/v1/deepfake_detection first checks the file for C2PA Content Credentials, then runs two detectors and reports everything in a signals object:
The image is
"real" only if neither signal flags it. The top-level genuine_score is the lower of the two, so decision and threshold work exactly as on the other endpoints.
Deepfake response
Fields
Content Credentials (C2PA)
ChatGPT, Gemini (Nano Banana), Adobe Firefly and a growing list of other generators sign the images they make with C2PA Content Credentials: a cryptographically signed record of how the file was made. We check for one before running the models. If a valid credential says the image was generated or edited with AI, that settles it: the image is flagged withgenuine_score: 0 and the models don’t run.
Decided by Content Credentials
generatorandsigned_byappear only when the signer chains to the official C2PA trust list (or the earlier Content Authenticity Initiative list), so they can’t be spoofed with a self-made certificate.- An AI image that was later cropped or adjusted in a non-AI tool still counts: the AI step stays in its signed history.
- A credential can prove an image is AI-made, but never that it’s real, so
content_credentials.decisionis only ever"spoof"ornull. - Credentials are fragile. Screenshots, re-saves, messaging apps and most social platforms strip them, so a missing credential tells you nothing. That’s why the models still run on everything else.
Images without a face
A face isn’t required. If there’s none, or the largest one is under 64 px, the face check is skipped andai_generated decides alone:
face_manipulation.status === "checked" on your side, or use /v1/unified_detection, whose liveness check rejects images without a usable face.
Thresholds
Your org’s deepfake threshold (default0.5) applies to both signals at once. At 0.5, each signal sits at its identity-verification operating point: about 0.5% of genuine selfies rejected per signal, roughly 0.9% combined. A higher threshold catches more and rejects more genuine images. See Thresholds & scores.
Getting the best results
- Send the original file. Resizing, re-compressing, screenshotting or rotating removes the fine traces the AI-image check reads, and strips Content Credentials.
- JPEG, PNG, WebP, AVIF, BMP, TIFF and GIF work. HEIC doesn’t, so convert iPhone photos first.
- Video: sample frames (one per second is plenty) and send each one. There’s no calibrated clip-level rule yet; flagging a clip when any frame is
"spoof"is a reasonable start.
Known limits
- Talking-head avatars and lip-sync from tools the model hasn’t seen are the hardest case.
- Heavily compressed or downscaled real photos get flagged a little more often.
- Faces under 64 px aren’t checked by
face_manipulation.ai_generatedstill runs.