FORENSIC SCIENCE · INDEPENDENT EXPERT EVIDENCEAdelaide, Australia
RHEM LabsInstruct an expert

Synthetic-media forensics

Deepfake Detection vs Synthetic-Media Forensics: What Can Actually Be Established?

Deepfake is a broad label. A forensic conclusion must identify the medium, alleged alteration and origin proposition actually examined.

RHEM Labs

“Deepfake” names no single production process. It can refer to a face inserted into video, generated speech, a newly synthesised image or an edited photograph. A detector trained to recognise one of these cannot be presumed to recognise the others. The word is useful in an initial enquiry, but it needs to be replaced by a testable proposition before forensic examination.

An entirely generated still image raises a question about whole-image origin. Face replacement in an otherwise camera-recorded video raises a local manipulation question. Synthetic speech has an audio formation pathway and needs audio-specific methods. A fabricated caption attached to an unaltered photograph may instead be a provenance or context problem. These distinctions determine what material to preserve, what comparison population is relevant and what a result can mean.

Detection and examination ask different questions

Automated deepfake detection commonly produces a score or class label. A threshold then turns the score into a decision, with error rates determined by the tested population. The label is useful for triage if those rates and the input conditions are known. It does not itself explain who made the media, when an alteration occurred or whether an event represented in the image happened. NIST’s image-generation evaluation accordingly reports discrimination and error-related measures, including AUC, true-positive rate at a stated false-positive rate and calibration measures, rather than treating a detector label as self-explanatory.

Synthetic-media forensics examines the question at several levels. File provenance may identify a source or documented processing step. Content Credentials can bind signed assertions to an asset, subject to the trustworthiness and continuity of the provenance chain. Local image analysis may investigate a suspected edit. Media-origin analysis asks whether measurable image characteristics support a physical-camera process or synthetic generation. None of those enquiries automatically establishes human authorship.

Where SPOT fits

RHEM Labs’ SPOT research programme investigates the image-origin problem through characteristics associated with sensor-based capture. Its published experiment compared noise-residue measurements from a defined camera-image population with DALL·E imagery and evaluated their relative support for competing origin hypotheses. The paper and its reported limits are central to understanding what has actually been tested.

SPOT is relevant to AI-generated still imagery and the image-origin component of synthetic-media forensics. It should not be described as a general audio detector, a face-swap locator or a system that resolves all synthetic-video questions. A video frame may be examined as an image under an appropriate method, but that does not by itself validate a video-level conclusion. Likewise, a finding compatible with camera capture would not rule out a camera photograph of a generated display.

The distinction matters in reporting. “The file contains no verified provenance record”, “a classifier score exceeded its threshold” and “measured residue characteristics favour one specified origin hypothesis” are different observations. Their interpretations depend on acquisition, transformations and method validation. A report should preserve those differences, particularly when a broad allegation of “deepfake” has not identified the actual disputed mechanism.

Related research & reading

FORENSIC INSTRUCTIONS

A question about digital evidence?

For legal practitioners and professional organisations: discuss the forensic question, available material and timeframes.

Contact the laboratory