FORENSIC SCIENCE · INDEPENDENT EXPERT EVIDENCEAdelaide, Australia
RHEM LabsInstruct an expert

Synthetic-media forensics

How Can You Tell Whether an Image Was AI-Generated?

A practical reading of visual clues, metadata, Content Credentials and forensic measurements when the origin of an image is questioned.

RHEM Labs

The first useful question is which image file is being examined. A platform thumbnail, a screenshot and the file originally saved by a camera or generator may show nearly the same scene while preserving very different evidence of creation. The source file, if obtainable, should be kept with its original name and recorded transfer history; analysis can then be performed on a working copy.

Visual inspection can identify something that deserves explanation: repeated texture, inconsistent reflections, impossible geometry or a region whose rendering differs from its surroundings. It cannot reliably identify a generation process by itself. Some synthetic images have no conspicuous anomaly, and conventional capture or editing can create similar appearances. An “AI image” verdict based on a strange hand or implausible shadow confuses a clue with a conclusion.

Ask what the file records

Embedded EXIF or other metadata may describe a camera, software and times. Those fields are useful if their origin and preservation can be established. They can also be rewritten by ordinary export, stripped by a platform or copied into another file. A camera-model field is not a physical trace of that camera. Its absence likewise gives no positive evidence of synthetic generation. Metadata interpretation starts with the process that created each field.

Content Credentials offer a more structured provenance record. Under the C2PA specification, a manifest contains signed claims and bindings to the asset. Validation can show whether the signed claim remains associated with the examined asset and who signed it under the applicable trust model. It cannot certify that a depicted event occurred. Credentials may be absent because a device never issued them, a platform did not retain them or an intervening transformation broke the chain. The C2PA analysis deals with those cases.

Measure the image, then interpret the measurement

An AI-image classifier compares a questioned file with patterns learned from labelled examples. Its score is conditional on those examples, the model and any threshold applied. If the image was resized, recompressed, screenshot or generated by a system absent from validation, its error rate may differ from the advertised test result. A high score may justify further examination; it is not an independent fact about the image’s creation.

Forensic signal analysis can ask a more specific question about physical image formation. Optics, a sensor and camera processing can leave measurable image characteristics. SPOT—Sensor Pattern Origin Testing evaluates selected noise-residue statistics against camera-origin and synthetic-origin populations. Its published study reports strong discrimination for a defined Dresden camera and DALL·E image experiment. A questioned image outside comparable conditions needs a correspondingly cautious interpretation. Absence of a detectable sensor-related signal cannot simply be translated into “AI-generated”: processing may also have obscured it.

Where the matter is consequential, retain the original and derivative files, record the chain between them and specify the precise allegation. A whole-image origin test cannot settle a local edit, and a camera-origin finding cannot settle whether the camera photographed a real event or a display. The strongest answer may identify which propositions the available evidence distinguishes and which remain open.

Related research & reading

FORENSIC INSTRUCTIONS

A question about digital evidence?

For legal practitioners and professional organisations: discuss the forensic question, available material and timeframes.

Contact the laboratory