Stop double-counting a named forensic mark as SynthID provenance

A manifest that names its own forensic soft-binding algorithm carries
that vendor's mark; the generic watermark-action vendor-token inference
must not add a second, differently-attributed invisible watermark from
the same bytes. Microsoft Designer manifests triggered exactly that:
signed by Microsoft, watermarked by InvisMark, with the generation
agent named "Azure OpenAI ImageGen" - the OpenAI issuer token inside
that service name plus the InvisMark watermarked action satisfied the
OpenAI SynthID-evidence rule, and identify reported one forensic mark
as two paid pixel watermarks.

Three changes, one rule at every inference site (the verdict-scan
comment's own lesson: a rule that lives in only one copy is a rule the
others silently lack):

- c2pa.py structured path: SynthID evidence now scopes to the
  signer/generator identity strings only (signature issuer, claim
  generator), never the raw chain, and is suppressed entirely when a
  soft-binding algorithm is named.
- c2pa.py byte fallback and metadata.py synthid_source: suppressed when
  the scan names a soft-binding algorithm.
- identify.py verdict scan: same suppression.

Gemini and ChatGPT originals keep their provenance-asserted SynthID
strings; the Designer regression is pinned by
test_designer_synthid_suppression.py (agent name alone is not the
vendor's provenance, and a named soft binding suppresses the
inference).
This commit is contained in:
Victor Kuznetsov
2026-08-27 15:20:45 -07:00
parent 0a3b227f2c
commit d8fcd0f79b
7 changed files with 198 additions and 80 deletions
@@ -0,0 +1,85 @@
"""Regression: a manifest that names its own forensic soft binding must not
also report a SynthID watermark from the generic vendor-token inference.
Microsoft Designer manifests sign as Microsoft, carry the InvisMark
``c2pa.watermarked`` action, and name their generation agent
"Azure OpenAI ImageGen". The OpenAI issuer token inside that agent name plus
the watermarked action used to satisfy the OpenAI SynthID-evidence rule,
double-counting one forensic mark as two pixel watermarks.
"""
from __future__ import annotations
from remove_ai_watermarks._internal.c2pa import c2pa_info_from_manifest_store
DESIGNER_STORE = {
"active_manifest": "designer",
"manifests": {
"designer": {
"signature_info": {"issuer": "Microsoft Corporation", "common_name": "Microsoft Corporation"},
"claim_generator_info": [{"name": "Microsoft Responsible AI Provenance", "version": "1.0"}],
"assertions": [
{
"label": "c2pa.actions",
"data": {
"actions": [
{
"action": "c2pa.created",
"softwareAgent": {"name": "Azure OpenAI ImageGen"},
"digitalSourceType": "http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia",
},
{"action": "c2pa.watermarked"},
]
},
},
{
"label": "c2pa.soft-binding",
"data": {"alg": "com.microsoft.invismark.1", "blocks": [{"value": "bf7a2993-cc1f-47e1-b1f0-cd8839aabb22"}]},
},
],
}
},
}
def test_named_soft_binding_suppresses_generic_synthid_evidence() -> None:
info = c2pa_info_from_manifest_store(DESIGNER_STORE)
assert info["ai_source_kind"] == "generated"
assert info["soft_binding_algorithm"] == "com.microsoft.invismark.1"
assert info.get("synthid_watermark") is None
assert info.get("synthid_vendors") is None
def test_vendor_agent_name_alone_is_not_the_vendors_provenance() -> None:
"""The identity-scoped inference must not fire on a service name either.
Same manifest without the soft binding: the "Azure OpenAI ImageGen" agent
is not an OpenAI signature or claim generator, so no OpenAI SynthID
evidence may be derived from it.
"""
store = {
"active_manifest": "designer",
"manifests": {
"designer": {
"signature_info": {"issuer": "Microsoft Corporation", "common_name": "Microsoft Corporation"},
"claim_generator_info": [{"name": "Microsoft Responsible AI Provenance", "version": "1.0"}],
"assertions": [
{
"label": "c2pa.actions",
"data": {
"actions": [
{
"action": "c2pa.created",
"softwareAgent": {"name": "Azure OpenAI ImageGen"},
"digitalSourceType": "http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia",
},
{"action": "c2pa.watermarked"},
]
},
}
],
}
},
}
info = c2pa_info_from_manifest_store(store)
assert info.get("synthid_watermark") is None