#37 - Uma Roy

23 Apr 2026 · 54 min · 21 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Uma Roy (Sysink) argues that AI-generated images/text/video are increasingly “undetectable” by AI detectors, so platforms need cryptographic verification. She proposes a “provable technology stack” for media: cryptographically sign capture, maintain signed chain-of-custody through edits, publish proofs to a “ledger of record,” and have apps verify and show a “pink checkmark” that content is real.

Guest background

Uma Roy is co-founder and CEO of Sysink, an applied cryptography company. She studied math and CS at MIT and previously did AI research at Google Brain (early LLM work including BERT). She’s known for building SP1, Sysink’s fast zero-knowledge virtual machine (ZKVM).

Key claims

AI detectors fail under simple perturbations (blur/noise/cropping). Cryptography can make authenticity verifiable end-to-end. iPhone Secure Enclave can support signing; Sysink is building an SDK. C2PA metadata and chain-of-edits fit into the stack.

Notable examples

AI receipt-number inflation that still passes detectors; adding dents/scratches for insurance fraud; editorial/war-zone images; “ledger of record” concept; references to Adam Mosseri/Instagram skepticism and X/Iran-war fake images.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Exploring Zero-Knowledge Virtual Machine

0:45 to 4:04

Uma explains the concept and applications of zero-knowledge proofs and their significance in cryptography.

“We built this ZKVM, which, how can I describe it?”

AI and Cryptography: A New Frontier

4:04 to 5:30

Discussion about how cryptography can address issues posed by AI and misinformation.

“So maybe you want to go through your slides?”

Challenges of AI Detection

5:30 to 8:40

Analyzing the current state of AI detection methods and their limitations.

“I don't know if you have any thoughts on that.”

The Role of AI in Text and Images

8:40 to 14:00

Debate on the effectiveness of AI detection in different media forms, including text and images.

“and you can actually go to the website aidetection.southink.xyz.”

Understanding AI's Impact on Communication

14:00 to 14:50

Explore how undisclosed AI affects perceptions of intelligence and effort.

“It's public, undisclosed AI that gets people mad.”

The Challenge of Evaluating AI-Generated Content

14:50 to 17:40

Discuss the challenges of discerning real versus AI-generated images and text.

“Like the outdoor scenes have too many people often, right?”

The Intersection of Fiction and Reality

17:40 to 19:31

Explore how fictional media influences our understanding of reality and history.

“I think you and I know it's made up, but I think, okay, here's my argument on this and let's continue.”

AI Detection Limitations and Implications

19:31 to 22:20

Analyze the limitations of AI detection methods and their implications for authenticity.

“There's all these examples and like, it's actually pretty fascinating.”

High Dimensionality and AI Misclassification

22:20 to 24:18

Understand how high dimensionality leads to challenges in AI classification.

“Like fundamentally, and I think if you think about how these models are trained, it kind of makes sense.”

Implementing Provable Technology in Content Creation

24:18 to 28:03

Learn about integrating cryptography in the content lifecycle for authenticity.

“And like it's just inevitable because like the decision you're just operating over such a high dimensional space.”
Show all 21 chapters

Understanding the Provable Tech Stack

28:03 to 30:28

Learn about the concept of a provable tech stack and its implications for content verification.

“I mean, and yeah, like all credit words do.”

AI and Cryptography in Content Creation

30:29 to 31:44

Explore how AI and cryptography are interconnected and their roles in media authenticity.

“And I think, finally, like, other people are starting to catch on because, like, the problem is finally very evident.”

Digital Tribes and Their Impact

31:45 to 35:09

Discuss the emergence of digital tribes and their implications for content sharing and verification.

“I think actually AI and crypto together are going to result in, you know, like, you know, I think the future is China versus the internet.”

The Future of Journalism with Crypto

35:10 to 37:11

Discover how cryptocurrency can transform journalism and improve information accuracy.

“Which I get, but there's a undercorrection and an overcorrection on anything.”

Provable Edit History and Technology Integration

37:12 to 41:59

Learn about the importance of a provable edit history in digital content and future technologies.

“I mean, yeah, I think the rest of the slides are just like a little more detail about what's going on.”

Cryptography's Role in AI

42:06 to 42:52

Learn how cryptography can address challenges posed by AI.

“all the signatures and all the cryptographic proof.”

The Political Awakening of the '90s

43:04 to 45:12

Explore the shift in political interest and cultural reflections of the '90s.

“So, um, well, what got me excited about this?”

Questioning Truth and Knowledge

45:12 to 46:55

Delve into the importance of verifying what we consider to be true.

“And so putting those together, you know, I started asking questions like, how do we actually know what's really true?”

The Iron Myth and Citation Tracking

46:55 to 49:08

Understand how myths can be perpetuated through incorrect citations.

“Spinach is a good source of iron, right?”

Pre-Headline vs Post-Headline People

49:08 to 51:34

Learn about the differences in perception of truth between researchers and the general public.

“And so now we can really, remember that Trugel thing that I was talking about?”

Addressing AI's Negative Externalities

51:34 to 53:31

Examine the challenges AI presents and the potential solutions.

“Like you can't be an expert on Turkish and Japanese and I don't know, Brazilian iron ore and so on and so forth.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Uma, welcome to the University of New York State podcast.

0:02Uma Roy:Thanks for having me. Awesome. You want to introduce yourself briefly? Yeah, so I'm co-founder and CEO of Sysink. Sysink is an applied cryptography company. We're probably best known for making the fastest zero-knowledge virtual machine, ZKVM for short, in the world, known as SP1. For those of you who aren't aware, ZK is this really powerful cryptography technique where it lets you prove to someone else something is true without revealing all the details. Kind of the canonical real-world example is that if I can prove to you that I'm over 21 without revealing my birthday or my home address or anything like that.

0:41Uma Roy:So instead of showing a driver's license at a bar, you can just show them a proof that you're of age. We built this ZKVM, which, how can I describe it? I would say it's somewhat like a foundation model for cryptography. So if you want to prove really complex statements in ZK, such as a rollup state transition function or like very complex predicates, the thing we built makes it super easy. You just write normal code, you stick it in to SP1 and out comes a proof. And then, yeah, we made it super fast and really easy to use, which is awesome. And I would say right now, succinct, although historically our ZKVM has been used mostly for proving blockchains and proving rollup state transition functions and things like this and like Ethereum and other chains.

1:24Uma Roy:Right now, we're really excited about the potential of cryptography to solve a lot of the problems that AI poses. I think Balaji has been an extensive tweeter about this topic for many years. You're very ahead of your time, honestly. Thank you. And so, yeah, I think, honestly, that's probably one of the most important things cryptography can do right now. And there's like a finally a clear catalyst. Every model release where the image stuff or video stuff gets better and better. It's like we need cryptography as a defense. And so I think it's time for cryptography to be on like a societal stage right now as like a solution to all the AI stuff.

1:59Uma Roy:So I'm very excited about that. Awesome. So, yeah, actually, many years ago, partly actually because of AI, but also with social media, when people are talking about misinformation, disinformation, and so on and so forth. years ago, I remember I tweeted something and I was like, oh, so you want to ban lies on the internet? Okay. Give me a function that says whether the remand hypothesis is true. Right. And so, you know, that's a reduction ad absurdum where we don't know whether it's true and it could be true and it's plausible that it's true, but there's many things in math, which have really arcane counter examples that, you know, you get up to N equals whatever, and it's actually not true.

2:48And so, but as I thought about that, I was like, well, how would you code Trugel, T-R-U-G-E-L-E, you know, if you were actually, you know, going to do it, right? How would you do it? And the thing is, LLMs get you some of the way towards that, right, because they will take a statement and they'll do at least a probabilistic search of the literature and pull things up

3:11Uma Roy:and so on and so forth, right? And the thing is, though, of course, then those assertions themselves need to be underpinned, the citations. And then that's how you get to on-chain everything. And so my view is, like, with LLMs, actually, you can kind of show a version of this today. If you ask any LLM to summarize some major crypto hack, it will show you probably some link that shows some on-chain block explorer record, among other things. And so that's currently only used to document financial things like the on-chain transaction, you know, during, let's say, FTX had a hack or whatever during that period, right?

3:52But as more and more things get logged on-chain, then more and more references from LLMs will point to on-chain events. And we get what I call the ledger of record. And I think Sysync could be maybe a big part of that. So you had some slides. So maybe you want to go through your slides?

4:06Uma Roy:Oh, yeah. What's your background by the way? You were born in the US. you um what's your yeah born in the us um yes born in the us i went to school at mit was a double major in math and cs i've always really loved math so that's kind of how i got into zk um and yeah i mean zk and cryptography have a lot of fascinating math and that was really big the draw for me um and actually before zk i was doing some ai stuff so i was like at google brain doing research into like early LLM. So this is pre-GPT. I was doing some stuff with BERT back then. So I'm familiar with that world. And now it's like exciting to see the synthesis.

4:47Yes. I mean, you know, the thing is, I, you know, I was actually also in machine learning prior to the deep learning era, but from the standpoint of genomics and diagnostics and whatnot. And, you know, just to digress on that for a second before we get into the ZK stuff, Like, you know, all the stuff with hidden markup models and conditional random fields and, you know, it was surprising to me that transformers worked as well as they did to get long range context in there. It's even more surprising to me that diffusion models work.

5:23Uma Roy:And yet they do. That, you know, you wouldn't necessarily intuit from the equations that they would work as well as they do in practice. I don't know if you have any thoughts on that. Maybe talk about that and then go to the next. When you were working on BERT, did you think, obviously there were people who had the graphs of scaling and here's how it's going to go, right? So there was some intuition that it could maybe get there, but it worked a lot. I mean, the jump between GPT-2 and GPT-3 and then chat GPT in terms of usability was very nonlinear, I think. Yes. Right? Go ahead. Were you surprised by that?

6:04Uma Roy:Oh, I mean, absolutely. I think even the people closest to the metal on this stuff seem surprised at how well it's going. And even today, the level of math problems they're solving and stuff like that. Yeah, I would say I was very surprised that this process, which with deep learning, there aren't really that many proofs. Like in cryptography, everything we do is proven. Like it's deterministic. You have very concrete bounds and proofs for everything. Yeah. And LLMs, it's just, it's like, why does deep learning work? Kind of vibes based. But right now the vibes are really good. It works really well.

6:45Right. And I think it's funny because, well, actually go through your talk and let's talk. Go. Prove what's real.

6:51Uma Roy:Okay, cool. So, yeah, I mean, I think you, one of your favorite quotes is AI makes everything fake. Crypto makes it real again. Yes.

7:31Uma Roy:sorts of things like the problem is i think today is like extremely clear and it's only getting to be worse and worse as these models get better and better uh so like the seed dance release recently of like the really good video models that like you know can really impersonate any celebrity or any person like it's very clear that ai makes everything fake is kind of like a huge problem for the internet so yeah that's like the problem statement um and then i think like one really interesting So people have identified this problem statement. It's not that hard to understand why it's so problematic.

8:07Uma Roy:I would say the state of the art right now for trying to detect AI is use AI. So people have trained these AI detectors to train models to say, hey, is something real or is something from the model? And recently at Sysynct, we did this benchmarking study to evaluate those claims and say, hey, does AI detection actually work? And we published this data set of realistic AI images and tried to benchmark all the leading commercial detectors. and you can actually go to the website aidetection.southink.xyz. But the resounding answer was like, yeah, the AI detection stuff is not robust and it just does not work.

8:53I'm going to slightly argue with you on this maybe, which is to say on text as opposed to images, right? So much, so this reminds me a little bit of, I'm not really arguing with the results of your paper, but on the macro thing, right? And so with Snapchat, you know, it has a deterrent to someone taking a screenshot of, you know, like a disappearing message. Now, of course, you or I or someone who's a computer scientist will say, well, there's still the analog hole. You can just hold up another phone and record it. And, you know, if you want to, you can just take a second phone and record it. And that doesn't have, you know, you can defeat it with a sufficiently motivated attacker relatively easily, right?

9:41However, most people aren't that motivated. And so the simple and dumb screenshot detection thing sets the norm and makes it relatively hard to do screenshots, right? Similar to how, you know, you could, people could work around the Twitter 140 character limit by pasting in screenshots of 140, you know, more than 140 characters, but they didn't for a long time, right? And my view is that there's a lot of AI text on X, for example, that at least I can trivially detect. It's not this, it's that, and the M dashes and so on and so forth. And there's certain people who just are clearly AI posters because of just the style.

10:20It's like this overdramatic kind of style. It jumps out to you immediately when you see it because you see it a lot. It's like seeing the same person writing over and over.

10:29Uma Roy:And pangram.com or something like that feels pretty good at detecting chat GPT type slop, which you see a lot of and claude and chatty for whatever reason a very similar text voice i think right on this kind of thing yeah i mean i guess they're trained on the same data to a certain yes whereas images you know maybe uh i i guess it depends on the class of image i mean obviously with hands and things like that gymnasts they're finally starting to get good with gymnastics with uh with c dance because those are unusual poses but they do like physics simulations i guess to train them. I don't know.

11:07Maybe you have a thought on that. You understand my point, right? Like AI detection may not work a hundred percent of the time, but for text, I think it currently works well enough to get a lot of the chat GPT type slop at a fairly high, like you can certainly see it visually, you know, like a human can see it. Then if it's unsubtle enough for us to see, let me pause there.

11:29Uma Roy:Yeah. I, I do agree that the tech stuff, at least right now, there are these watermarks almost like the m dash or the patterns you were saying like oh it's x this is x not y right um but i i still think that similar to images actually like the study we did basically was you take an image that an ai generates and by the way these things are pretty good like i actually i've gotten personally fooled a bunch of times yes yes sure so empirically it seems to be really good. And then we did the study where you basically perturb the image a bit. So you blur it or you crop it or you add some like indiscernible Gaussian noise to the image.

12:13Uma Roy:And then the AI detectors all completely break. And I think even in text, that's kind of true, right? And I mean, who's to say using AI to help you write some of your tweets? Maybe that's not even a bad thing necessarily, right? Like ultimately, like content is content. And maybe or saying something interesting with the AI's help. But like a lot of people do these tricks where they're like, get the output from ChatGPT and then they tell ChatGP, remove all the M dashes. And then it's not that detectable. No, it's true. I guess the thing is, so here's my view on that. It's my emerging view. So at least here's our current standard on this.

12:47So at NS, our rule is no public undisclosed AI. Right? Right. So why do I say that? Well, first is people can just go full AI and full AI means like, cause AI is a shortcut.

13:04Uma Roy:Yeah. And as a shortcut, I think it's a good term because people can take too many shortcuts and they fake it and they don't know what they're doing and so on. The more expert you are, the more legitimate it is to take a shortcut because you know how to do it the normal way. Right. And it's like writing down a theorem without doing the full proof every time. It's right. Using a function call route. There's a reason that people use shortcuts. Okay. but they can overuse them, fine. So the alternative is no AI, which a lot of people actually are gonna go to, and there's like an anti-AI moment, fine.

13:34But no public undisclosed AI, I think in four words it captures, so you can use private AI and that's undisclosed because you're going and editing your own stuff, right? I mean, you're like you're editing code, who cares? You're using it for yourself, right? Public disclosed AI, whether it's a watermark at the bottom right, or it's like an animation, a comic, a movie, something like that, no one can get mad because you're not trying to pull one over on somebody, right? It's public, undisclosed AI that gets people mad. And at least if I analyze my own reaction on that, I don't, when someone is sending me something that's obviously AI, I think they're either stupid or lazy.

14:19Why? They're stupid because they can't see the obvious AI tells. Like they send an AI slop slide deck or they have an AI webpage that has a lot of, like it's one thing if they say, hey, this is a prototype, check it out. Okay, fine. Right? But that's disclosed AI. If it's undisclosed and it's just got like a wall of AI, because AI tends to, you know, in AI images, they're more full of people than normal images by default. you know, if you've noticed, unless you actually pull that back, right? Like the outdoor scenes have too many people often, right? And that's like one tell, right? And similarly, AI pages and AI slide decks are not succinct.

15:04Uma Roy:Yeah, yeah, yeah. They're just really, right? And so either they're dumb and they can't tell what's good, or they're lazy and they're hitting a few keys and then sending me a bunch of slop and I have to go through it. And fundamentally they're taxing the other side. It's like someone leaving a voice memo for you. Yeah. You know, like I have to verify everything because they didn't verify everything. And so when they, whenever I get an AI message from somebody, I downweight them because of that. And I, and I downweight them as a poster and so on and so forth, because they just, they're taking shortcuts in a way that makes me question their judgment.

15:48If he gets good enough that, go ahead, sorry, what were you going to say?

15:51Uma Roy:Well, I think one reason the fake images and fake text is a little different is, I mean, historically, you could just write whatever words you want. Even pre-AI, you could just write a bunch of things that were not true, like you could lie. So I think Cubans are very used to critically evaluating the text they see because like people can always just write whatever. I think we're much less used to being able to critically evaluate images we see. Fake images. Historically, it was pretty hard. I mean, okay, you had things like Photoshop and this and that, but like, you know, it'd be pretty hard to really fake something elaborate or like fake, for example, the president of the United States doing like a one minute long video saying whatever, you just could not have done that in the past.

16:39Uma Roy:And now with the AI tools, it's very easy to do that. So it's really interesting you say that. And I want to continue your presentation. I agree. And I'll give a partial counter argument, which is, I actually think most of the images and videos people have seen are television or movies until recently. And those were actually all fictional and synthetic. And so they kind of live within a world where some significant fraction of their inbound training data is fictional as seen by the extent to which people reference, I don't know, Star Wars or The Handmaid's Tale or something like that, like the, you know, Harry Potter.

17:23That's actually more real for many people than actual history.

17:28Uma Roy:But that's like disclosed. It is disclosed, but I don't think they can actually... Go ahead, say, say, say, say. Okay, I was just going to say that is disclosed and that you know it's not, you know it's made up. I think you and I know it's made up, but I think, okay, here's my argument on this and let's continue. But the, I call it Jurassic Ballpark. Like, you know, Jurassic Park has the scene where, see, I'm actually referencing a fictional movie scene to explain fictional movie scenes, very meta, okay? So Jurassic Park has the scene where the dinosaurs have amphibian DNA spliced in because the scientists didn't know what to make of that part.

18:09So they spliced in amphibian DNA. And that leads to the dinosaurs reproducing. The point being that when we are dealing with a situation that we don't have personal experience of, like we don't have personal data on, you implicitly rely on some movie you've seen about that area to tell you how it's like for example unless you've actually been if unless you've worked at cia or you know people at palantir you don't really understand what the actual cia is as opposed to the movie version you think the movie version is in the ballpark and even if it's like more dramatized or whatever Right. And and it's often just totally not.

18:55And so that's why I mean, like, you're right that we kind of know it's fictional, but we don't know what reality is. And so often we think that the fictional is just a jazzed up version of the real as opposed to like totally, totally, totally off.

19:09Uma Roy:Mm-hmm. So anyway, so the reason I say that is I think there's a huge opportunity. One of the things I want to fund at some point is people taking actual history and then using AI to dramatize it. Mm-hmm. So now it's actually more fictional. It's fictional, but factual. Fictional depiction of real events, you know? Anyway, keep going. I didn't mean to digress. Keep going. There's all these examples and like, it's actually pretty fascinating. So here - Oh, essentially, the receipts. yeah i mean even i mean this is like kind of maybe a mundane example but we did all these we had a bunch of different categories of like real cases where ai deep fakes could be somewhat harmful and one is just you know receipts and like reimbursements and we had ai generate a bunch of images that were like taking a real receipt and modifying the numbers to be much greater than they actually were like at by an order of magnitude and then we put them through these AI image detectors.

20:04Uma Roy:And it turns out like, you know, they're okay. They're like, oh, this is a 36 % chance it's AI. This is a 44 % chance it's AI. Maybe - But what's the original? Some things. These are actually real photos. No, I mean, but did the original come up as 0 %? Oh, I don't have those numbers here, but I think it was like pretty accurate. um so the reason yeah the reason i ask is i'd love to see that data if you can pull it at some point because even if the detector was saying 36 if it could if it had variance you could rescale the axis you know i mean like if the if the real photos were left shifted relative to the fake photos you could recast it as you know like a binary classifier problem yeah like basically the distribution of real, like the distribution of it.

20:55Uma Roy:But then the problem is if you just do simple perturbations to the AI generated stuff, like you add a simple blur or noising. And I mean, if you are looking at the video of this and not the podcast, you can see these basically look pretty identical to the human eye. The AI detector says 4 % chance this is AI. So it's just not robust. Wow. Interesting. Okay. Well, yeah. Okay. That's true across a variety of examples. and then that's even true across a variety of problems so we did like some other examples okay this one's maybe a little more higher stakes you take a picture of a car that's not damaged you add ai to like add dents and scratches maybe you're doing insurance fraud again similar story the ai says hey okay like the original version when you just do naive like hey grok tell me like add dents um the ai detector will say hey it's like 44 chance or something like that but when you add some trivial blurring and noising, the AI detector goes down to like 2%.

21:58Uma Roy:So there's other, you know, then we took pictures of like real editorial photos. So you could imagine like war zones or like, you know, other journalism or famous political leaders and like kind of similar story across all these different categories of images. And so our conclusion from the study was that AI detection is a dead end. Like fundamentally, and I think if you think about how these models are trained, it kind of makes sense. Like when you're training these models, you're optimizing some sort of loss function from like the generation to like the manifold of real data. And you're literally optimizing so that the things you spit out look statistically very similar to the real data.

22:41Uma Roy:And so it's not that difficult to imagine that it's going to be very hard to detect what's real and what's fake because the models are being trained to minimize that. And there's actually like a bunch of work without going into too much detail. And also, I mean, obviously, I'm no longer an AI researcher, so I'm not like super in the weeds here. But there's a bunch of work done at MIT and by a bunch of other people on adversarial examples, where basically they had these detectors. Back then it was these image net classifiers. And then they added, they did a similar study. They added like some simple noise and stuff like that.

Read the full transcript

23:17Uma Roy:And then they found that the image classifier is more robust to these adversarial perturbations. So you could always kind of find some perturbation of an image. Like you would take an image of a panda, you would add some simple blurring. It would look the same to a human, but then the classifier would flip from panda to like dog. Right. And this is to do with basically just the fact that you would never actually see a point of that kind in the manifold of where pandas live. You could perturb it out to the manifold where dogs live because there was no training data along that vector typically. It's like very thin on that axis.

23:58Uma Roy:Yeah. Again, I wasn't in this research line. So my naive like way I think about it is like just these are such high dimensional decision boundaries. Like we're going to mess up at some point. And like there is going to be some point in the decision boundary where you think it's a dog, but like too human. It looks like a panda. And like it's just inevitable because like the decision you're just operating over such a high dimensional space. That's kind of how I think about it. Yeah, there's a there's actually a like a the pedal width versus length thing. like there's this irish data set in um in r i'll bring this up here oh yeah yeah i've heard of the famous one you know what i'm talking about right and so it's like um like something like this is uh probably a 3d actually you know what a better one is like swiss roll or something like that right um in 3d basically let's see if i can pull this up so something like this so swiss roll right is sort of something where um you have like the yellow category and the green category aquamarine light yellow blue right and in three space they're clearly distinct um but if and let's say this was you know uh the panda and this is the dog or something like that if you put a vector and you perturbed it in such a way that you had a point that was i don't know 60 percent of the way towards this blue part and there's no normal points that existed here in image space.

25:32That's my intuition for how the perturbation works. I should look that up, but that's certainly how it works with low dimensional things and probably something like that works with higher dimensional. And similarly to the pedal width one over here. Anyway, I want to get into succinct because this is the probabilistic. Let's get into your deterministic. Go, go, go. So this also, So if you had something over here that'd be outside of the training set, you could misclassify it as a circle when it was actually a triangle or vice versa. Okay, go, go, go. It's all your ball.

26:08Uma Roy:Yeah, so we fully established that, yeah, the AI detecting AI, so it's like not going to work. That seems bad. So it's the same. Well, okay, AI makes everything fake. That's what you said. What's the solution? Crypto makes it real again. Yep. So we're big believers of that. It's a thing doesn't apply to cryptography company. So now, like, let's dive into what that actually means. So today, like, how does content actually get posted online? I mean, basically, first, it gets captured, whether it's on like a smartphone or a camera or a microphone for audio or some other sensor. then it goes through some editing uh whether it's like photoshop or these ai editing tools and then it gets published so it's like across social media news services news wires traditional media youtube and then it gets consumed so you look at the content and you say like you you just look at the content so that's kind of like the current life cycle and yeah throughout all this there's like no verification so it would be impossible for you to tell if something's real or something's fake.

27:15Uma Roy:Now, how does crypto help with this? So this is like what we're building at Sysynct, but we think there's this notion of basically what we call the provable technology stack. So at every point in this like capture, edit, publish, consume lifecycle, you insert in cryptography and provable technology to prove its role. So to start, when you capture something - Yeah, this is exact. This is you must have taken some of my content and maybe. Yeah, yeah. OK, OK. A lot of it is very inspired by like a lot of your work. Yeah. OK, well, this is great. So basically there's a crypto camera and then chain of custody, ledger of record, public verification.

27:56Exactly. This is exactly the stuff that I've wanted out there for whether it's scientific experiments or something. Keep going. I'm listening. I know this. Say what you're going to say.

28:05Uma Roy:Yeah, yeah. I mean, and yeah, like all credit words do. I think you identified that this is the solution maybe like five years ahead of its time, five years ahead of the problem. And you're always very ahead of your time. So a lot of this stuff is like very inspired by your work. And I think there's a lot of other, like I think Mark Andreessen has talked about this actually, and I'll get to this later, like the head of Instagram is now talking about this. But yeah, okay. Just to get into what is a provable tech stack. So at capture, things are captured on hardware devices. Hardware devices can have private keys that are binded to the device.

28:41Uma Roy:So you have a cryptographic chip with the key. That's kind of how you can think of it. And basically, like as the raw sensor data is coming into the camera, the cryptographic chip signs like the content of the raw sensor data, and it binds like the content being captured to the specific device time and location. So that's cryptographic capture. Then as the content gets edited, you have this like chain of custody and chain of edits. So there's a cryptographically signed manifest for every transformation you do, whether it's like cropping or color correction or grading or things like that. And you basically keep this append only record of what's going on to the image.

29:21Uma Roy:and then finally you publish the piece of content and the manifest of the original signature when it got captured to the chain of edits and you publish that to a unbiased permanent ledger which is like this ledger record and then when the content actually gets consumed so it's like in some front end whether it's youtube or instagram or x um the front end integrates with the ledger and it basically verifies all the signatures, verifies they're real and displays that information to the user. And if the user wants more information, they can just click and verify all the signatures for themselves.

30:01Uma Roy:So today on most content platforms, we have the blue check mark for your verified identity. You can imagine in the future, maybe all content comes with a pink check mark that says, hey, this content is actually real and here's the device and here's the series of transformations that happened to it. Mm-hmm. Very cool. So, okay, keep going. So, yeah, this is the provable tech stack, and this is, like, all the stuff we're building at Succinct. And, yeah, I think, to your point, you talked about this for a really long time, which is, like, very cool. And I think, finally, like, other people are starting to catch on because, like, the problem is finally very evident.

30:40Uma Roy:So, there's this quote from Adam Masseri who runs Instagram. Cryptograph, please sign a capture. Yep. So yeah, he posted at the start of 2026, he posted like, hey, here's Instagram's like kind of what we're thinking about, what I'm thinking about right now. And he says that basically we're going to move from assuming what we see is real by default to starting with skepticism. So he's kind of identifying this like AI mix everything fake problem. And then he said, okay, platforms like Instagram will do good work identifying AI content, but they'll get worse at it over time as AI gets better. it will be more practical to fingerprint real media than fake media.

31:18Uma Roy:And then this is kind of like the thesis of Prove What's Real and all this cryptography stuff. Camera manufacturers will cryptographically sign images at Capture, creating a chain of custody. So, yeah, I mean, even like people like Adam who are running Instagram are saying that crypto is going, cryptography is going to be the solution to this like AI, the problems that AI creates for like content platform. That's right. Now I think actually crypto social and AI are all interlinked here because another piece of this, which is actually implicit in like the first part of what he's saying, starting with skepticism, pay attention to who is sharing something and why.

31:58I think actually AI and crypto together are going to result in, you know, like, you know, I think the future is China versus the internet. Did we talk about that? Have you heard me say it, talk right about that?

32:12Uma Roy:I've heard you say a little bit about it. So I think the future is a billion person Chinese super state or a thousand million person network states. Why? Because everybody thinks about AI improving productivity, but that was only true within a tribe where you can trust, you know, you can share information. And whether you call it indexing or surveillance, right? Because one is good and one is consensual and one is bad and one is not, right? So it is indexing everything and it's learning everything and it doesn't really miss like a single remark somewhere. AI can pull out a remark from like three years ago and surface it and synthesize in a way that no human, you know, or you'd have to have a very attentive, smart human.

32:56It was human limited, that level of surveillance from before, right? Right. So, or that level of synthesis, you know, the look over every commit and find security holes from years ago. It's amazing. Right. But that operates within the tribe. Outside the tribe, it's spam, it's scams, it's slop. Right. And so basically the cost of production goes way down, but the cost of verification goes way up. And so this part about paying attention to who is sharing something and why, I think another big piece of this is web three of trust. So you take web of trust, like I trust you because I know you and I've known you in person.

33:40And when you cryptographically sign something on a camera, there is the human part of that as well as the machine part. like ultimately if i wasn't actually there with you in the room i have to trust at some point some human assertion that this data because i can see it on chain that it was stamped at this time and um there's various proofs that one can put on there like proof of location proof of this proof of that but ultimately at like you as a human have to tell me that you didn't manipulate it before you cryptographically signed it, like you, because you could do something upstream, like the analog hole upstream, you know, the equivalent of putting something in front of the camera, right?

34:23And we can make it hard to do that, but we can make it impossible to do that. And unless like every single camera has one of these, and I think maybe it'll get there eventually, but there'll also be a demand for those things that don't have these, kind of like burner phones, you know what I mean, right? And so, and there's so many phones out there, there's billions of phones that do not have crypto chips in them that, just like you can get an old laptop, you could get a fakeable phone, right? And people will also revolt against too much tracking or what have you. They want it to be free, whatever.

34:56Anyway, I think that's another piece of this is the full supply chain of custody includes the person who's sending it to you. And so who is sharing something and why? If they're within your crypto tribe, crypto thinks tribally natively and ai is going to make people think tribally necessarily and so everything reduces to digital tribes where digital borders and physical borders become the same and china is the biggest digital tribe of all because they can centrally moderate all of their chat apps and so on and so forth like they just whatever ai detection stuff they roll out and we chat they can force human verification and so on and say i have just a central choke point where basically a billion people get onboarded into whatever AI detection, prevention, fake detection thing that they want, but the rest of the world doesn't have the same level of, I mean, Google and others can roll out certain levels of things, but they've almost opted for a more anarchic standard because of the whole freedom of speech fight, right?

35:56Which I get, but there's a undercorrection and an overcorrection on anything. And what you want is consensual moderation, I think. Anyway, so it's a compliment to what you're saying. Keep going.

36:05Uma Roy:Um, yeah, I, I think what you're, I think in the future, like it's not, I don't imagine a future where every photo posted Instagram is required that it's real. Cause like, I mean, some AI pictures are really cool or like really interesting. I think it's more like to your point of consensual moderation. It's like, if you want to prove something's real, and I think a lot of people deeply care about that, well then now you finally using cryptography actually have the tools to do that. And then, yeah, if you want to follow content creators that have those capabilities or only post real stuff, you can do that.

36:41Uma Roy:And then, you know, social media is one thing, but obviously for things like journalism, I think Nikita Beer, who's the head of product at X, tweeted about this. There's these accounts posting totally fake pictures from the Iranian war, and it's like pretty bad and like people are getting misinformed. And so obviously that's like not OK. And I think this sort of technology, I'm hopeful will help with much higher stakes situations like that, or, you know, political ads or like what the president is saying or things like that, I think will be really important to like prove what's real there. Great.

37:12Okay, cool. All right, keep going. Cool.

37:15Uma Roy:I mean, yeah, I think the rest of the slides are just like a little more detail about what's going on. So already today, you said, you know, how many cameras actually have this cryptographic chip. Well, fun fact, every single iPhone does have a secure enclave that has this capability. And so, you know, interacting with these enclaves across all the device types is really hard. And so we've built this SDK to kind of provide a unified experience for people who want to use it. Is it free? How does it cost? How much does it cost? Yeah, yeah. The SDK, well, it's not published yet, but we're going to publish it.

37:49Okay. I want to try, I will commission some apps on this once you publish this.

37:53Uma Roy:Oh, okay. Yeah, yeah. That'll be cool. So that is actually the foundation of a new kind of media. Yes. Yeah, yeah. Yes. Yeah. I think there is a lot of potential there. I think incentivizing decentralized media collection in an AI first, crypto first, social first, mobile first, internet first way, this is like a missing piece of that. Where we have all of these, quote, reporters from around the world. and on any topic that we care about, we can incentivize first party reporting where we pay in crypto and we verify in crypto, where we pay in cryptocurrency and verify with cryptography. We essentially have like a decentralized news outlet.

38:39So this is something that I want to get going and maybe we can collaborate on this. We can talk about this right after this.

38:44Uma Roy:Yeah, that would be very cool.

38:49Uma Roy:And yeah, with citizen journalism, Like you kind of, well, especially now with the AI generation stuff, you actually do need a way to verify that it's actually real. And so I totally agree with this. And I think we would focus it on the news of the network state and startup societies and cryptocurrency and technology, biotech, areas that I think are not well covered but should be because they are for tech decision makers. because the thing is news is a huge topic, right? And rather than the news of the state, we'd focus on the news of the network and those types of things that are, like with a relatively small amount of money, you could get much more coverage of them because they're more important for technical decision makers.

39:37And that's kind of the niche that all of these tech outlets basically abdicated. And actually in part, the reason they abdicated is because a full-time journalist is, like a professional journalist, is often somebody who doesn't actually know technology because if they did, they wouldn't be a full-time journalist. They'd be actually like a player on the field, right, building. So, moreover, by being a, quote, full-time journalist, they're loyal to the journalist tribe as opposed to the technologist tribe, and technologist tribe is taking away revenue from journalist tribes, so a lot of their coverage is very hostile.

40:14So the way we solve both of those problems, in my view, is rather than one full-time journalist making, I don't know, 50K, whatever it is, we have 50 part-time journalists who earn$1 ,000 bounties for writing up what they know. And because they have domain knowledge, if they write up one article a year, we're good.

40:34Uma Roy:Right. So that's like NS News. And so maybe we can integrate. Yeah, yeah. Yeah. Okay, yeah. We should talk about that. Yeah, you can build that with our stuff now. It's like pretty, the whole point of that is it makes it easy. Okay, great. Go, keep going and let's talk more. Go. Cool. Yeah, then there's the provable edit history part where after you get the provable capture, you do all the stuff you want to do with it. And there's actually these existing standards for it called C2PA, which kind of tracks, which is a metadata standard that kind of tracks, okay, who, what series of edits did you do?

41:07Uma Roy:What production did you do? And then it appends it to a manifest. and then finally after you've kind of compiled the proof of capture the proof of edits um it gets published to this thing which you came up with this name the ledger of record which uh is this like open unbiased you know place where all this content gets published and then that's where all the content that gets displayed in front ends so for example instagram or x or whatever it can read from this ledger, which is basically just a database of like what is actually real or not. So that's kind of our vision for provable technologies and like the whole stack.

41:53Uma Roy:And yeah, we kind of imagine that this stuff will show up one day in every single app, every single real picture on the internet will have a pink checkmark that says it's real with all the signatures and all the cryptographic proof. And you can, anyone viewing a picture can just look at that and know what's actually real. So that's our kind of vision for how cryptography is going to solve a lot of the problems posed by AI. Amazing. Okay. So, um, people should go to succinct.xyz? Yeah. People can go to succinct.xyz, um, or follow us on Twitter at Succinct Labs. And we will be posting, we're building this whole stack and we're going to be releasing like a lot of products and related technologies, you know, in the coming months.

42:44Okay, awesome. Okay, so...

42:48Uma Roy:It'd be interesting to hear kind of your vision for how you think this is going to like be put into the world or like, you know, you've been talking about these ideas for so long. I'm just curious to know like more about why I got what got you excited about it and like how you think this is going to like proliferate. Sure. So, um, well, what got me excited about this? Um, you know, in the nineties, like, you know, when I was, I was a kid then, so I'm about maybe 10, 15 years older than you, something like that. Uh, or I mean, I, I would never presume to know your age or whatever, just saying like probably, probably in that ballpark, right.

43:23In the nineties, nobody cared about politics. It was something where it was literally being interested in politics was like being interested in the train tables or the bus schedule or something like that. And it was genuinely something, why would you care about this legislative, this and that? No one cares. And you cared about music, movies, sports, video games, whatever, right? It was just a vacation from history. And so for much of my life, I was essentially just an apolitical academic. And all I care about was math, computer science, bioinformatics, all that kind of stuff. And then after essentially the full political breakdown of arguably, you can argue when it started 2001, 2008, 2015, 2020.

44:21Everyone's got a different moment, right?

44:26There's a saying, which is an amazing tweet, if the news is fake, imagine history. Okay. And you actually start realizing a lot of the movies in the 90s were almost like the collective unconscious was putting out movies like The Matrix, Eternal Sunshine of the Spotless Mind, The Game, Dark City, Fight Club, 12 Monkeys, all of which were essentially about your memento, right? Your memory playing tricks on you. And in some sense, the world was not what it seemed, right? The Truman Show, right? The Truman Show, The Matrix, all of these are like you're living in a constructed world, right? Memento, your memory of the past isn't the same, right?

45:15And it was as if like almost the collective world was waking up to realize that the centralized century of the 20th century was an illusion in some ways, and that there was more to the past and they'd sort of been, you know, hypnotized, zombified or what have you. And so putting those together, you know, I started asking questions like, how do we actually know what's really true? Like, let me give an example, maybe a seemingly trivial example, but this is in the network state book. Let's even take F equals MA. How would you actually know that's true? If you track it all the way back, ultimately there are scatter plots.

45:58You know, when people rolling balls down inclined planes, right, where they are taking X and Ys and correlating them and then effectively doing a line fit that is then generalized into this deterministic physical law, right? Underpinning everything that we think is true is ultimately a set of observations that you could track all the way back to Newton, like, you know, the famous, you know, apocryphal apple falling down, right? Like what you think you know is true, if you can track back all the citations all the way back to root, that's the reason that we think it's true. Why is that actually sometimes important to do?

46:37Well, I'm forgetting, this is a whole complicated story. And I think it's something like, there's a story about vitamin C, I believe, in medicine. I'm probably getting this wrong and I'll look it up, but it's like vitamin C supplementation, but it's, what was it, spinach? There's a whole medical story. Hold on, let me find this. The iron myth, right? Spinach is a good source of iron, right? And this is one of those things where somebody tried to track it back and it was either this or something else where when you tried to track the citations all the way back, It was a complicated mixture of multiple mistaken citations on top of each other.

47:28I think this is it here.

47:39Look at this.

47:44The sudden thing. I think this is it.

47:46Uma Roy:Um, basically the complex and convoluted myths is the one call for want of a less complex name, the iron decimal point error myth.

48:00And essentially it is a decimal error knowledge gap. It's like a myth piled on top of a myth. It's like something complicated enough that I have to go and remember it. Right. You can look at this document. The point being that that is a concrete example of something where someone literally dug through every citation going all the way back, and they found that the thing that people thought was solid was actually based on nothing. right? All kinds of social science has failed the reproducibility crisis in this way, right? So all kinds of political science, history, social science is something where now with LLMs, we can back solve and go all the way back, right?

48:51Because it's much better search, right? So you can track it all the way back to all the original citations behind the claim, right? You can push it pretty hard to do that deep research, whatever you want to call it. Like, you know, the team of agents thing that Grok has can pull like a thousand sources or something like that much faster than a human can. And so now we can really, remember that Trugel thing that I was talking about?

49:12Uma Roy:Yeah. We can really start interrogating. It's almost like the, you know, the Bertrand Russell program in math of really trying to put math on an axiomatic basis, right? And really trying to have as few axioms as possible. He builds the whole thing from set theory. And I think it's like on page 347, he says, and thus we prove that one plus one equals two. You know the thing I'm talking about, right? It's like a famous thing in math, right? So you're probably aware of it. So like that, I realized how ignorant I was about what had actually happened in the past, about what scientific facts were actually true, about how scoped my knowledge was.

49:54And I started to ask what, I know this is a longer answer than you wanted, but this led me to this, right? It's like, I was like, you know, as a research scientist, and you're a research scientist also, we're in the unusual position of being pre-headline people. And what I mean by that is, like, this was more true on the Twitter of like five years ago, but there's a fair number of, let's call them normie NPC type people who genuinely cannot believe something is true until it's appeared in a headline. That is to say, until NYT or the State Department or something like that, their implicit epistemology was, is a reputable source saying it?

50:37If so, then true. If not, then false. Now, this was always bizarre to me because as a research scientist, you're used to figuring out if something is true on your own using logic and reason. And eventually I was able to figure out this difference between pre-headline people and post-headline people. A pre-headline person, you have some scientific finding and you are going to publish it and you are actually the upstream source of that finding. Like the press release will be based on your paper, right? Or conversely, you have some VC investment round and you know something is true before the world knows it's true.

51:14So you're actually upstream. It's like a miner. You're mining truth before it's being sold at the market. However, you realize that actually the guy who's a post-headline person has some wisdom all his own because he implicitly, I'm not saying they're doing this explicitly, they kind of know that you can only be a pre-headline person in so many areas. Right. Like you can't be an expert on Turkish and Japanese and I don't know, Brazilian iron ore and so on and so forth. Much of what you're sensing is going to be essentially on some web three of trust, which is based on some information supply chain.

51:49Right. Anyway, it was through thinking through things like this and how we build a higher standard of truth that got me to where we were. Let me pause here.

51:59Uma Roy:Interesting. um yeah i guess you've been thinking about this for a really long time and then i think we've been thinking about this for honestly maybe the past three to six months as we saw the ai problem get worse and worse and there's this interesting asymmetry i mean our team is based on software there's so many smart people working on accelerating all this ai stuff which is really good there's obviously incredible positive externalities. But I think if there's a technology that's genuinely so powerful, obviously, it's going to have negative externalities. And I think there's very few people focused on combating these negative externalities.

52:40Uma Roy:And I think in this domain, with the pictures and images and fake audio, and, you know, that poses real problems. And I do think this is an area where the combination of cryptographic hardware, cryptographic software, chain of trust, custody, ledger record, provable technology broadly as a category can actually help some solve those negative externalities. Amazing. Yeah, that's how I got to it. But you got to it much earlier than all of us, which is kind of your specialty, which is very cool. Well, thank you. But I appreciate you also grinding through all the details to actually build the SDK and so on, because obviously that's non-trivial.

53:25So let's talk more about that. And Uma, thank you for coming on Never See a Podcast.

53:31Uma Roy:Thank you for having me.

From the publisher

Uma Roy is a cryptographer and cofounder of Succinct. We discuss how zero knowledge acts as a defense against AI, the challenges with AI detection tools, and how crypto makes digital media real again. If you are interested in the intersection of AI and cryptography, apply to Network School at https://ns.com.

More from The Network State Podcast

All 27 episodes
#37 - Uma RoyThe Network State Podcast · 54 min
Listen in VO