Login / Register ID | EN
This page has no official English version. It was translated automatically and may contain errors. Read the original in Indonesian →
Deepfake Makin Halus, Ini Cara Mengecek Asal Videonya
Foto: Pexels
Cyber Security IT

Deepfakes are becoming more sophisticated; here’s how to check the origin of a video.

The most popular way to recognize fake videos is by examining the faces. Stiff blinking, lips that don't match the sound, blurry hair edges, fingers that suddenly split. This method is still useful. The problem is, its effectiveness is short-lived. Each time generative models are updated, one by one, these characteristics disappear, and yesterday's effective checklist becomes blunt.

There are other approaches that do not depend on how polished the machine's output is. Check the file's history, not its appearance.

File history, not faces

C2PA has developed an open standard called Content Credentials. This standard defines provenance as facts about a file's history: when it was created, with what tools, and what changes were made. This information is packaged into a C2PA Manifest and then cryptographically signed.

A manifest contains three parts. A set of assertions, which are statements about the file. A claim that wraps those assertions. Then a claim signature, a digital signature using the signer's private key. The certificate uses X.509, the same standard as HTTPS and S/MIME security.

Two questions provenance does not answer

This is where people often misunderstand. C2PA states it clearly: Content Credentials do not assess whether the content of the file is true. It only ensures that its history is intact, free from tampering, and comes from a known signer. An original photo could be accompanied by misleading information, and provenance would not capture that.

The second question is more tricky. If a video does not have Content Credentials, does that mean it is fake? The official answer from C2PA is just one word: maybe. Adding provenance is voluntary, and the standard deliberately avoids a two-tier ecosystem where files without credentials are automatically suspected.

Hard binding and soft binding

Each manifest must have a hard binding to its file, in the form of a cryptographic hash. SHA-256 is recommended unless there is a specific reason to choose otherwise. Change one pixel, and the hash changes, causing the credentials to become invalid. That is why it is called tamper-evident. Changes are not prevented, but they are detectable.

The downside is also clear. Metadata can be removed, and once removed, its history is lost. For this, there is soft binding, which is an invisible watermark or perceptual fingerprint embedded in the content itself, used to recover a manifest that has been detached. C2PA emphasizes that soft binding should not replace hard binding due to the risk of collision.

The costs and how to view them

Attaching a manifest increases the file size. The chain of the signer's certificates and the timestamp chain are each about 10 KB. The much heavier part is actually the thumbnail, which ranges from about 100 KB to 1 MB depending on its quality.

For the average reader, just remember four levels of visibility. Level 1 indicates that the credentials exist and have been validated. Level 2 summarizes its history. Level 3 opens the details. Level 4 presents all signature data for forensic purposes.

No single tool is sufficient

NIST closes the last gap of hope. The AI 100-4 report concludes that no single content transparency approach can stand alone. Provenance tracking, watermarking, and synthetic content detection must work together, along with the digital literacy of the reader.

So checking faces remains useful. Just don't make it your only reference, because what you are testing there is the neatness of the machine's output, not the origin of the file.

If you prefer to see an explanation of the visual characteristics directly, there is a clip.

Sources