Skip to main content
/v1/deepfake_detection first checks the file for C2PA Content Credentials, then runs two detectors and reports everything in a signals object: The image is "real" only if neither signal flags it. The top-level genuine_score is the lower of the two, so decision and threshold work exactly as on the other endpoints.
Deepfake response
That example is a face swap: the photo as a whole looks camera-made, but the face was replaced.

Fields

Content Credentials (C2PA)

ChatGPT, Gemini (Nano Banana), Adobe Firefly and a growing list of other generators sign the images they make with C2PA Content Credentials: a cryptographically signed record of how the file was made. We check for one before running the models. If a valid credential says the image was generated or edited with AI, that settles it: the image is flagged with genuine_score: 0 and the models don’t run.
Decided by Content Credentials
  • generator and signed_by appear only when the signer chains to the official C2PA trust list (or the earlier Content Authenticity Initiative list), so they can’t be spoofed with a self-made certificate.
  • An AI image that was later cropped or adjusted in a non-AI tool still counts: the AI step stays in its signed history.
  • A credential can prove an image is AI-made, but never that it’s real, so content_credentials.decision is only ever "spoof" or null.
  • Credentials are fragile. Screenshots, re-saves, messaging apps and most social platforms strip them, so a missing credential tells you nothing. That’s why the models still run on everything else.

Images without a face

A face isn’t required. If there’s none, or the largest one is under 64 px, the face check is skipped and ai_generated decides alone:
If your flow needs a face (selfie onboarding, for example), check face_manipulation.status === "checked" on your side, or use /v1/unified_detection, whose liveness check rejects images without a usable face.

Thresholds

Your org’s deepfake threshold (default 0.5) applies to both signals at once. At 0.5, each signal sits at its identity-verification operating point: about 0.5% of genuine selfies rejected per signal, roughly 0.9% combined. A higher threshold catches more and rejects more genuine images. See Thresholds & scores.

Getting the best results

  • Send the original file. Resizing, re-compressing, screenshotting or rotating removes the fine traces the AI-image check reads, and strips Content Credentials.
  • JPEG, PNG, WebP, AVIF, BMP, TIFF and GIF work. HEIC doesn’t, so convert iPhone photos first.
  • Video: sample frames (one per second is plenty) and send each one. There’s no calibrated clip-level rule yet; flagging a clip when any frame is "spoof" is a reasonable start.

Known limits

  • Talking-head avatars and lip-sync from tools the model hasn’t seen are the hardest case.
  • Heavily compressed or downscaled real photos get flagged a little more often.
  • Faces under 64 px aren’t checked by face_manipulation. ai_generated still runs.