Image Forensics

Deep forensic analysis of image files: extract and inspect EXIF metadata, detect editing software signatures, identify timestamp anomalies, analyze compression history, and flag manipulation indicators across all embedded data layers.

What image forensics examines beyond the visible image

Every digital image file contains two distinct layers: the visible pixel data and the embedded metadata. The metadata layer holds a forensic record of how the image was created, where it was taken, what software has touched it, and often when every modification was made. This layer is invisible to casual viewing but contains the most reliable authenticity evidence.

Forensic analysis reads both layers simultaneously: it extracts and validates the metadata record, then compares what the metadata claims against what the pixel data actually shows. Inconsistencies between these two layers are often more revealing than any visual artifact alone.

Six EXIF and metadata fields that matter most for forensics

Not all metadata fields carry equal forensic weight. These six are the most diagnostic for image authenticity.

Make / ModelCamera manufacturer and model. Should match the photo style — a phone camera model in a professional studio shot is suspicious. AI-generated images have no Make/Model unless manually injected.
SoftwareRecords which software last saved the file. Photoshop, GIMP, Lightroom, or image generation software all leave identifiable signatures. Multiple Software entries suggest successive edits.
DateTimeOriginal vs. DateTimeDateTimeOriginal is when the shutter fired. DateTime is when the file was last saved. A large gap between these two timestamps is a reliable manipulation indicator.
GPSInfoIf present, contains latitude, longitude, altitude, and timestamp of when and where the image was captured. Verifiable against claimed location. Absent from AI-generated images and screen captures.
ImageUniqueID / SerialNumberMany cameras embed a unique identifier per image and a body serial number. These can strongly link an image to a specific camera body and help identify image-origin chains.
CompressedBitsPerPixel / QualityCompression history analysis detects images that have been re-saved multiple times, which can indicate editing. Double-JPEG compression leaves measurable artifacts in the quantization tables.

What 'no metadata' actually means

Many platforms (Instagram, Twitter/X, WhatsApp, Facebook) strip EXIF data when images are uploaded. An image with no metadata isn't automatically suspicious — it may simply have been shared through a social platform.

However, an image with no metadata that is claimed to be an original, unedited camera photo is a strong red flag. Genuine camera photos accumulate metadata through every capture and export step. Their absence on a file presented as original suggests deliberate stripping or AI generation.

Compression history as a manipulation indicator

Every time a JPEG image is re-saved, the lossy compression algorithm runs again on already-compressed data. This creates measurable patterns in the DCT coefficient distribution — specifically in the quantization tables. Researchers call this double-JPEG compression (DJPEG) analysis. PhotoProof AI's origin detection signal incorporates DJPEG analysis to flag images that have been re-saved after editing.

PNG and WEBP files don't carry JPEG compression history, but they carry their own metadata structures that can indicate editing software, creation tools, and file modification chains.

Frequently asked questions

What is EXIF data and why does it matter for image authenticity?

EXIF (Exchangeable Image File Format) is a metadata standard that digital cameras and smartphones embed in photos. It records camera settings (ISO, aperture, shutter speed), device information (make, model, serial number), GPS location, and timestamps. For forensics, it's the closest thing to a photo's chain of custody — genuine photos accumulate EXIF through each save step, while AI-generated images produce none.

Can EXIF data be faked?

Yes. EXIF data can be edited with tools like ExifTool, Photoshop, or purpose-built metadata editors. However, faked EXIF has tells: the data is often copied inconsistently from other images, the Software field may not match claimed camera output, compression artifacts don't match the claimed settings, and GPS coordinates may not match the claimed location.

What if the image has no EXIF data at all?

Missing EXIF has two explanations: the image was shared via a social platform that strips metadata (very common), or the EXIF was deliberately removed (or was never created, as with AI-generated images). PhotoProof AI's image origin signal estimates whether the pixel-level characteristics are consistent with a camera capture or with AI generation, even when EXIF is absent.

Does image forensics work on screenshots?

Yes, but with significant caveats. Screenshots contain no camera EXIF because there is no camera. They may contain OS-level metadata (device model, OS version) in some formats, but primarily the analysis falls back to pixel-level and compression pattern examination. Screenshots can be reliably distinguished from camera photos in most cases.

How is image forensics different from AI image detection?

They complement each other. AI image detection looks for statistical and semantic patterns in the pixel data that indicate AI generation. Image forensics examines the metadata layer — the file's non-pixel records. A sophisticated deepfake might fool the AI detector but have incorrect or absent EXIF. A genuine photo might score suspicious on semantic analysis but have perfect, verifiable metadata. Running both analyses together produces a more complete picture.

Run a forensic metadata analysis

Get 3 free analysis credits when you create an account. Every image report includes full EXIF extraction, metadata integrity assessment, and compression history analysis.

Analyze an image →

Related tools

AI search answer layer

Fast answer for people and AI search

Image forensics evaluates metadata, compression, lighting, edges, noise, and other visual traces to support authenticity decisions.

Primary entity
Image forensics
Topic cluster
Image Forensics
Search intent
commercial
Content type
Guide

Quick answer

Image forensics evaluates metadata, compression, lighting, edges, noise, and other visual traces to support authenticity decisions.

Key facts

  • Primary entity: Image forensics
  • Topic cluster: Image Forensics
  • Search intent: commercial
  • Content type: Guide

Methodology

  • Separate AI-generation probability from authenticity confidence.
  • Combine visual, metadata, manipulation, compression, provenance, and context signals.
  • Explain uncertainty and limits instead of presenting binary proof.

Pros & limitations

  • AI and forensic detection should be interpreted as probabilistic evidence, not absolute proof.
  • Reliable authenticity decisions should combine model output with provenance, context, metadata, and human review.
Content hub

Image Forensics: Technical cluster for forensic image analysis, metadata review, compression signals, and manipulation traces.

Explore next

Recommended reading path

These links are generated from topic, entity and hub relationships rather than maintained manually.