingRiad S. Wahby, Ye Ji, Andrew J. Blumberg, Abhi Shelat et al.CCS 2017 · 78 citations
- Proof-Carrying Data Without Succinct ArgumentsBenedikt Bünz, Alessandro Chiesa, William Lin, Pratyush Mishra et al.CRYPTO 2021 · 58 citations
- Proof-Carrying Data from Arithmetized Random OraclesMegan Chen, Alessandro Chiesa, Tom Gur, Jack O'Connor et al.EUROCRYPT 2023 · 17 citations
Related papers
- VerITAS: Verifying Image Transformations at ScaleTrisha Datta, Binyi Chen, Dan BonehS&P 2025
- Trust Nobody: Privacy-Preserving Proofs for Edited Photos with Your LaptopPierpaolo Della Monica, Ivan Visconti, Andrea Vitaletti, Marco ZecchiniS&P 2025
- TruePix: Fast and Memory-Efficient Zero-Knowledge Authentication for Images and VideosLi Liu, Puwen Wei, Yunyan Zou, Zhuoran Ji et al.CCS 2026
- Eva: Efficient Privacy-Preserving Proof of Authenticity for Lossily Encoded VideosChengru Zhang, Xiao Yang, David F. Oswald, Mark Ryan et al.S&P 2025
- ProvCam: A Camera Module with Self-Contained TCB for Producing Verifiable VideosYuxin (Myles) Liu, Zhihao Yao, Mingyi Chen, Ardalan Amiri Sani et al.MobiCom 2024 · 7 citations
