Quick answer: Deepfake forensics is the process of scientifically detecting whether a video, audio or image was generated or altered with artificial intelligence. The expert does not rely on a single AI detector; they examine the file's metadata, compression and encoding traces, light and shadow consistency, face and voice synchronization and the statistical patterns left by generation models together. The goal is not to give a firm yes or no label but to document the findings with a chain of integrity and produce a court admissible, repeatable result. Because AI generated media evolves quickly, a defensible result relies not on a single tool but on a multi method and transparent process.

AI generated fake videos and audio are now used in fraud, reputation attacks and the creation of fake evidence. A fake phone call imitating an executive's voice can request a money transfer, or a sentence never spoken can be presented as real. This article explains what is examined in deepfake forensics, the limits of the methods and how a defensible report is produced.

Why deepfake is a hard problem

Deepfake detection is not searching for a fixed signature. Because generation models constantly improve, a marker that worked yesterday can disappear today. Also, when a file is compressed and shared multiple times, both the forgery traces and the traces of the real content are degraded. So the percentage score from a single AI detector is not evidence on its own.

The forensic approach relies not on a single signal but on multiple pieces of evidence that support each other. No method is conclusive alone, but together they form a consistent picture.

What is examined in forensic analysis

Layer Examination What it shows
Metadata Recording device, date, encoding traces Generation and editing history
Compression Frame and block inconsistencies Trace of later intervention
Visual consistency Light, shadow, reflection, blinking Physically impossible scenes
Face and voice sync Lip and audio alignment Overlay and generation trace
Statistical pattern Noise trace left by the model Probability of artificial generation

On the image side, methods such as EXIF and error level analysis used in photo and image forensics are used here as complementary. On the audio side, the originality and manipulation detection methods from audio forensics are applied.

The limit of AI detectors

Many tools on the market give the probability that a medium is a deepfake as a percentage. These scores are useful but have limits:

  • Generalization problem. A detector catches the generation methods it was trained on well but can miss a new model.
  • False positive and negative. A real but low quality recording can look fake, and a well generated fake can look real.
  • Lack of explainability. If a tool says fake but cannot show why, its defense in court is weak.

So the detector score is an input to the process, not its conclusion. The principles about AI agent hallucination and reliability apply here too: tie the result to verifiable evidence.

How a defensible report is produced

1. Preserving source and integrity

The examined file must be obtained according to digital evidence and chain of custody principles, its integrity fixed with a hash and the original never altered. Analysis is done on copies.

2. Multi method examination

Not a single tool but all of the metadata, compression, visual, audio and statistical layers are examined. If the findings support each other, confidence increases.

3. Transparent and repeatable method

The tools, versions and steps used are recorded. Another expert following the same method should reach the same result.

4. Honest uncertainty

If the result is not certain, the report states this clearly. In digital forensics, finding the truth without being deceived is more valuable than a claim of exaggerated certainty. A false positive can lead to an innocent person being accused.

The KAOS and DSET approach

DSET runs deepfake and AI generated media examination with a process that combines AI speed with human expert oversight. The local AI engine KAOS is used for fast pre screening and pattern detection of large volume media, but the final assessment is always made with multi method examination and expert oversight. Because KAOS runs fully offline, sensitive evidence files are not sent to external services, which is critical for privacy and KVKK. The result is not a single score but a court admissible report documented with a chain of integrity.

Frequently asked questions

An app said a video is a deepfake, is that evidence? Not sufficient on its own. The score from a tool is the start of the process. For evidentiary value the finding must be supported by multi method examination, the chain of integrity must be preserved and the method must be documented in a repeatable way.

Can deepfakes be detected with certainty? Certainty is not always possible. In well generated media compressed many times the markers weaken. Rather than claiming certainty, the forensic approach honestly presents the strength of the available evidence and clearly states the uncertainty.

Can audio deepfakes be detected too? Yes. For audio the metadata, recording environment consistency, compression traces and the statistical patterns left by generation models are examined. When audio and video are together, lip and audio sync is also a strong indicator.

Sources

For a forensic examination of whether a video, audio or image was generated with artificial intelligence, contact DSET. We provide ISO/IEC 27037 compliant, court admissible media forensics from our Ankara Hacettepe Teknokent laboratory.