Skip to main content

WAI Extension: Reproducible-Reconstruction Binding

Mirrored from the canonical text at commit 117bad22 ().

Status: Draft. A cryptographic hard binding over the deterministically decoded pixels of a neural-coded asset — the reconstruct-side analogue of the Asset Provenance extension, and a bridge from WAI’s byte-exact decode into C2PA / JPEG Trust provenance. Reference impl: the reconstruction_binding module of wai-rs (feature provenance). Keywords MUST, MUST NOT, SHOULD, MAY are RFC 2119/8174.

1. Scope and model

A provenance manifest binds itself to an asset with a hard binding: a cryptographic hash over the asset’s bytes. For neural-coded media that hash covers the compressed codestream. A hard binding over the decoded image is possible only when the decode is reproducible: where two conformant decoders may produce different pixels, a hash of the decoded image is not portable across implementations, and provenance over the rendered result falls back to fuzzy soft bindings (perceptual hashes, watermarks), which are approximate and spoofable.

This is not incidental to the codec. The JPEG AI standard (ISO/IEC 6048 / ITU-T T.840) defines its normative bit-exact conformance point at the output of the entropy decoder, not at reconstruction to pixels; and its multi-branch design specifies up to three synthesis transforms (decoderID 0/1/2), any of which produces a conformant reconstruction of the same codestream. Reconstruction to pixels is therefore, by design, not required to be bit-exact, and one codestream may legally decode to different images. A hash of the decoded pixels is not portable under the base standard.

Over a capability registered at decode-equivalence — WAI’s integer-exact decoders, wai.neural.int_hyper and the other NeuralIntegerExact capabilities (determinism-tiers §5) — every conforming sink reconstructs the same pixels, so the decoded-pixel hash is portable by construction.

wai.image.jpegai is registered at entropy-consistency, the tier of the base standard’s conformance point. WAI’s exact JPEG AI decoder nevertheless reconstructs to RGB deterministically — one pinned reconstruction, reproducible across machines under stated conditions. Its entropy decode and its hyper-decoder, context-model and synthesis networks are integer; dequantisation, latent refinement, the post-filter chain (including the eICCI post-filter, a float CNN) and colour conversion run in IEEE-754 float with a fixed evaluation order, in the default floating-point environment, which the decoder checks before decoding. It implements one configuration: 256×256 4:4:4, model_id 0 (tools_0), beta_displacement_log 0, the high-operation-point synthesis (so a binding over its output carries decoderId 2), and the other header conditions in determinism-tiers §5. The reference sink refuses codestreams outside that configuration. Within it, a sink without the integer weight bundle, or in a non-default floating-point environment, falls back to a float decode whose pixels are not pinned, and no binding applies to its output. The pinned reconstruction is a property of the exact decoder, not of the capability: its reproducibility rests on that decoder’s build and on the process’s floating-point environment (determinism-tiers §5–§6). Within those conditions it restores the precondition a hard binding needs — a stable hash of the decoded pixels — for a verifier that runs the same decoder (§2). This extension expresses that hash as a provenance assertion.

A reconstruction-binding is not a content capability. The asset declares an ordinary capability (wai.image.jpegai, wai.neural.int_hyper, …) and is carried and decoded normally; the binding is metadata about the decoded result, the way provenance is metadata about the carried bytes.

2. The binding

A binding is a hash plus the descriptor that makes the decode reproducible:

{
  "alg": "sha256",
  "hash": "<lowercase hex SHA-256 over the canonical decoded pixels>",
  "reconstruction": {
    "decoderId":  2,          // the pinned synthesis branch (multi-branch codecs;
                              // 2 for wai.image.jpegai's exact decoder)
    "profile":    "<id>",     // codec profile
    "level":      "<id>",     // codec level
    "width":      256,
    "height":     256,
    "format":     "RGB8",     // canonical: row-major, 3 bytes/pixel, no padding, no alpha
    "colorSpace": "bt709"
  }
}

Conformance criterion:

3. C2PA / JPEG Trust carriage

C2PA (and JPEG Trust, ISO/IEC 21617-1, which is built on the C2PA architecture) has no standard assertion that hashes decoded/rendered pixels — every standard hard binding (c2pa.hash.data, c2pa.hash.boxes, c2pa.hash.bmff) hashes the compressed bytes. A reproducible-reconstruction binding is therefore expressed as a custom assertion, using C2PA’s reverse-domain labelling for third-party assertions:

The digest is the same value WAI’s own receipt carries (§4), so a validator with a WAI decoder reaches a matching hash whether it reads the C2PA CBOR assertion or the WAI receipt.

4. WAI receipt carriage

The binding MAY be carried in a WAI receipt alongside an asset provenance receipt: provenance binds the opaque asset bytes (content-hash-equivalence, BLAKE3 over the envelope); this binds the reconstructed pixels (SHA-256 over the canonical RGB — decode-equivalence, or for wai.image.jpegai the exact decoder’s pinned reconstruction). Together they cover both halves of the thesis — the bytes that are carried and the pixels that are reconstructed. The reference impl emits the §2 JSON via ReconstructionBinding::to_json.

5. Machine-readable AI-content marking

A reproducible-reconstruction binding is a substrate for machine-readable marking of AI-processed media. Where a regime requires content to be marked in a machine-readable, detectable format (for example EU AI Act Article 50, whose transparency obligations apply from 2 August 2026, with the technical marking standards developed via the Code of Practice), a signed assertion that binds the reconstructed content — carried through the neural coding step rather than invalidated by it — is a mechanism that survives decode. WAI states this as a capability (a signed, reproducible binding over decoded content); it does not make a legal claim, and any deployment MUST confirm sufficiency against the applicable regime.

6. Reference implementation

wai-rs, feature provenance, module reconstruction_binding: ReconstructionDescriptor, ReconstructionBinding::{bind, verify, hash_hex, to_json, C2PA_LABEL}. bind hashes the canonical RGB8 buffer under a descriptor; verify re-hashes a freshly decoded buffer and compares. The digest is a plain SHA-256, reproducible by any SHA-256 implementation — which is what makes it portable into a C2PA validator.