Three-Layer Forensic Fingerprinting for Insider Leak Attribution: Robust Tracing, Tamper Localization, and Content Binding

To address the challenge of insider leak attribution, this paper presents a three-layer DCT-domain forensic fingerprinting architecture that jointly provides: (i) robust user tracing via QIM-embedded fingerprints with Reed-Solomon error correction; (ii) key-shared tamper detection with block-level localization; and (iii) cryptographic content binding that rejects transplant attempts. All three layers are embedded in a single pass over disjoint DCT bands to prevent interference. Evaluated on 138 benchmark images, the scheme identifies the correct leaker in every benign test, flags every tested manipulation with 0.46-0.88 IoU, completely blocks transplant attempts, and identifies colluders in averaging attacks with zero false positives. Finally, a forced trade-off analysis demonstrates that erasing the fingerprint necessarily destroys the content (dropping quality to at most 25.2 dB PSNR) or triggers a full tamper alarm, proving that no clean, untraceable copy can be laundered.