Skip to main content
CrossCoach
Sign inRequest access
A close human portrait filling a near-black frame, split down the middle by a hard seam: the left half a crisp, cleanly captured face, the right half tearing apart into corrupted pixel blocks and a magenta-and-cyan RGB-split fringe, as if the same face cannot decide whether it is a real photograph or a synthetic one.
Reading · Image authentication

Image Authentication: What Can the File Establish?

Before asking who appears in an image or recording, the court may need to know how the file was made, altered and preserved. Six sections set out what current methods can establish and where they fail.

16 min readBased on the the image-authentication and deepfake research
I

The first question is whether it happened

A CCTV still, phone video or recorded confession now raises a question before identification: does the file depict a real event, or was it generated or altered?

Maura Grossman and Paul Grimm, writing in the Columbia Science and Technology Law Review in 2025, describe the change between 2014 and 2024. Generative AI became widely available and capable of producing synthetic images, audio and video that, in their words, make it "nearly impossible, even for computer scientists, to tell authentic from fake content." A voice clone was used to obtain nearly £200,000 from a UK energy firm in 2019. In 2024, a Hong Kong finance worker paid US$25.6 million after a video call in which every other participant was a deepfake.

A fabricated exhibit may be accepted as real. In December 2023, a recording apparently capturing a Pikesville, Maryland high-school principal making racist remarks led to threats and his suspension. Forensic analysis later identified "traces of AI-generated content with human editing after the fact." The athletic director who created it was charged.

The reverse problem is the "liar's dividend," named by Robert Chesney and Danielle Citron in 2018. Awareness of convincing fakes allows a person to dismiss authentic evidence as synthetic. Defendants in U.S. v. Doolin and U.S. v. Reffitt suggested that video from 6 January might have been deepfaked. Tesla's lawyers argued that recorded statements by Elon Musk about autonomous driving might be fake, an argument Judge Pennypacker rejected.

Authentication can therefore fail in either direction: a fabrication may be accepted, or authentic evidence may be rejected. The threshold for admission of audio or video is relatively low; the proponent must show that it is "more likely than not" what they claim. Once a jury has seen the material, a court "cannot unring this bell."

The examination may involve container structure and metadata, PRNU sensor patterns, copy-move traces and detector output. Each method answers a narrower question than is this image real? The task is to explain what the file supports without turning a technical finding into a verdict on the event depicted.

Once this audio evidence is heard by the jury, the effect is often permanent and indelible. Dissimilar to an instruction to strike or ignore something, a court cannot unring this bell.
Grossman and Grimm, Columbia Science and Technology Law Review (2025)
A data plate: the giant figure '$25.6M' paid by a finance worker after a video call in which every other participant was a deepfake.
Fig. 1 · Is the image even real? In 2024 a Hong Kong finance worker paid US$25.6 million after a video call in which every other participant was a deepfake — the question of whether a file depicts a real event now comes before who is in it.
Challenge 01 · Put it to the test

Prove it was not AI

Counsel sets down the exhibit, leans in, and frames the impossible demand.

The question

"Mr. Analyst, you cannot prove this video was not generated by AI, can you? You can only tell us you found no sign that it was."

Your answer
II

Three layers, three different questions

An authentication opinion may combine three examinations, each answering a different question.

Pixel analysis looks for traces of editing. A spliced region may have a compression history unlike the rest of the frame, producing JPEG "ghosts" after recompression. Copy-move forgery can leave unusually similar regions. Resampling may produce periodic correlations between neighbouring pixels. Error-level analysis identifies areas that compress differently. Each technique depends on assumptions. Chen, Fridrich and Goljan write that a method "only works when specific assumptions are satisfied and will fail if the assumptions are not met," and that digital forgery detection is "a complex problem with no universally applicable solution." The report should identify the tools used, their findings and the alterations they may fail to detect.

Sensor analysis asks whether an image carries the photo-response non-uniformity (PRNU) pattern associated with a camera. Chen, Fridrich and Goljan (2008) describe PRNU as "a unique authentication watermark involuntarily inserted by the imaging sensor." A reference pattern is estimated from images, ideally defocused views of a cloudy sky, then compared with the questioned image using a Neyman-Pearson hypothesis test. The decision threshold is selected for a chosen false-alarm rate, and the probability of falsely rejecting a true correspondence is reported. Block-by-block analysis may identify regions in which the sensor pattern is absent. An alteration that preserves the noise, such as recolouring a stain, may not be detected.

Container analysis examines the file structure rather than the visible picture. Iuliani et al. (2019) analysed the arrangement of atoms such as ftyp, moov, mdat and trak in MP4 and MOV files. Devices and applications produce different structures. Their method compared a questioned file with native references from a claimed device. On 578 native videos in the VISION dataset, plus social-media copies, it achieved an AUC of 1 for videos altered by WhatsApp, YouTube or FFmpeg. FFmpeg can cut a clip without re-encoding the pixels, leaving stream-based methods with no change to detect while altering the container. Device-brand attribution was expressed as a likelihood ratio. Container analysis may remain possible when image quality is too poor for pixel methods.

The three questions are therefore distinct: what traces exist in the pixels, whether a sensor pattern is present, and how the file was constructed.

Each method only works when specific assumptions are satisfied and will fail if the assumptions are not met. Obviously, digital forgery detection is a complex problem with no universally applicable solution.
Chen, Fridrich, Goljan & Lukáš (2008)
A data plate listing three examinations, each a different question: pixels (what was edited?), sensor PRNU (which camera?), and container (how the file was built?) — each narrower than 'is it real?'.
Fig. 2 · Three layers, three different questions. An authentication opinion combines what the pixels show was edited, whether the sensor fingerprint is present, and how the file was constructed — each a narrower question than "is this image real?"
Challenge 02 · Put it to the test

Which method gave a yes or no?

Counsel walks the analyst back through the report, method by method.

The question

"You told the jury this image is authentic. Did any of your three tests return a definitive answer? Your report says the camera-fingerprint test used a threshold. What is its error rate, and where is that figure reported?"

Your answer
III

A negative result is not proof

Dirik and Karakucuk estimated the sensor pattern from fifty Sony DSC-H50 images and then removed it. The mean peak-to-correlation energy fell from 5621.94 to 6.29, below the decision threshold of 50. Across six further cameras, including a Canon EOS 1100D, Nexus 4 and Samsung S3 Mini, the method anonymised about 99% of images while retaining image quality near 34 dB PSNR.

The method subtracts a scaled noise estimate, typically using a factor around 3.0, until correlation with the source camera collapses. It requires images from the camera but not physical access to it. Related methods can transfer another sensor pattern into an image. A PRNU association may therefore be manufactured, and a true association may be concealed, without an obvious visual change. That possibility must be considered when interpreting either a positive or negative result.

Pixel-level traces such as JPEG ghosts, resampling and double compression are rewritten when a file is exported or uploaded. Yang and colleagues measured the effect on container traces. Their EVA method achieved 97.6% accuracy distinguishing pristine from tampered video, including clips cut without re-encoding or reduced to thumbnail size. After processing by Facebook, TikTok, Weibo and YouTube, accuracy fell to 0.76, 0.80, 0.79 and 0.60 respectively. On YouTube, the true-negative rate for correctly flagging tampered video was 0.36. The authors write that "the social media transcoding process that flattens the containers almost independently on the video origin." After YouTube processing, videos edited with Avidemux and Exiftool had identical container representations.

Metadata is also readily changed or removed. Yang's team altered a video date with a single Exiftool command: exiftool "-AllDates=1986:11:05 12:00:00".

A finding that no manipulation was detected does not prove authenticity. It is compatible with an unaltered image, but also with an altered image whose traces were removed by anonymisation or social-media processing. The conclusion should be expressed as the absence of detected indications under the methods and conditions used.

After YouTube transcoding, videos produced by Avidemux and by Exiftool have exactly the same container representation.
Yang et al. 2020, Efficient video integrity analysis through container characterization
A data plate: a camera's sensor-fingerprint strength of 5,621.94 dropped to 6.29 after anonymisation — far below the decision threshold of 50, with no visible change.
Fig. 3 · A negative result is not proof. The same technique that reads a camera fingerprint can erase it: one method dropped the sensor-pattern correlation from 5,621.94 to 6.29 — below the threshold of 50 — while keeping the picture looking untouched.
Challenge 03 · Put it to the test

Authentic, or just laundered?

Counsel holds up the report at the line that reads "no signs of manipulation."

The question

"Your report says you found no signs of manipulation. Published methods can remove those traces, and YouTube processing may destroy them. Can you distinguish an image that was never altered from one in which the alteration is no longer detectable?"

Your answer
IV

A benchmark score is not a casework error rate

In 2019, Andreas Rössler and colleagues released FaceForensics++, containing more than 1.8 million manipulated facial images produced by DeepFakes, Face2Face, FaceSwap and NeuralTextures. Their XceptionNet detector achieved 99.26% binary accuracy on raw video. That figure describes performance on manipulations and conditions represented in the dataset.

With low-quality H.264 compression, accuracy fell from 99.26% to 81.00%. On a held-out benchmark that recompressed and resized videos in unknown ways, the low-quality model achieved 70.10% overall accuracy, while precision for pristine images fell to 52.40%. Performance on unfamiliar processing conditions was therefore substantially poorer than the headline benchmark.

Dell'Anna, Montibeller and Boato built TrueFake in 2025: 600,000 images from GANs and diffusion models, including 180,000 processed through Facebook, X and Telegram. Five current detectors scored at least 0.93 on image classes represented in training. On unseen StyleGAN3 images, three of four CNN detectors produced true-positive rates of 0.00, 0.02 and 0.00. After Facebook sharing, the NPR detector's fake-detection rate fell to zero for StyleGAN images. Across all detectors, Facebook produced losses in true-positive or true-negative performance ranging from 10% to 100%. CLIP-D performed best but still lost about 10% or more on half the image classes after social compression.

Spreeuwers et al. found a similar problem in face-morph detection in 2022. An LBP/SVM detector had an equal error rate of about 2.5% within one dataset. When trained on FRGC and tested on the different ARF set, the rate rose to 80%. Visually imperceptible Gaussian noise increased within-dataset error from below 5% to above 20%, and down-up scaling raised it above 12%. Every algorithm tested failed the hardest cases in the SOTAMD benchmark, which used seven morphing tools and print-scan variants.

These systems may learn traces of the generation and processing pipelines represented in training. A new generator or social-media recompression can remove or change those traces. A benchmark result is therefore not an error rate for an exhibit produced and processed under different, unknown conditions.

The cross dataset performances were much worse than the within dataset performances ... the EER of the LBP-SVM1 and LBP-SVM2 methods increases to 80% resp. 79%.
Spreeuwers et al. 2022, Sec. 16.6.2
A data plate: a leading deepfake detector scored over 93% in training but a 0% true-positive rate on an unseen generator (StyleGAN3) — a benchmark score is not a casework error rate.
Fig. 4 · A benchmark score is not a casework error rate. Detectors that scored over 93% on the image classes they were trained on caught 0% of fakes from an unseen generator — performance collapses on the unknown conditions of a real exhibit.
Challenge 04 · Put it to the test

Where was 99 percent measured?

Counsel writes the headline accuracy figure on a board and turns back to the witness.

The question

"You quoted accuracy above 99%. Was that measured on material like this clip, from an unknown source and compressed by a social-media platform, or on test videos resembling the detector’s training data? What is its error rate on an exhibit like this one?"

Your answer
V

What a provenance credential does and does not prove

C2PA records an image's provenance as it is created and edited. A camera may sign an origin manifest at capture. Editing software can add an active manifest, and a publisher can sign another step after compression or captioning. The record combines assertions, cryptographic hashes and X.509 certificates. Leonard Rosenthol, chair of the C2PA technical working group, said in 2022 that, unlike detection, "it's not an arms race." The system records who handled a file and when instead of inferring manipulation from artifacts.

Golaszewski, Krawetz, Sherman and colleagues at UMBC, Hacker Factor and the NSA later conducted an independent security analysis. Their executive summary concludes that current C2PA specifications "fail to achieve their claimed security goals."

They reported several weaknesses. Signed data did not cover its own timestamp, allowing the timestamp to be changed. Verification tools were not required to check certificate revocation. A Nikon certificate revoked in November 2025 was still accepted by Adobe's checking tool six months later, while another tool rejected the same file. Some file fields could remain outside the signed region; on one phone, that included GPS location, allowing a false location to be inserted and displayed as certified. Credentials could also expire: a US election-office pilot image that validated in January 2025 failed a year later despite no change to the file.

The report states the central limit: "C2PA provides provenance signals, not proof of authenticity." Provenance describes the recorded history of a file. It does not establish that the scene depicted occurred. A signed manifest can accompany fabricated content, while the absence of a credential proves little because many exhibits were never signed.

Williams and colleagues at Liverpool John Moores also showed that examination tools may change a file. Magnet Copilot AI produced a content-identical copy of a known synthetic image with a new inode-change date and different permissions. The pixels had SSIM 1.0, but the operating system treated it as a separate file. They also discuss Matter of Weber (October 2024), where a court rejected an expert's use of Microsoft Copilot for lack of repeatability. Provenance can assist with media signed at capture, but the original should still be preserved and tool effects documented.

C2PA provides provenance signals, not proof of authenticity.
Golaszewski et al., Verifying Provenance of Digital Media (2026)
A data plate contrasting what a content credential proves (who signed the bits, and when) with what it does not prove (that the depicted event occurred), noting C2PA provides provenance signals, not proof of authenticity.
Fig. 5 · Signing the picture does not save the picture. A content credential records who signed the file and when — not that the scene depicted occurred. A signed manifest can accompany fabricated content.
Challenge 05 · Put it to the test

A valid credential, but real?

Counsel produces a file with a green "verified" Content Credential badge.

The question

"This exhibit carries a digital credential your report describes as valid. Does it establish that the depicted event occurred, or only that software signed the file? Can a revoked certificate still appear valid in a checking tool?"

Your answer
VI

Report the finding, not a verdict on authenticity

Onyekwere and colleagues reviewed ten leading deepfake-detection studies published between 2018 and 2025 against forensic evidence standards. None satisfied all of them. XceptionNet achieved 99.26% on FaceForensics++ but 65.18% on Celeb-DF when the manipulation method changed. MesoNet fell to 54.82%. None of the reviewed studies reported confidence intervals, and only 40% reported false-positive or false-negative rates. A detector flag is therefore not, by itself, a conclusion that an image is a deepfake.

SWGDE's Best Practices for Image Authentication (version 2.0, March 2025) says it is impossible to prove a negative. A thorough examination may support that manipulation or digital creation is unlikely. If alterations are detected, the practitioner may conclude that the imagery is not authentic. "No indications of manipulation were found" reports the outcome of the examination; it does not certify authenticity. SWGDE also warns that manipulation of a single still may evade a trained examiner and that a generated frame of a person may be indistinguishable to a human. A series of images or video may provide more information than one frame, and any limitation should be stated.

If the tool has a validated error rate for comparable casework conditions, report it. If it does not, say so. Onyekwere notes reported false-positive rates around 12.8% and explains that, at realistic prevalence, even a strong detector may produce many false accusations for each true one. A benchmark result should not be presented as a casework error rate.

Integrity and authenticity are also different. SWGDE says a hash can show that a copy is identical to the file from which it was made, but not that the depicted scene is true. Hash the file on receipt, preserve the original, examine a working copy and document the workflow contemporaneously. Those steps establish integrity and chain of custody, not authenticity.

Geradts, in the Interpol review of forensic video analysis for 2019 to 2022, distinguishes binary detection research from forensic evaluation. The expert explains what the analysis supports, sometimes through likelihood ratios, and the court determines the ultimate issue. SWGDE adds that numerical probabilities require a proper scientific foundation and should be expressed against stated propositions.

Supportable language includes: this image contains features consistent with manipulation; these features are unlikely under an unaltered capture; no indications of manipulation were found using the stated examinations; or the PRNU correlation supports capture by this device. Avoid converting those findings into this is a deepfake, this is authentic or an accuracy figure that has not been validated for comparable evidence.

The forensic expert does not pass a verdict on the authenticity of evidence, but explains using likelihood ratios and analysis from the models what the chances are of the video being authentic.
Geradts & Riphagen 2023, Interpol review of forensic video analysis 2019-2022
A data plate: a scale with two forbidden verdicts at the ends — 'THIS IS A DEEPFAKE' and 'THIS IS AUTHENTIC' — and the defensible finding held in the middle: 'features consistent with manipulation; no indications found'.
Fig. 6 · Report the finding, not a verdict. Defensible language stays between the two poles: "features consistent with manipulation", "no indications were found", "the PRNU supports this device" — never "this is a deepfake" or "this is authentic".
On the stand: what you can say, and what to swap it for

Each phrase on the left runs a "consistent with" finding up into a verdict the science cannot support. Swap it for the qualified version that says only what your examination actually showed. Grounded in SWGDE Best Practices for Image Authentication (2025) and the Interpol review (Geradts 2023).

What to carry into the witness box
  • 01Authentication is asymmetric. "I found no sign of manipulation" is a finding about your examination, not proof the image is real, and it is not exculpatory either. Absence of detected tampering is absence of evidence.
  • 02Your method is really three examinations: what happened inside the pixels, which sensor made it, and how the file was built. Each answers a different question, and each fails under its own conditions. Describe them separately.
  • 03The tools that read a fingerprint can forge one, and the pipelines that carry an image erase the traces. A PRNU "match" can be manufactured, and a single pass through YouTube can wipe the cues you were looking for.
  • 04A 99 percent benchmark score is an in-distribution recognition rate, not a casework error rate. On an unknown generator after social-media compression, the best detectors fall toward chance.
  • 05A Content Credential proves who signed the bits, not that the scene was real, and most exhibits carry none. The act of checking the file can itself alter the original.
  • 06Say "consistent with manipulation," "no indications were found," "the PRNU supports this device." Refuse "this is a deepfake," "this is authentic," and "the tool is right 95 percent of the time on evidence like this." Keep integrity (a matching hash) separate from authenticity (a true scene).
Challenge 06 · Put it to the test

Does that make the video a fake?

You are on the stand. Counsel has saved the simplest leap for last.

The question

"Your tool reports 95 percent accuracy and it flagged this clip as a deepfake. So you are telling the jury this video is fake, correct?"

Your answer
Ask the tutor

Still have questions about the research?

Ask anything about the image-authentication and deepfake research. The tutor answers from the document itself — and keeps one eye on how it might come up under cross-examination.

Your question
References
Next reading

Bite-Mark Comparison: Two Premises Under Test

Keep going

Counsel is briefed on this literature. Take it into the witness box and practise image & video authentication.