DeepFake Check
Back to Blog
DeepCheckAI Team 4 min read

How to Read a C2PA Actions Assertion Without Overstating It

Preserve the file before reading the record

Save the exact media file you received and record its source page, filename, and the time you obtained it. If a platform offers several downloads, label the copy you actually inspect. This evidence log is a review method proposed here, not a procedure required by C2PA.

Open that copy in a compatible C2PA validator. The specification describes assertions as statements about an asset. Those statements can cover asset creation, edit actions, capture-device details, and bindings to content. C2PA defines an action as an operation performed by an actor on an asset, with “create,” “embed,” and “apply filter” as examples.

Copy the validator output instead of shortening it to “editing verified.” Keep the exact action wording, the assertion label, the validation message, and the file to which the result belongs. If the application does not display a detail, mark it as not displayed rather than reconstructing it from the filename or the visible image.

Define the review question in plain language before interpreting the record. One reviewer may need to know whether the available provenance mentions a filter. Another may need to compare the recorded changes in two copies. A third may be checking a caption about a public event. Write down that question and the evidence needed to answer it. This prevents a valid technical result from being reused as an answer to a broader question.

Record only the changes the provenance states

Make one row for each edit-action statement shown by the validator. Use columns for the exact statement, the associated asset or manifest shown by the tool, the validation result, and an unresolved question. This table is an editorial method for keeping observation separate from interpretation.

C2PA says that existing provenance is preserved when an asset changes and that each new change is added to the provenance. That supports tracing recorded changes across the available manifests. It does not give a reviewer permission to fill gaps. When the available record does not state the sequence, purpose, person, or complete set of tools, leave those points unknown until another source establishes them.

Two copies may expose different provenance. Label both files, repeat the validation, and compare the exact statements. A difference establishes that the records or copies differ. It does not by itself identify who changed the asset or explain why.

Keep screenshots as supporting notes, but retain the files and copied text as the primary review material. Screenshots can omit surrounding status messages or make two similar filenames look identical. A short file table with source page, download time, filename, size, and validator used gives another reviewer a stable starting point.

Check the signed claim, then check the event separately

C2PA assertions are referenced by a claim. The claim is digitally signed, and the assertions, claim, and claim signature form a C2PA Manifest. A C2PA validator checks the digital signature and its credential, checks assertions for validity, and presents that information to the user.

Write a provenance conclusion that names the file, manifest, signature result, validated assertions, recorded edit actions, and unresolved points. Keep a second conclusion for the real-world claim. That conclusion should use the original publication, the account or organization presenting the media, the claimed date and place, and independent evidence about the event.

A validated provenance record helps assess the integrity and source of the record. It does not independently establish that the depicted event happened or that a caption is accurate. A failed validation also has a limited meaning. Preserve the error and identify the check that failed instead of converting it into a verdict that the whole file is fake.

Keep detection as a separate risk signal

A saved image, video, audio, or text file can be submitted to DeepFakeCheck for a probabilistic risk signal. Use a C2PA validator for the provenance record and keep the DeepFakeCheck result in a separate section of the review.

Automated analysis can produce false positives that flag authentic media and false negatives that miss synthetic or manipulated media. Attach the result to the analyzed copy. A high-risk result supports further investigation, while a low-risk result does not authenticate the file. Continue the provenance and factual checks regardless of the risk level.

Finish with the exact file, copied validator output, unknowns, source-page checks, detector result if used, and the decision taken. The next reviewer should be able to repeat the inspection without inventing an edit history.

Sources

  • C2PA, “Content Credentials: C2PA Technical Specification”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html

Suspect an image might be AI-generated?

Use our advanced deepfake detection tool to analyze images with high precision.

Analyze Image Now