验证数字媒体来源的可信度:为何 C2PA 规范不足
密码学与安全
2026-04-29 v1
摘要
生成式 AI 的迅猛崛起使得大规模制造逼真的假媒体变得容易。作为回应,工业联盟开发了内容来源与真实性联盟(C2PA),旨在为数字内容提供可验证的来源。我们研究团队对 C2PA 进行了首次全面、独立的安全分析。我们的研究包括对 C2PA 核心协议的首次形式化方法分析。我们发现当前的 C2PA 规范未能实现其声称的安全目标。此外,它们也未能实现所有此类来源系统所需的关键附加目标。结果是,C2PA 如若被错误地依赖,可能误导用户、平台和政策制定者。C2PA 是一个有前景的想法,但尚不应用于金融披露、新闻或法律证据等高风险场景。
引用
@article{arxiv.2604.24890,
title = {Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short},
author = {Enis Golaszewski and Neal Krawetz and Alan T. Sherman and Edward Zieglar and Sai K. Matukumalli and Roberto Yus and Carson L. Kegley and Michael Barthel and William Bowman and Bharg Barot and Kaur Kullman},
journal= {arXiv preprint arXiv:2604.24890},
year = {2026}
}
备注
This short non-technical whitepaper summarizes the findings and recommendations from our detailed technical study