Apple Reference Image: A New Approach for Verified Photography
Apple Reference Image: A New Approach for Verified Photography
Apple Reference Image:验证摄影的新方法
Today, powerful, widely available AI tools allow users to easily generate or alter photorealistic images to a degree that was difficult to imagine just a few years ago. These tools enable helpful features, like one-touch removal of background distractions, but they also make it difficult to distinguish between photographs that depict real events, and synthetic images that are heavily altered or entirely generated. 如今,功能强大且广泛可用的 AI 工具让用户能够轻松生成或修改照片级逼真的图像,其程度在几年前是难以想象的。这些工具带来了诸如一键移除背景干扰等实用功能,但也使得人们难以区分记录真实事件的照片与经过深度修改或完全生成的合成图像。
So, in the case where the essential role of a photograph is to prove that something actually happened, an image appearing photorealistic is no longer sufficient to establish its veracity. This is not a simple problem to address. Modern cameras rely on sophisticated image-processing algorithms to produce the final viewable image, so certifying that an image accurately reflects what a real camera sensor captured requires a chain of trust covering the sensor as well as the computational photography software that interpreted the capture. 因此,当照片的核心作用是证明某事确实发生时,仅凭照片看起来逼真已不足以证明其真实性。这是一个难以解决的问题。现代相机依赖复杂的图像处理算法来生成最终的可视图像,因此,要证明一张图像准确反映了真实相机传感器所捕捉的内容,就需要建立一条涵盖传感器以及解读该捕捉内容的计算摄影软件的信任链。
Industry approaches to this problem, based on the C2PA standard, attach provenance metadata after capture and certify the history of image edits from that point forward. This approach, however, is vulnerable to compromise at any point in the editing chain, and a viewer has no way to detect such a failure. It can also create privacy risks for photographers working in dangerous conditions by tying the image to a public identity, either to a particular device or to an individual. 基于 C2PA 标准的行业解决方案是在拍摄后附加来源元数据,并从那时起证明图像的编辑历史。然而,这种方法在编辑链的任何环节都容易受到破坏,且观看者无法检测到此类失效。此外,它还可能将图像与特定设备或个人等公开身份绑定,从而给在危险环境下工作的摄影师带来隐私风险。
iPhone is the world’s most popular camera and the most secure consumer mobile device, and as such Apple is uniquely positioned to take on this challenge. The iPhone camera is integrated into a platform that sets the industry’s highest standards of security from the silicon up. We also operate Private Cloud Compute (PCC), an industry-leading privacy-preserving cloud infrastructure that is secure, auditable, and can perform verifiable algorithmic operations without allowing anyone — even Apple — the ability to see the data being processed. iPhone 是世界上最受欢迎的相机,也是最安全的消费级移动设备,因此苹果公司在应对这一挑战方面具有独特的优势。iPhone 相机集成在一个从芯片底层就确立了行业最高安全标准的平台上。我们还运营着私有云计算(PCC),这是一种行业领先的隐私保护云基础设施,它既安全又可审计,能够执行可验证的算法操作,且不允许任何人(包括苹果公司)查看正在处理的数据。
Leveraging these state-of-the-art capabilities, we have created Apple Reference Image, a novel solution for verifiable photography on iPhone, and debuting on the main camera sensor of iPhone 18 Pro and iPhone 18 Pro Max. This new, opt-in camera mode lets a photographer create a securely timestamped reference image that accurately reflects what was captured by the iPhone’s camera sensor. 利用这些尖端功能,我们创造了 Apple Reference Image,这是一种在 iPhone 上实现可验证摄影的新颖解决方案,并将首次在 iPhone 18 Pro 和 iPhone 18 Pro Max 的主摄像头传感器上亮相。这种全新的可选相机模式允许摄影师创建带有安全时间戳的参考图像,准确反映 iPhone 相机传感器所捕捉的内容。
Dedicated secure hardware on the device protects the integrity of this reference image, and Private Cloud Compute protects the privacy of the image data during processing. The system is built to be resilient to compromise, no matter how unlikely: any fraudulent images can be revoked without exposing the photographer’s identity. Apple Reference Image offers a trustworthy, scalable guarantee that a reference image is what it claims to be: a real photograph, captured by a real sensor in an iPhone camera, at a specific time. It sets a new standard for verifiable digital photography. 设备上的专用安全硬件保护了该参考图像的完整性,而私有云计算则在处理过程中保护了图像数据的隐私。该系统旨在抵御各种破坏(无论可能性多小):任何欺诈性图像都可以在不暴露摄影师身份的情况下被撤销。Apple Reference Image 提供了一种可信且可扩展的保证,证明参考图像名副其实:即在特定时间由 iPhone 相机中的真实传感器所捕捉的真实照片。它为可验证的数字摄影树立了新标准。
The Core Requirements of Apple Reference Image
Apple Reference Image 的核心要求
A high-assurance photographic provenance system must meet three core requirements: 一个高保证的摄影来源系统必须满足三个核心要求:
- Semantic authenticity: a reference image must faithfully show what the sensor captured. Transformations of image data from the raw captured pixels to the final viewable image must be publicly verifiable. 语义真实性: 参考图像必须忠实地展示传感器所捕捉的内容。从原始捕捉像素到最终可视图像的图像数据转换过程必须是公开可验证的。
- Resilience to compromise: image authenticity cannot be undermined by tampering with the camera sensor, through common cryptographic attacks, or via software-level jailbreak of the device. If, despite these protections, any fraudulent reference images are created, they can be revoked. 抗破坏性: 图像的真实性不能因篡改相机传感器、常见的加密攻击或设备软件层面的越狱而受到损害。如果尽管有这些保护措施,仍产生了任何欺诈性参考图像,它们是可以被撤销的。
- Privacy preservation: an outside observer cannot determine whether any pair of reference images were taken by the same device. Image contents are not exposed to Apple or anyone else. 隐私保护: 外部观察者无法确定任何一对参考图像是否由同一设备拍摄。图像内容不会暴露给苹果公司或任何其他人。
Apple Reference Image leverages custom-designed image sensors in iPhone 18 Pro and iPhone 18 Pro Max to ensure reliable capture of image data, and relies on Private Cloud Compute, which provides a computational environment for secure photographic processing that cannot be subverted even in the case of device compromise. We believe no other commercially-available photographic provenance system meets these strict requirements. Apple Reference Image 利用 iPhone 18 Pro 和 iPhone 18 Pro Max 中定制设计的图像传感器来确保图像数据的可靠捕捉,并依赖私有云计算,它为安全摄影处理提供了一个计算环境,即使在设备被破坏的情况下也无法被颠覆。我们相信,目前市面上没有任何其他摄影来源系统能满足这些严格的要求。
Semantic Authenticity
语义真实性
For any photographic authenticity system, the defining goal is that a user can trust that what is shown as the authenticated image corresponds to the scene that was actually photographed. A central challenge these systems face is how to secure the extensive photographic processing pipeline of a modern computational camera. Simply signing the raw values emitted by a sensor does not yield a viewable image: these pixels still need significant processing, like demosaicing and lens-shading correction, to be usable. 对于任何摄影真实性系统而言,其核心目标是让用户能够相信,作为认证图像展示的内容确实对应于实际拍摄的场景。这些系统面临的一个核心挑战是如何保护现代计算摄影相机庞大的图像处理流水线。仅仅对传感器发出的原始数值进行签名并不能产生可视图像:这些像素仍需要进行大量的处理(如去马赛克和镜头阴影校正)才能使用。
To solve this, prior industry systems have delayed signing images until they reach the end of their software processing pipeline. But this approach is vulnerable to attacks that inject spoofed pixel data onto the data transport from the sensor, or to compromises of the device operating system that can completely alter the image before signing. Neither signing raw sensor values, nor delaying signing until the photograph is processed, meets our bar for semantic authenticity. 为了解决这个问题,以往的行业系统会将图像签名推迟到软件处理流水线的末端。但这种方法容易受到攻击,例如在传感器的数据传输过程中注入伪造的像素数据,或者在签名之前通过破坏设备操作系统来彻底篡改图像。无论是对原始传感器数值进行签名,还是推迟到照片处理完成后再签名,都无法达到我们对语义真实性的要求。
Our solution hinges on splitting the Apple Reference Image process into two phases: creating a secure digital negative, and developing that negative into a reference image. Each phase receives our strongest protections. The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data. This creates a hardware-enforced assurance that the operating system receives pixel data exactly as the hardware sensor captured it, preventing injection or tampering attacks. We treat image metadata with the same level of protection. Sensor-produced metadata is signed at capture time tog… 我们的解决方案关键在于将 Apple Reference Image 的过程分为两个阶段:创建安全数字底片,以及将该底片开发为参考图像。每个阶段都受到我们最强有力的保护。安全数字底片的创建始于相机传感器的安全启动,进入专门的参考捕捉模式。该模式指示传感器在捕捉后立即对像素数据进行加密签名,并防止传感器固件修改数据。这在硬件层面确保了操作系统接收到的像素数据与硬件传感器捕捉到的完全一致,从而防止了注入或篡改攻击。我们以同等水平的保护来对待图像元数据。传感器生成的元数据在捕捉时即被签名……