C2PA Update Manifests: How to Review Later Metadata Changes
Preserve the file and separate the review questions
Save the exact media file you are examining and record its source page, filename, and acquisition time. Open that copy in a C2PA-compatible validator, then note the validator name and version. Keep the complete output with the file. This evidence log is an editorial method proposed here, not a case-management format required by C2PA.
Separate two questions before reading the manifest chain: whether a later manifest added provenance assertions without changing the digital content, and whether a caption or claim about the depicted event is accurate. An update manifest can help with the first question. The second needs the publisher's original context and independent evidence.
Assign an identifier to every manifest and claim shown by the validator. Record which one is active, which ingredient it references, and which assertion appears in each manifest. That prevents a later metadata record from being silently merged into the original signed claim.
Identify an update manifest by its stated job
C2PA 2.2 describes an Update Manifest for provenance workflows in which additional assertions need to be added while the digital content is unchanged. The specification gives it the JUMBF type c2um. Record the type displayed by the validator, but do not rely on the label alone. Read the assertions and the ingredient relationship as well.
An Update Manifest must contain exactly one ingredient assertion. For c2pa.ingredient.v3, that assertion references the activeManifest and claimSignature of the asset being updated, and its relationship is parentOf. Older ingredient versions use a different field described by the specification. Copy the version, relationship, and references exactly. If the validator does not expose them, report that they were not displayed rather than guessing their values.
The referenced ingredient manifest may itself be a standard manifest or another update manifest. Follow the chain one step at a time. Keep each observation tied to the manifest that actually contains it.
Check what an update manifest may add
The specification permits c2pa.actions or c2pa.actions.v2 only when every action uses a value from its restricted list. Open the linked section and copy the displayed action value rather than replacing it with a broad description such as edited. The allowed value tells you what the claim records; it does not explain the operator's motive or establish that the recorded assertion is factually correct.
An update manifest may also contain a time-stamp assertion, a certificate-status assertion, or both. Record these results in their own fields. A time-stamp concerns the signature evidence evaluated by the validator. It should not be presented as the camera capture time or the time when the depicted event occurred. A certificate-status result likewise answers a credential-validation question, not the truth of a caption.
Compare two copies only after documenting them separately. For each copy, list the file identifier, manifest identifier, ingredient reference, allowed action if present, time-stamp result, certificate-status result, and unresolved question. A blank field means the tool did not show or find it during that run.
Treat prohibited assertions as a validation issue
C2PA says an Update Manifest must not contain the listed hard-binding assertions: c2pa.hash.data, c2pa.hash.boxes, c2pa.hash.collection.data, c2pa.hash.bmff.v2, or c2pa.hash.bmff.v3. It must not contain c2pa.hash.multi-asset or a thumbnail assertion either. The specification explains that content bindings do not need to be updated when the content has not changed, while an action outside the allowed list or a thumbnail implies a digital-content change.
If a validator reports one of those assertions inside an update manifest, preserve the complete output and report the narrow conflict. Do not repair the record by deleting a field from your notes, and do not turn the conflict into a claim that the media is synthetic. Check the exact file again with the documented validator and, when possible, compare the publisher's retained original or another independently obtained copy.
Keep detection and event verification in separate columns
A saved image, video, audio file, or text can be submitted to DeepFakeCheck for a probabilistic risk signal. DeepFakeCheck does not validate an update manifest, follow its ingredient reference, verify its signature, or decide whether its action list follows C2PA. Store that output apart from the manifest record.
Automated analysis can produce false positives that flag authentic material and false negatives that miss synthetic or altered material. A high-risk result supports further review; a low-risk result does not authenticate the file or confirm that an update manifest is valid. Continue checking the provenance chain, the original publication, and the real-world claim regardless of the detector result.
Close the review with the inspected file, validator and version, manifest sequence, ingredient references, assertion and action values, validation conflicts, external-source findings, detector output if used, and the decision taken. The record should let another reviewer repeat the checks without treating later metadata as a rewrite of the original claim.
Sources
- C2PA, “C2PA Technical Specification — Update Manifests”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_update_manifests
Need to check a suspicious file?
Open the matching detector and interpret the result alongside the source and context.
Open Detector