Reference

AI image provenance glossary

Short definitions of the terms used across these guides, each with where it lives and what WipeTheAI does with it.

Updated 23 September 2026

Nineteen terms, in alphabetical order, each tied to where it lives in a file or in the pipeline and to what WipeTheAI does with it. Most of them belong to one of three separate layers: the file’s metadata, a watermark hidden in the pixels, or a platform’s own judgment. We think mixing up the layers causes more bad advice on this subject than anything else.

A

APP11
JPEG application segment 11 (marker FFEB), where a JPEG carries its C2PA manifest as JUMBF boxes. A JPEG segment holds at most 65,533 bytes, so a large manifest is split across several APP11 segments. Our cleaner drops every APP11 segment and labels it as Content Credentials when it finds a jumb box near the start. Removing it without re-encoding is covered step by step.

C

C2PA
The Coalition for Content Provenance and Authenticity, and the technical standard it publishes for signed provenance records attached to media. Metadata layer, not pixels. A result of “no C2PA manifest found” proves only that the file lacks the record, never that a person made the picture. The C2PA explainer goes through what a record contains.
caBX
The PNG chunk that holds a C2PA manifest. Its lowercase first letter marks it as ancillary under the PNG rules, which means any viewer or editor that doesn’t recognise the name is expected to skip over the chunk and still show the image as if it were not there. We delete it and rewrite the checksums of the chunks that remain. WebP uses a RIFF chunk named C2PA instead, which our cleaner missed until 23 September 2026, as the C2PA removal guide admits.
Claim generator
The field in a C2PA claim that names the software that wrote it, such as an image generator or an editor. It is usually the quickest way to see which tool made a file. In a file with more than one manifest our scanner shows the current (last) one’s generator and lists the earlier ones, next to the declared actions and whether a signature block is present; it does not validate the signature. For that, see how to check an image for Content Credentials.
Content Credentials
The public-facing name for C2PA manifests, used by Adobe and the Content Authenticity Initiative. Adobe says Firefly attaches them automatically when every pixel was generated, and that they may also be stored in its public Content Credentials cloud, so a copy can outlive the one in your file. Adobe’s tools are covered in the Firefly and Photoshop guide.

D

Durable credentials
Content Credentials backed up by two other things: an invisible watermark carrying a short identifier plus a pointer to where the manifest can be retrieved, and a fingerprint computed from the pixels. The Content Authenticity Initiative described the three together in April 2024. The point is recovery after the embedded manifest has been stripped. We don’t know of published figures on how often that recovery happens in practice. Where it fits in the standard is in what C2PA Content Credentials are.

E

EXIF
Numbered camera tags stored in the file: a JPEG APP1 segment starting Exif, a PNG eXIf chunk or a WebP EXIF chunk. Tag 0x8825 points to the GPS block, and the rest can hold serial numbers and an owner name. Automatic1111 also writes its prompt into the UserComment tag of JPEG and WebP files. Our cleaner removes the whole block, except that a JPEG keeps its Orientation tag (0x0112) so the photo stays upright; the EXIF and GPS guide lists the tags worth caring about.

I

ICC profile
The colour profile that tells software how to read a file’s colour numbers (JPEG APP2, PNG iCCP, WebP ICCP). Delete it from a Display P3 photo and saturated colours go flat when it is read as sRGB. ExifTool’s documentation warns that -all= removes colour space information; our cleaning step keeps it, though the re-saved file you download may not. ExifTool, a screenshot and WipeTheAI compared shows the difference.
img2img
See regeneration.
IPTC DigitalSourceType
A field from the IPTC photo metadata standard, usually written inside XMP, that says how an image came to exist. Its value is a web address from IPTC’s controlled list, ending in a code such as trainedAlgorithmicMedia (made by a generative model) or compositeWithTrainedAlgorithmicMedia (a real image with generative edits such as inpainting). Midjourney and Shutterstock committed to using it in May 2023, and Meta reads it to decide labels. The second code is why lightly edited real photos get labelled, as the Instagram AI label explainer shows.

J

JUMBF
JPEG Universal Metadata Box Format (ISO/IEC 19566-5): a container of typed boxes, the outer one labelled jumb. C2PA stores its manifest store as JUMBF in every format, wrapped in whatever carrier the format allows: APP11 in JPEG, caBX in PNG. ExifTool deletes the group with exiftool -jumbf:all= photo.jpg, as described in the guide to deleting a C2PA manifest.

M

Manifest
One signed C2PA record: assertions (such as the actions taken and the ingredient files used), a claim that binds them to the image by hash, and a signature. A file can carry a manifest store with several manifests, one per editing step. Editing the pixels without writing a new manifest breaks the hash, which is how validators spot tampering. Reading a manifest covers what each part tells you.

P

Provenance oracle
Our name for the outside check we test a result against, because no public detector exists for Google’s production SynthID. For Google images it is Gemini’s answer to “Was this created with Google AI?”, a classifier judgment that combines a SynthID check with Gemini’s own reasoning, not Google’s production detector. OpenAI’s public verify page plays the same part for its images. The SynthID detector guide covers who can use what.

R

Regeneration (img2img)
Pushing an image partway into a diffusion model’s noise and letting the model paint it back. Zhao and colleagues showed in 2023 that this provably removes watermarks whose changes stay small in the pixels. Our Maximum disruption mode is a light regeneration. It passed Gemini’s check on all three of our test image types; per-image results vary. Details are in the SynthID watermark guide.
Rinsing
Running regeneration more than once on the same image. The WAVES benchmark found two rinses gave the best balance of removal and quality on the watermark it tested. What repeating does in practice is in our notes on the watermark pass.

S

SSIM
Structural similarity: a score where 1 means two images are identical in structure. Every WipeTheAI result shows one. Ours is computed over the whole frame on small greyscale previews about 128 pixels across, so it tracks overall change well and can miss small printed text that regeneration has garbled. Check text by eye on the before-and-after slider. The comparison of cleaning methods uses it too.
Strength
In img2img, the share of the denoising schedule the model redoes: 0 leaves the image alone, 1 repaints it from noise. Low values keep the picture close to the original. On our most heavily marked test image, the lowest values we tried failed Gemini’s check, so the setting that works sits in a narrow band.
SynthID
Google DeepMind’s invisible watermark, written into the pixel values rather than stored as metadata. DeepMind says it is designed to stand up to cropping, filters and lossy compression, and Google’s paper tests it against 30 common image transformations and combinations of them. OpenAI announced in May 2026 that its images carry it too. No public tool can confirm it. WipeTheAI never says it detected SynthID; it labels it Likely or Possible from the file’s own evidence. What SynthID is, at more length.

T

trainedAlgorithmicMedia
See IPTC DigitalSourceType.
TrustMark
An open-source invisible watermark from Adobe Research and the University of Surrey, MIT-licensed, that hides a 100-bit payload in images from about 150 pixels on the short side upward, with no upper limit. It is one way to build durable credentials. We haven’t tested our recipe against Adobe’s check. Adobe’s use of it is in the Content Credentials in Adobe tools guide.

X

XMP
Adobe’s XML metadata format. In a JPEG it is an APP1 segment starting http://ns.adobe.com/xap/1.0/; in PNG an iTXt chunk with the keyword XML:com.adobe.xmp; in WebP an XMP chunk. It carries IPTC fields, edit history and AI source types. Our cleaner drops it in all three. Which generators write what is in the AI generators metadata comparison.

Sources

  1. C2PA Technical Specification 2.1
  2. IPTC NewsCodes: digital source type
  3. IPTC: Midjourney and Shutterstock AI sign up to use of IPTC Digital Source Type
  4. Content Authenticity Initiative: Durable Content Credentials (8 April 2024)
  5. Adobe TrustMark on GitHub
  6. Google DeepMind: SynthID
  7. SynthID-Image paper (arXiv 2510.09263)
  8. Zhao et al., invisible image watermarks are provably removable (arXiv 2306.01953)
  9. WAVES watermark robustness benchmark (arXiv 2401.08573)
  10. ExifTool application documentation