Quick answer: Image forensics is the digital forensics discipline that scientifically examines whether an image is genuine or edited, spliced or AI generated. A photo's evidentiary value is assessed in three layers: metadata (EXIF: capture date, device, location, editing software trace), pixel analysis (compression inconsistency, cloning, splicing, shadow and perspective errors) and source verification (reverse image search, other copies of the same scene). The most critical rule, as with audio: analysis needs the original file; an image arriving via WhatsApp or as a screenshot loses most of its forensic value because it loses EXIF data and pixel traces.

A photo is now submitted as evidence everywhere: damage assessment, workplace incidents, divorce cases, social media defamation, insurance claims. But image editing tools and AI have become so widespread that "there is a photo" means little on its own. Establishing whether an image truly reflects the moment it was taken, or was tampered with, is the job of image forensics. This guide explains how the process works and what can be proven.

Three layer analysis

Layer What is examined What it shows
Metadata (EXIF) Date, device, location, software trace Does the image match the claimed source
Pixel analysis Compression, cloning, splicing, ELA Are there editing marks
Source verification Reverse search, copies of the same scene Is the image original or borrowed

These three layers complement each other. Metadata may look clean while pixel analysis shows montage; or the image may be genuine but taken from the internet and stripped of its context.

Metadata (EXIF) analysis

Modern cameras and phones embed an EXIF tag into every photo: capture date and time, device make and model, lens and exposure settings, often GPS location and, if any, a trace of the editing software used. This data tells the image's story. For example, if the photo is claimed to be "taken yesterday" but EXIF shows a different date or carries an editing software signature, it is a warning sign. But EXIF can be deleted or altered; so it is not enough alone and is supported by pixel analysis.

Pixel analysis: montage and cloning detection

Traces left in the image itself are sought:

  • Error Level Analysis (ELA). Every time an image is saved it compresses to a degree. Areas added or edited later show a different compression level from their surroundings; ELA makes this difference visible.
  • Clone detection. Copy paste traces used to hide or duplicate an object are caught by repeating pixel patterns.
  • Splicing analysis. When two different photos are merged, noise pattern, color temperature, shadow direction and perspective inconsistencies emerge.
  • Shadow and light consistency. If the shadows of objects are inconsistent with the scene's light source, that object may have been added later.

AI generated images

The biggest recent challenge is fully AI generated images. Such images usually lack EXIF or carry the generator's trace; they also contain statistical patterns not seen in natural photos and, at times, anatomical inconsistencies. This is closely related to deepfake detection. To be honest: AI images are improving fast and no detection method is one hundred percent certain; the result is presented with a probability and a confidence level.

Why the original file is essential

A screenshot or an image forwarded via a messaging app loses its original EXIF data and fine pixel traces; the app recompresses it. So for analysis, the device holding the image, or a bit for bit copy, must be obtained with the chain of custody preserved. The same principle applies in audio forensics.

Frequently asked questions

Is a screenshot admissible? It has limited value. A screenshot does not carry the original metadata and pixel traces and can be easily edited. If possible, the original image at its source and the device holding it should be obtained.

If the EXIF data is deleted, does analysis end? No. EXIF is a supporting layer; even if deleted, examination continues with pixel analysis (ELA, cloning, splicing) and source verification.

Can Photoshop editing be found with certainty? A well done analysis will most likely catch editing marks, but no method gives an absolute guarantee. The result is presented as an evidence based assessment.

Can an AI image always be told apart? Not always. Generation tools are evolving fast. Analysis gives strong clues but expresses the result as a probability, not a definite verdict.

Sources

To have a photo's authenticity, editing and source examined with a court ready report, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide digital forensics and digital evidence services.