WAI Extension: Reproducible-Reconstruction Binding
Mirrored from the canonical text at commit 117bad22 ().
Status: Draft. A cryptographic hard binding over the deterministically decoded pixels of a neural-coded asset — the reconstruct-side analogue of the Asset Provenance extension, and a bridge from WAI’s byte-exact decode into C2PA / JPEG Trust provenance. Reference impl: the
reconstruction_bindingmodule ofwai-rs(featureprovenance). Keywords MUST, MUST NOT, SHOULD, MAY are RFC 2119/8174.
1. Scope and model
A provenance manifest binds itself to an asset with a hard binding: a cryptographic hash over the asset’s bytes. For neural-coded media that hash covers the compressed codestream. A hard binding over the decoded image is possible only when the decode is reproducible: where two conformant decoders may produce different pixels, a hash of the decoded image is not portable across implementations, and provenance over the rendered result falls back to fuzzy soft bindings (perceptual hashes, watermarks), which are approximate and spoofable.
This is not incidental to the codec. The JPEG AI standard (ISO/IEC 6048 /
ITU-T T.840) defines its normative bit-exact conformance point at the output
of the entropy decoder, not at reconstruction to pixels; and its multi-branch
design specifies up to three synthesis transforms (decoderID 0/1/2), any of
which produces a conformant reconstruction of the same codestream. Reconstruction
to pixels is therefore, by design, not required to be bit-exact, and one
codestream may legally decode to different images. A hash of the decoded pixels is
not portable under the base standard.
Over a capability registered at decode-equivalence — WAI’s integer-exact
decoders, wai.neural.int_hyper and the other NeuralIntegerExact capabilities
(determinism-tiers §5) — every conforming sink
reconstructs the same pixels, so the decoded-pixel hash is portable by
construction.
wai.image.jpegai is registered at entropy-consistency, the tier of the base
standard’s conformance point. WAI’s exact JPEG AI decoder nevertheless reconstructs
to RGB deterministically — one pinned reconstruction, reproducible across
machines under stated conditions. Its entropy decode and its hyper-decoder,
context-model and synthesis networks are integer; dequantisation, latent
refinement, the post-filter chain (including the eICCI post-filter, a float CNN)
and colour conversion run in IEEE-754 float with a fixed evaluation order, in the
default floating-point environment, which the decoder checks before decoding. It
implements one configuration: 256×256 4:4:4, model_id 0 (tools_0),
beta_displacement_log 0, the high-operation-point synthesis (so a binding over its
output carries decoderId 2), and the other header conditions in
determinism-tiers §5. The reference sink refuses codestreams
outside that configuration. Within it, a sink without the integer weight bundle, or
in a non-default floating-point environment, falls back to a float decode whose
pixels are not pinned, and no binding applies to its output. The pinned
reconstruction is a property of the exact decoder, not of the capability: its
reproducibility rests on that decoder’s build and on the process’s floating-point
environment (determinism-tiers §5–§6). Within those
conditions it restores the precondition a hard binding needs — a stable hash of the
decoded pixels — for a verifier that runs the same decoder (§2). This extension
expresses that hash as a provenance assertion.
A reconstruction-binding is not a content capability. The asset declares an
ordinary capability (wai.image.jpegai, wai.neural.int_hyper, …) and is carried
and decoded normally; the binding is metadata about the decoded result, the way
provenance is metadata about the carried bytes.
2. The binding
A binding is a hash plus the descriptor that makes the decode reproducible:
{
"alg": "sha256",
"hash": "<lowercase hex SHA-256 over the canonical decoded pixels>",
"reconstruction": {
"decoderId": 2, // the pinned synthesis branch (multi-branch codecs;
// 2 for wai.image.jpegai's exact decoder)
"profile": "<id>", // codec profile
"level": "<id>", // codec level
"width": 256,
"height": 256,
"format": "RGB8", // canonical: row-major, 3 bytes/pixel, no padding, no alpha
"colorSpace": "bt709"
}
}
- Hash algorithm —
sha256(the C2PA default; every C2PA validator supports it). MUST be an algorithm in the C2PA hash-algorithm registry. - Canonical buffer — the hash is computed over the decoded image as a
RGB8buffer: row-major, three bytes per pixel, no row padding, no alpha, exactlywidth * height * 3bytes. No other pre-processing. - The descriptor is part of the binding. A multi-branch codec decodes one
codestream several ways; a verifier MUST decode under exactly the descriptor’s
decoderId,profile, andlevelbefore hashing, or the comparison is meaningless. The descriptor pins the one reconstruction the hash is over.
Conformance criterion:
- Over a capability registered at decode-equivalence (see
determinism-tiers), a verifier that decodes the
codestream with any conforming decoder under the binding’s descriptor, hashes the
canonical
RGB8buffer, and compares MUST obtain the recordedhash. - Over
wai.image.jpegai(registered atentropy-consistency), the hash is over the reconstruction of WAI’s exact decoder (§1). A verifier MUST decode with that decoder — not the float fallback — in the default floating-point environment, and then MUST obtain the recordedhash. A verifier that decodes any other way has not checked the binding: a mismatch it finds is not evidence that the asset changed, and it MUST NOT report the binding as failed on that basis. The reference dispatch (decode_envelope) does not report which path ran, so a verifier calls the exact decoder directly (jpegai_decode::decode), which refuses rather than falls back.
3. C2PA / JPEG Trust carriage
C2PA (and JPEG Trust, ISO/IEC 21617-1, which is built on the C2PA architecture)
has no standard assertion that hashes decoded/rendered pixels — every standard
hard binding (c2pa.hash.data, c2pa.hash.boxes, c2pa.hash.bmff) hashes the
compressed bytes. A reproducible-reconstruction binding is therefore expressed as a
custom assertion, using C2PA’s reverse-domain labelling for third-party
assertions:
- Assertion label:
science.transaction.wai.hash.reconstruction - Body: the object in §2, serialized as a CBOR map (the C2PA assertion
serialization). Field names map 1:1 to the JSON above:
alg(text),hash(byte string), andreconstruction(a map ofdecoderId(uint),profile/level/format/colorSpace(text),width/height(uint)). - Placement: this assertion is additional. A manifest SHOULD still carry a
standard hard binding (
c2pa.hash.dataover the codestream) referenced by the claim’screated_assertions, so it is valid in any C2PA validator; the reconstruction binding sits beside it. The byte-binding proves these compressed bytes; the reconstruction binding upgrades that to and anyone who decodes them per this descriptor obtains this exact image (forwai.image.jpegai, anyone who decodes them with the exact decoder, §2). - Signature: the assertion is covered by the C2PA claim signature like any other, so it is tamper-evident.
The digest is the same value WAI’s own receipt carries (§4), so a validator with a WAI decoder reaches a matching hash whether it reads the C2PA CBOR assertion or the WAI receipt.
4. WAI receipt carriage
The binding MAY be carried in a WAI receipt alongside an asset
provenance receipt: provenance binds the opaque asset bytes
(content-hash-equivalence, BLAKE3 over the envelope); this binds the reconstructed
pixels (SHA-256 over the canonical RGB — decode-equivalence, or for
wai.image.jpegai the exact decoder’s pinned reconstruction). Together they cover
both halves of the thesis — the bytes that are carried and the pixels that are
reconstructed. The reference impl emits the §2 JSON via
ReconstructionBinding::to_json.
5. Machine-readable AI-content marking
A reproducible-reconstruction binding is a substrate for machine-readable marking of AI-processed media. Where a regime requires content to be marked in a machine-readable, detectable format (for example EU AI Act Article 50, whose transparency obligations apply from 2 August 2026, with the technical marking standards developed via the Code of Practice), a signed assertion that binds the reconstructed content — carried through the neural coding step rather than invalidated by it — is a mechanism that survives decode. WAI states this as a capability (a signed, reproducible binding over decoded content); it does not make a legal claim, and any deployment MUST confirm sufficiency against the applicable regime.
6. Reference implementation
wai-rs, feature provenance, module reconstruction_binding:
ReconstructionDescriptor, ReconstructionBinding::{bind, verify, hash_hex, to_json, C2PA_LABEL}. bind hashes the canonical RGB8 buffer under a
descriptor; verify re-hashes a freshly decoded buffer and compares. The digest is
a plain SHA-256, reproducible by any SHA-256 implementation — which is what makes it
portable into a C2PA validator.