End-to-End Trust Chain for Image Verification
Budget: $8 – $15 USD
Will only hire high level profiles. Nothing sent without NDA.
Develop an end‑to‑end “trust chain” that captures, verifies, analyses, and displays images.
3. Core Deliverables (modular)
1. Mobile Capture SDK
• Native Android + iOS wrappers (CameraX / AVFoundation)
• C2PA or equivalent manifest signing (hash, GPS, timestamp)
• Gallery import must be blocked; live‑view capture only
• Lightweight encryption & background upload (TLS 1.3, mTLS)
2. Image Forensics Micro‑service
• Error‑Level Analysis (ELA)
• PRNU sensor noise check
• GAN / deepfake classifier (PyTorch; ready for custom training)
• REST / gRPC endpoint; JSON score output
3. Deduplication & Similarity Search
• Perceptual hash (aHash/pHash/dHash) + FAISS index of CLIP embeddings
• API: query → returns matching IDs + similarity score
4. Vehicle & License‑Plate Recognition
• OpenALPR Community edition integration
• Make/Model classifier (MobileNet v3 or similar)
• VIN OCR (Tesseract or custom CNN)
5. Depth / Damage Estimation
• MiDaS depth map on each image
• Basic metric conversion (wheel diameter reference)
• Output JSON (meta + depth statistics)
6. Optional Physics‑Based “Plausibility” Module
• BeamNG.tech headless simulation via BeamNGpy
• Generate synthetic crash mesh → compare SSIM / LPIPS
7. Back‑End Orchestration
• FastAPI (Python 3.11) micro‑services
• Celery / Redis for async jobs
• Docker‑compose → Kubernetes Helm charts
8. Admin & Investigator Dashboard
• React + Tailwind UI
• Claim table, image viewer with heat‑map overlay, anomaly timeline
• Simple Neo4j graph visual (D3.js) for cross‑claim links
9. Security & Compliance
• Zero‑trust network: mTLS, cert‑pinning, OAuth2 / OIDC (Keycloak)
• Vault‑managed secrets
• Immutable logging (Loki, S3 Object‑Lock)
• Supply‑chain scanning: Trivy, Semgrep, SBOM
10. CI/CD & Documentation
• GitHub Actions (build, test, container sign via Cosign)
• README + Swagger/OpenAPI specs for each service
• Architecture diagram & run‑book
4. Expected Skill Set
• Python (deep‑learning + FastAPI)
• Mobile native (Kotlin, Swift)
• Computer Vision / OpenCV
• Docker & Kubernetes
• React / TypeScript
• DevSecOps fundamentals
5. Confidentiality Note
• Full workflow, datasets, and business context disclosed only after NDA signature.
• No third‑party subcontracting without written approval.
• Code ownership transfers upon final payment.
Develop an end‑to‑end “trust chain” that captures, verifies, analyses, and displays images.
3. Core Deliverables (modular)
1. Mobile Capture SDK
• Native Android + iOS wrappers (CameraX / AVFoundation)
• C2PA or equivalent manifest signing (hash, GPS, timestamp)
• Gallery import must be blocked; live‑view capture only
• Lightweight encryption & background upload (TLS 1.3, mTLS)
2. Image Forensics Micro‑service
• Error‑Level Analysis (ELA)
• PRNU sensor noise check
• GAN / deepfake classifier (PyTorch; ready for custom training)
• REST / gRPC endpoint; JSON score output
3. Deduplication & Similarity Search
• Perceptual hash (aHash/pHash/dHash) + FAISS index of CLIP embeddings
• API: query → returns matching IDs + similarity score
4. Vehicle & License‑Plate Recognition
• OpenALPR Community edition integration
• Make/Model classifier (MobileNet v3 or similar)
• VIN OCR (Tesseract or custom CNN)
5. Depth / Damage Estimation
• MiDaS depth map on each image
• Basic metric conversion (wheel diameter reference)
• Output JSON (meta + depth statistics)
6. Optional Physics‑Based “Plausibility” Module
• BeamNG.tech headless simulation via BeamNGpy
• Generate synthetic crash mesh → compare SSIM / LPIPS
7. Back‑End Orchestration
• FastAPI (Python 3.11) micro‑services
• Celery / Redis for async jobs
• Docker‑compose → Kubernetes Helm charts
8. Admin & Investigator Dashboard
• React + Tailwind UI
• Claim table, image viewer with heat‑map overlay, anomaly timeline
• Simple Neo4j graph visual (D3.js) for cross‑claim links
9. Security & Compliance
• Zero‑trust network: mTLS, cert‑pinning, OAuth2 / OIDC (Keycloak)
• Vault‑managed secrets
• Immutable logging (Loki, S3 Object‑Lock)
• Supply‑chain scanning: Trivy, Semgrep, SBOM
10. CI/CD & Documentation
• GitHub Actions (build, test, container sign via Cosign)
• README + Swagger/OpenAPI specs for each service
• Architecture diagram & run‑book
4. Expected Skill Set
• Python (deep‑learning + FastAPI)
• Mobile native (Kotlin, Swift)
• Computer Vision / OpenCV
• Docker & Kubernetes
• React / TypeScript
• DevSecOps fundamentals
5. Confidentiality Note
• Full workflow, datasets, and business context disclosed only after NDA signature.
• No third‑party subcontracting without written approval.
• Code ownership transfers upon final payment.