VER 1.0 — The Visual Embedding Recordstable
§12 Security Considerations
- Unsigned metadata is attacker input. EXIF is forged in one line of exiftool. Trust tiers (§7.4) exist so forged capture times and GPS never reach trusted fields.
- Decoder attack surface. Image parsers are a historical RCE goldmine. CPNP decoding MUST run sandboxed (seccomp/jail/WASM or equivalent).
- Adversarial images. Small perturbations can move or collide embeddings and perceptual hashes. The semantic and perceptual tiers are similarity signals — never authentication, never moderation-evasion-proof. Authentication lives at the byte tier and C2PA.
- Embedding inversion. Vectors leak content; reconstruction attacks are practical. Vectors of private assets MUST receive access control equal to the assets themselves.
- Model supply chain. weights_sha256 pinning plus space immutability prevents silent weight swaps and drift.
- Context poisoning. Grade-C sources (surrounding text) are untrusted by definition; retrieval systems SHOULD weight by grade and trust tier.
- Hash ambiguity. The dimensioned pixel_hash preimage (§4) forecloses cross-dimension collisions on equal-length buffers.
