Skip to content
AI.info

Generative AI

Generative Media, Editing, and Provenance

Design and evaluate image, audio, and video generation or editing systems with explicit preservation, disclosure, and provenance requirements.

By the end you can

Analogy

A restoration that invents the face, in its authors' own words

Restorers of damaged photographs fill the missing areas with period-appropriate detail. The result can look entirely authentic and still contain a face, an inscription, or an object that never existed. Generative restoration supplies plausible detail on the same principle, at machine speed, and can produce as many alternative versions as anyone asks for.

The clearest published case is a system whose own authors wrote the warning. PULSE, published in 2020, upsamples a low-resolution face by searching a StyleGAN latent space for high-resolution images that downscale correctly to the input. Read that criterion again. The search returns a face consistent with the blurred pixels. That is not the same thing as the face that produced them, and many faces satisfy it.

The authors said so themselves. They revised the paper twice, on 24 June and 20 July 2020, adding a Bias section and a model card that the first version did not have. Under the heading "Intended Use" the model card reads: “PULSE makes imaginary faces of people who do not exist, which should not be confused for real people. It will not help identify or reconstruct the original image.” The same revision reports FairFace success rates by race group, running from 79.2% for Black faces to 90.2% for Latino/Hispanic. The invention is not evenly distributed either.

Realism evaluates appearance; source fidelity evaluates whether the output preserves what the evidence supports.

Comparison

Media tasks carry different truth contracts

The same diffusion or autoregressive model may serve all of them. Their obligations still differ. The difference is not a matter of care taken by the operator; it is fixed by what the task promises.

Free generation reconstructs no scene. It owes diversity, prompt adherence, rights, and disclosure, but no fidelity to an original. Source-conditioned editing owes preservation of declared properties: masks, identity and geometry constraints, and a comparison of the regions that were supposed to stay put. Restoration and enhancement carry the heaviest contract of the three, because the detail the model supplies is precisely the detail a reader will treat as evidence. PULSE belongs in that third column. Its model card states the bound of the whole class rather than a defect of one implementation: “It will not help identify or reconstruct the original image.” A restoration pipeline that cannot say that out loud to its users has not understood which task it is running.

FigureComparison · 3 columns

Free generation

Create a new artifact from text, layout, or latent controls.

  • No original scene must be reconstructed
  • Diversity and prompt adherence matter
  • Rights and misuse still require controls
  • Disclosure depends on product context

Source-conditioned editing

Modify selected attributes while preserving declared source properties.

  • Needs masks or editable regions
  • Identity and geometry may need constraints
  • Unchanged areas require comparison
  • Edit history should remain traceable

Restoration or enhancement

Improve readability or perceived quality of degraded evidence.

  • May be expected to preserve historical content
  • Hallucinated detail is a central risk
  • Original must remain accessible
  • Uncertainty should be disclosed

Visual

A defensible editing pipeline records both intent and transformation

Media provenance requires more than a watermark placed at export, and the reason is on the record. On 20 November 2024 the National Institute of Standards and Technology published AI 100-4, an overview of technical approaches to digital content transparency. It describes what happens to a record once the file leaves your systems: “Metadata recorded within a file can similarly be stripped altogether, as it often is when files are shared (e.g., via social media platforms). Metadata may be stripped to deceive recipients of the content about its provenance or for benign reasons such as privacy protection.”

Two steps below follow directly from that sentence. The original is captured and retained because, when the attached record does not survive, the unedited source is the only remaining copy of the evidence. Provenance is published as a layer rather than as a single mark because stripping is routine. And because stripping is often innocent, a missing record cannot by itself be read as a confession.

FigureProcess · 6 steps
  1. 1

    Capture the original

    Preserve source bytes, metadata, rights, and collection context.

  2. 2

    Declare the edit contract

    Specify editable regions, protected properties, and forbidden changes.

  3. 3

    Generate candidates

    Record model, prompt, seed, controls, and intermediate assets.

  4. 4

    Validate preservation

    Compare masks, identity, geometry, text, timing, or audio characteristics.

  5. 5

    Review safety and rights

    Check consent, impersonation, copyrighted material, and sensitive content.

  6. 6

    Publish provenance

    Attach durable records of origin and transformation while retaining the unedited source.

Provenance can document a history without proving a scene is true

A signed provenance record can identify the tool, publisher, and sequence of edits associated with an asset. It can help detect missing records or unauthorized modification. It does not prove that the camera captured a truthful scene, that the editor held every necessary right, or that the described event occurred.

That is not a sceptic's complaint from outside. The standard says it first. The C2PA and Content Credentials Explainer, version 2.2, released on 22 April 2025, poses the question as its own heading — "Can provenance information be used to determine whether a digital asset, such as an image or video, depicts the truth?" — and answers it: “Provenance information can help establish the truth about the origin, history and authenticity of digital content, by providing evidence for its creation, discovery, ownership and movement over time; but provenance information alone cannot tell you whether the digital content is true, accurate or factual.” That is the Coalition for Content Provenance and Authenticity describing the limits of its own specification.

NIST AI 100-4 makes the parallel point one level down, about the signature rather than the claim it carries: “A signature cannot verify that the metadata is accurate; on a technical level, it merely serves a notarization function, indicating that the signer attested to the existence of the metadata at a given time”. A valid signature tells you who asserted what, and when. Whether the assertion is true is a separate investigation. Provenance is what makes that investigation possible, not what concludes it.

Authentic metadata can describe the origin of an inauthentic scene.

Example

Generated media fails in several distinct ways

Evaluation is worth little unless it separates these failures instead of collapsing them into one aesthetic score. One of the six already has a regulator and a date attached to it. The Federal Communications Commission adopted Declaratory Ruling FCC 24-17 on 2 February 2024 and released it on 8 February: “In this Declaratory Ruling, we confirm that the TCPA’s restrictions on the use of “artificial or prerecorded voice” encompass current AI technologies that generate human voices.” A cloned voice placed on a call therefore requires the called party's prior express consent, absent an emergency purpose or an exemption. The audio failure and the rights failure below are, in that setting, the same event seen from two directions.

  • Prompt failure: The image omits a requested object or reverses a spatial relation.
  • Preservation failure: An edit changes a person’s identity outside the intended region — the PULSE result generalized to every source-conditioned system that is judged by how good the output looks.
  • Temporal failure: Video motion creates inconsistent objects, lighting, or physical interactions.
  • Audio failure: A cloned voice preserves timbre while altering emotion, pronunciation, or speaker identity cues; since FCC 24-17 it also carries a consent duty under the Telephone Consumer Protection Act when it is used on a call.
  • Rights failure: Training, reference, or output material violates consent, license, or publicity constraints — and consent, in the Commission's formulation, is the called party's, prior and express, not the deployer's good intentions.
  • Misuse failure: The artifact enables impersonation, fraud, harassment, or fabricated evidence; the ruling above came out of a proceeding on what AI does to unwanted robocalls and robotexts, which is where that misuse arrived first.

Key idea

No single provenance signal survives every transformation

Visible labels can be cropped, metadata can be stripped, and learned watermarks degrade. The degradation has been measured rather than merely feared. Saberi and colleagues showed in 2024 that a diffusion-purification attack, with minimal visible change to the picture, drives the detection AUROC of low-perturbation image watermarks below 0.65. A model-substitution adversarial attack with an L-infinity budget of epsilon = 2/255 drives the Tree-Ring watermark's AUROC down to 0.14. That is far below chance. The detector is not merely blind; it is systematically wrong.

Their abstract states the structural result, not just the measurement: “For watermarking methods that introduce subtle image perturbations (i.e., low perturbation budget methods), we reveal a fundamental trade-off between the evasion error rate (i.e., the fraction of watermarked images detected as non-watermarked ones) and the spoofing error rate (i.e., the fraction of non-watermarked images detected as watermarked ones) upon an application of a diffusion purification attack.” The same team built spoofing attacks that make unwatermarked real images register as watermarked. That turns the false positive from an accident into an attack surface. An adversary can discredit a genuine photograph by making it look synthetic. NIST AI 100-4 puts the general form of the point on the record: any covert-watermark detector carries a nonzero probability of false positives and false negatives.

Use layered controls: provenance metadata, disclosure in the interface, retained originals, access policy, abuse monitoring, and incident response. Describe the coverage and limits of each mechanism, in the numbers above where numbers exist.

Provenance is a layered evidence system, not an indestructible mark.

Case

A statistical watermark, and a marking duty with a date on it

A watermark can be built into the sampling of a language model itself. Kirchenbauer and colleagues published the method in 2023. Before a word is generated, it selects a randomised set of “green” tokens and softly promotes their use during sampling. Detection is then a statistical test with interpretable p-values, run “using an efficient open-source algorithm without access to the language model API or parameters”.

The idea has since been deployed and its cost measured. Google DeepMind's SynthID-Text runs in Gemini and Gemini Advanced, and the production results were reported in Nature on 23 October 2024. The authors compared approximately 20 million watermarked and unwatermarked responses: “We found that the thumbs-up rate for the two models differed by 0.01% (with the watermarked model being higher); and the thumbs-down rate differed by 0.02% (with the watermarked model being lower).” Both differences were statistically insignificant. Whatever else is contested about watermarking, the claim that marking necessarily degrades the product has now been tested at production scale. It did not survive.

Regulation has moved alongside the method. Article 50(2) of the EU Artificial Intelligence Act — Regulation (EU) 2024/1689, of 13 June 2024 — requires providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content to ensure that the outputs “are marked in a machine-readable format and detectable as artificially generated or manipulated”. The European Commission's FAQ on the article asks providers for marks that are “effective, reliable, robust and interoperable machine-readable marks”. The Regulation “became applicable on 2 August 2026”. Note the gap the anchors leave open. The deployed evidence above is for text, and the attacks above show that image marks fall to methods the duty does not repeal.

Steps

Evaluate quality and fidelity separately

Build a release set that reflects both creative goals and what has to be preserved. A published one already shows the shape. HEIM, a 2023 benchmark for text-to-image models, scores them against twelve named aspects: text-image alignment, image quality, aesthetics, originality, reasoning, knowledge, bias, toxicity, fairness, robustness, multilinguality and efficiency.

Its abstract gives both the scale and the result: “We curate 62 scenarios encompassing these aspects and evaluate 26 state-of-the-art text-to-image models on this benchmark. Our results reveal that no single model excels in all aspects, with different models demonstrating different strengths.” Twelve aspects, 62 scenarios, 26 models, and no winner across the board. That is the empirical reason a single aesthetic score cannot stand in for the evaluation. It is also why step 2 below needs several rubrics rather than one. A model chosen on image quality alone is being selected without evidence on eleven other axes it was also measured against.

FigureProcess · 6 steps
  1. 1. Define the task class

    Separate generation, editing, restoration, and evidence enhancement.

  2. 2. Select human criteria

    Use rubrics for composition, coherence, identity, timing, and intended meaning.

  3. 3. Add source comparisons

    Measure changed and protected regions using task-specific features.

  4. 4. Test transformations

    Apply resizing, compression, cropping, remixing, and transcodes to provenance signals.

  5. 5. Red-team misuse

    Include impersonation, fraudulent documents, deceptive context, and evasion attempts.

  6. 6. Define disclosure

    Specify when users and downstream platforms see generation or edit history.

Media systems need an evidence policy as well as a quality model

Generated media can support design work, make products accessible, simulate scenes nobody photographed, and carry an idea to someone. The same capabilities can fabricate records or introduce unsupported detail into source-conditioned work. The four documents behind this lesson each mark one boundary of the resulting policy. PULSE's model card marks what a restoration can never be asked to prove. The C2PA Explainer 2.2 marks where provenance stops. Saberi and colleagues mark how far an image watermark degrades under attack. HEIM marks how many aspects a release decision is actually made across. Article 50(2) of the EU AI Act sets a floor under all of it from 2 August 2026, and the SynthID-Text result in Nature suggests the floor is affordable for text.

The next lesson turns to evaluation across generative applications. How good the media looks becomes one part of a broader evidence portfolio that includes task success, safety, latency, cost, and human judgment.

Key takeaways