AI image generation has changed the way we handle evidence.
A support team receives a photo of a broken product. A marketplace seller gets a refund request with a suspicious damage image. A contractor sends a "completed work" photo before asking for payment. A community moderator sees a viral image and needs to decide whether to slow its spread.
The hard part is not just asking, "Was this made by AI?"
The harder question is:
Can we make a careful, repeatable decision about this file without pretending that any single detector is a final authority?
This post lays out a practical workflow for image verification. It combines provenance, file integrity, AI-generated image detection, pixel-level review, and human context checks.
It is the same basic logic behind tools like ShanHaiYin, which provides AI content identification and provenance verification for images, text, audio, and video.
Why One AI Score Is Not Enough
Many AI detectors return a score: 82 percent AI, likely synthetic, suspicious, pass, review, block, and so on.
That is useful, but it should not be treated as a verdict.
There are several reasons:
- An AI-generated image may be cropped, compressed, screenshotted, filtered, or re-exported.
- A real photo may be heavily edited by ordinary software.
- Social platforms often strip metadata.
- Some generation tools add provenance signals, while others do not.
- A detector may be strong on one model family and weaker on another.
So the right mental model is not:
detector score equals truth
It is:
detector score plus provenance plus file integrity plus context equals a better review process
The Practical Workflow
When an image matters, use this sequence:
- Preserve the original file
- Calculate a file fingerprint
- Check provenance signals
- Run AI image detection
- Review pixel-level and semantic clues
- Ask for source material when needed
- Generate a report that can be shared
Let's walk through each step.
1. Preserve the Original File
Before analyzing anything, save the exact file you received.
Do not crop it.
Do not draw arrows on it.
Do not improve the brightness.
Do not screenshot it again.
Do not re-upload it through a chat app that compresses images.
If you need annotations, create a copy.
This matters because every edit can destroy useful signals. Compression, resizing, and re-exporting can remove metadata and change pixel patterns. If the file later becomes part of a dispute, you also want to show that your analysis was based on the submitted file, not on your modified version.
2. Calculate a File Fingerprint
A SHA-256 hash does not tell you whether an image is real or fake.
What it does tell you is whether two files are exactly the same.
For example, on many systems you can run sha256sum suspicious-image.jpg.
You can store the hash with your review record. Later, if someone asks, "Are we still talking about the same file?", the hash gives you a clear answer.
This is especially useful for marketplaces, internal audits, customer support disputes, and compliance workflows.
3. Check Provenance Signals
Provenance is about where a piece of content came from and what happened to it along the way.
The C2PA standard and Content Credentials are designed to provide signed information about the origin and editing history of digital media. The C2PA FAQ describes Content Credentials as a way to capture and express content provenance, including how content was created and modified.
If a file contains valid provenance data, it may answer questions like:
- Was this captured by a camera?
- Was it exported by an AI tool?
- Which app modified it?
- Has the signed content been altered?
But there is an important limitation: absence of provenance does not prove a file is fake.
Many real images have no Content Credentials. Many platforms strip metadata. Many workflows still do not preserve provenance.
So provenance is a strong signal when present, but not a complete answer when absent.
4. Run AI Image Detection
AI image detection looks for statistical, visual, and structural signals that may indicate synthetic generation or manipulation.
A detection system may inspect things like:
- texture patterns
- lighting consistency
- object boundaries
- local pixel distributions
- semantic inconsistencies
- signs of deepfake or assisted editing
- traces left by generation or enhancement tools
For example, Tencent Cloud provides an AI-generated image identification capability that is designed to detect whether an image may be AI-generated or tampered with.
ShanHaiYin integrates Tencent Cloud's image AI generation identification capability and combines it with provenance and pixel-level review signals.
The practical value is simple: instead of saying "this image feels wrong", you can say:
This submitted file was technically reviewed, and the report found specific indicators that require further verification.
That wording matters. It is useful in support tickets, refund disputes, moderation queues, internal reviews, and vendor communication.
5. Review Pixel-Level and Semantic Clues
Automated detection should be paired with human review.
Look for obvious inconsistencies:
- shadows that point in different directions
- text that bends or melts
- repeated textures in walls, grass, packaging, or fabric
- hands, cables, buttons, screws, labels, or product details that do not make sense
- damage marks that do not match the physical object
- reflections that do not match the scene
- background objects that merge into each other
For operational cases, context is often more important than aesthetics.
A product damage photo should match the order, packaging, shipping label, SKU, and reported issue. A repair completion photo should match the location, device, timestamp, and expected work. A workplace attendance photo should match the actual site.
An image can be visually plausible and still be the wrong image for the claim.
6. Ask for Source Material
If the image has technical doubts, ask for additional source material.
A good request is specific:
- Send the original photo file, not a screenshot.
- Send a short continuous video.
- Show the object from wide shot to close-up.
- Include the order number, device ID, room number, shipping label, or today's date.
- Capture the same issue from another angle.
- For damage claims, show packaging, label, full item, and damage detail in one sequence.
This is not just bureaucracy.
Single images are easier to fake than consistent sequences. A continuous video with physical context, multiple angles, and specific requested details raises the cost of fraud.
7. Generate a Shareable Report
The final output should not be a vague label like "fake" or "real".
A useful report should include:
- the main conclusion
- the reasoning or signals behind the conclusion
- the request or case ID
- the SHA-256 fingerprint of the submitted file
- relevant provenance findings
- a clear statement of limitations
This is the format ShanHaiYin uses for its reports: a main conclusion, reasoning, request number, and SHA-256 file fingerprint.
The goal is to make the review traceable and easy to share with another person.
That could be a marketplace support agent, a platform reviewer, a manager, a client, or a legal advisor.
Example: A Suspicious Refund Image
Imagine you operate an online store.
A customer submits one image showing a cracked product and asks for an immediate refund. The photo looks strange: the crack is sharp, the lighting on the damage area does not match the rest of the object, and the customer refuses to send a video.
A practical response would be:
- Save the submitted image without editing it.
- Upload the file to an AI image detection and provenance tool.
- Download the report.
- Ask the customer for a continuous video showing the packaging, shipping label, full product, and damage area.
- Submit the original image, report, and order screenshots to the platform if needed.
You are not claiming the report is a court judgment. You are saying the submitted evidence has technical doubts and deserves manual review.
That is often enough to move the conversation from "your word against mine" to a more structured review.
What This Workflow Can and Cannot Do
It can help you:
- reduce blind trust in screenshots and single images
- preserve the original file for later review
- identify AI-generation or editing risk signals
- create a record that another person can inspect
- support refund, moderation, vendor, or internal review decisions
It cannot:
- prove the full real-world story by itself
- replace platform policy or human judgment
- guarantee that every AI image will be detected
- prove that an image is truthful just because no AI signal was found
This distinction matters. A good verification workflow does not overpromise. It gives reviewers better evidence and a cleaner process.
A Simple Rule of Thumb
If the image will affect money, trust, safety, moderation, reputation, or access, do not rely on the image alone.
Preserve the file.
Check provenance.
Run detection.
Review the context.
Ask for source material.
Save a report.
That is a much stronger workflow than arguing from gut feeling.
If you want to try this on images, text, audio, or video, ShanHaiYin provides AI content identification and provenance verification with downloadable reports.
References
- ShanHaiYin: https://shanhaiyin.com/
- C2PA FAQ: https://c2pa.org/faqs/
- C2PA specification: https://spec.c2pa.org/specifications/specifications/2.4/index.html
- Content Credentials: https://contentcredentials.org/
- Tencent Cloud image AI generation identification: https://cloud.tencent.com/document/product/1125/116997
- NIST AI RMF Generative AI Profile: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
Top comments (0)