Quick answer
Image forensics evaluates metadata, compression, lighting, edges, noise, and other visual traces to support authenticity decisions.
Deep forensic analysis of image files: extract and inspect EXIF metadata, detect editing software signatures, identify timestamp anomalies, analyze compression history, and flag manipulation indicators across all embedded data layers.
Every digital image file contains two distinct layers: the visible pixel data and the embedded metadata. The metadata layer holds a forensic record of how the image was created, where it was taken, what software has touched it, and often when every modification was made. This layer is invisible to casual viewing but contains the most reliable authenticity evidence.
Forensic analysis reads both layers simultaneously: it extracts and validates the metadata record, then compares what the metadata claims against what the pixel data actually shows. Inconsistencies between these two layers are often more revealing than any visual artifact alone.
Not all metadata fields carry equal forensic weight. These six are the most diagnostic for image authenticity.
Many platforms (Instagram, Twitter/X, WhatsApp, Facebook) strip EXIF data when images are uploaded. An image with no metadata isn't automatically suspicious — it may simply have been shared through a social platform.
However, an image with no metadata that is claimed to be an original, unedited camera photo is a strong red flag. Genuine camera photos accumulate metadata through every capture and export step. Their absence on a file presented as original suggests deliberate stripping or AI generation.
Every time a JPEG image is re-saved, the lossy compression algorithm runs again on already-compressed data. This creates measurable patterns in the DCT coefficient distribution — specifically in the quantization tables. Researchers call this double-JPEG compression (DJPEG) analysis. PhotoProof AI's origin detection signal incorporates DJPEG analysis to flag images that have been re-saved after editing.
PNG and WEBP files don't carry JPEG compression history, but they carry their own metadata structures that can indicate editing software, creation tools, and file modification chains.
EXIF (Exchangeable Image File Format) is a metadata standard that digital cameras and smartphones embed in photos. It records camera settings (ISO, aperture, shutter speed), device information (make, model, serial number), GPS location, and timestamps. For forensics, it's the closest thing to a photo's chain of custody — genuine photos accumulate EXIF through each save step, while AI-generated images produce none.
Yes. EXIF data can be edited with tools like ExifTool, Photoshop, or purpose-built metadata editors. However, faked EXIF has tells: the data is often copied inconsistently from other images, the Software field may not match claimed camera output, compression artifacts don't match the claimed settings, and GPS coordinates may not match the claimed location.
Missing EXIF has two explanations: the image was shared via a social platform that strips metadata (very common), or the EXIF was deliberately removed (or was never created, as with AI-generated images). PhotoProof AI's image origin signal estimates whether the pixel-level characteristics are consistent with a camera capture or with AI generation, even when EXIF is absent.
Yes, but with significant caveats. Screenshots contain no camera EXIF because there is no camera. They may contain OS-level metadata (device model, OS version) in some formats, but primarily the analysis falls back to pixel-level and compression pattern examination. Screenshots can be reliably distinguished from camera photos in most cases.
They complement each other. AI image detection looks for statistical and semantic patterns in the pixel data that indicate AI generation. Image forensics examines the metadata layer — the file's non-pixel records. A sophisticated deepfake might fool the AI detector but have incorrect or absent EXIF. A genuine photo might score suspicious on semantic analysis but have perfect, verifiable metadata. Running both analyses together produces a more complete picture.
Get 3 free analysis credits when you create an account. Every image report includes full EXIF extraction, metadata integrity assessment, and compression history analysis.
Image forensics evaluates metadata, compression, lighting, edges, noise, and other visual traces to support authenticity decisions.
Image forensics evaluates metadata, compression, lighting, edges, noise, and other visual traces to support authenticity decisions.
Image Forensics: Technical cluster for forensic image analysis, metadata review, compression signals, and manipulation traces.
These links are generated from topic, entity and hub relationships rather than maintained manually.
Read the next guide in this topic cluster.
Review methodology and research pages.
Clarify the terms used across this topic.
Compare adjacent detection and authenticity workflows.
See the test scope and evidence behind detection performance claims.
Continue with the most useful next concept.