Multimedia Authentication and Deepfake Forensics
Authenticating media and detecting fakery: image, video and audio tamper detection, deepfakes and synthetic media, source attribution, and steganography.
- 60hours
- 30topics
- 10modules
Media authentication and integrity
Why authenticity matters and the questions an examiner must answer.
Start module- Media Authentication FundamentalsThis topic introduces the core questions a forensic examiner must answer when assessing media authenticity: has the content been altered, and does it originate from the claimed source. It covers the legal and investigative context in which authentication requests arise, from criminal proceedings to insurance fraud and journalism verification.13 min
- Chain of Custody for Digital MediaMaintaining an unbroken chain of custody is essential before any technical examination can carry weight in court. This topic covers acquisition procedures, write-blocking, hashing for integrity verification, and documentation standards applied to image, video, and audio exhibits.13 min
- Authentication Versus Enhancement: Defining the Examiner's ScopeAuthentication forensics asks whether a file is genuine, while enhancement forensics improves intelligibility of content assumed to be genuine. This topic clarifies the boundary between the two disciplines, explains why conflating them undermines testimony, and maps when each type of examination is warranted.13 min
Image authenticity and tamper detection
Detecting edited, spliced and manipulated images.
Start module- Image File Format and Integrity ChecksStructural analysis of image containers such as JPEG, PNG, and TIFF can reveal inconsistencies that indicate post-capture editing. This topic explains how examiners inspect file headers, chunk structures, and embedded data for signs of re-saving or format conversion.13 min
- Copy-Move and Splicing Detection in ImagesCopy-move forgery duplicates regions within the same image, while splicing composites content from two or more sources. This topic describes block-matching algorithms, keypoint-based detectors, and deep-learning classifiers used to locate these manipulations.13 min
- Noise Inconsistency and Lighting Analysis for Image ForgeryGenuine images carry spatially consistent sensor noise and physically plausible lighting geometry. This topic covers how examiners measure noise variance across image regions and model illuminant direction to expose areas that were composited under different conditions.13 min
Video authentication
Detecting edited, re-encoded and manipulated video.
Start module- Detecting Frame Deletion and Insertion in VideoRemoving or inserting frames breaks the temporal continuity of inter-frame compression and leaves detectable artifacts in motion vectors and GOP structure. This topic explains how examiners parse container timestamps, GOP boundaries, and inter-frame residuals to identify discontinuities.13 min
- Double Compression Analysis in VideoRe-encoding a video to conceal edits leaves a statistical signature because the quantisation grids of two successive compression passes rarely align. This topic covers how DCT coefficient histograms and macroblock statistics are used to detect double compression and estimate the parameters of the first encoding.13 min
- Matching Video to a Source CameraBeyond PRNU analysis, video carries camera-specific signatures in its codec settings, bitrate profile, and colour pipeline. This topic describes how examiners correlate these parameters to a suspect device and assess whether internal metadata is consistent with the claimed recording device.13 min
Audio authentication
Detecting edited and synthesised audio recordings.
Start module- Detecting Discontinuities in Audio RecordingsCuts, splices, and re-recorded segments introduce energy transients, phase discontinuities, and background-noise level shifts that are not present in continuous recordings. This topic covers spectrographic methods and automated detectors used to locate these discontinuities in speech and environmental audio.13 min
- Electric Network Frequency Analysis for Audio DatingThe mains power frequency embedded as hum in recordings fluctuates in a pattern that national grid operators log, creating a dateable fingerprint. This topic explains how ENF extraction, reference database matching, and statistical correlation are used to verify or refute a recording's claimed time and date.13 min
- Voice Conversion and Cloning DetectionVoice conversion systems and neural text-to-speech cloning can produce audio that passes casual listening but leaves artifacts in spectral smoothness, prosody naturalness scores, and GAN discriminator residuals. This topic surveys the detection landscape and explains how anti-spoofing models are evaluated using the ASVspoof benchmark corpora.13 min
Deepfakes and synthetic media
How synthetic media is made and how it is detected.
Start module- How Deepfakes Are Generated: GANs, Diffusion and Face Swap PipelinesUnderstanding detection requires understanding generation. This topic explains how generative adversarial networks, diffusion models, and face-swap pipelines such as FaceSwap and DeepFaceLab produce synthetic faces and how the choice of architecture influences which artifacts are left behind.13 min
- Deepfake Detection Methods: From CNNs to Foundation ModelsDetection approaches range from handcrafted artifact analysis to end-to-end convolutional classifiers and large vision-language models fine-tuned on synthetic media benchmarks. This topic reviews major detection architectures, their generalisation limits across generation methods, and the FaceForensics++ evaluation protocol.13 min
- Provenance Watermarking and Invisible Signing of Synthetic MediaGenerative model providers and standards bodies are deploying imperceptible watermarks and cryptographic model fingerprints to enable downstream provenance verification. This topic covers techniques such as SynthID, model-specific fingerprinting, and the tradeoffs between robustness and capacity in watermarking synthetic media.13 min
Source device identification
PRNU, sensor noise, microphone and codec fingerprints.
Start module- Photo Response Non-Uniformity and Sensor FingerprintingEvery imaging sensor has a unique fixed-pattern noise component caused by pixel-level manufacturing variation, known as photo response non-uniformity. This topic explains how PRNU is estimated from flat-field images, matched against scene images using a normalised cross-correlation detector, and used to attribute images and video frames to a specific camera body.13 min
- Lens Distortion, CFA Pattern and Demosaicing FingerprintsBeyond sensor noise, cameras leave device-class signatures in the form of colour filter array interpolation artifacts and lens distortion profiles. This topic explains how CFA pattern identification and radial distortion parameter estimation can distinguish device models and expose footage that has been composited from a different optical system.13 min
- Microphone and Codec Identification in Audio ForensicsMicrophones and audio codec implementations impart characteristic frequency response curves, noise floors, and bitrate-dependent quantisation signatures. This topic describes how spectral fingerprinting and bitstream analysis are used to link an audio recording to a device class or to detect recompression that contradicts claimed recording conditions.13 min
Steganography and hidden data
Concealing and detecting hidden data in media files.
Start module- Steganography Principles and Common Carrier FormatsSteganography hides the existence of a message by embedding it within innocuous cover media such as images, audio files, or video. This topic covers least-significant-bit substitution, spread-spectrum embedding, and palette-based methods across JPEG, PNG, WAV, and MP4 carriers.13 min
- Steganalysis: Statistical and Machine Learning Detection MethodsSteganalysis detects the presence or estimates the payload of hidden data without necessarily recovering the message itself. This topic reviews chi-square attacks, calibration-based detectors, rich model feature sets, and convolutional steganalysis networks, along with their relative effectiveness against adaptive embedding schemes.13 min
- Network Steganography and Covert ChannelsHidden data can be transmitted over networks by exploiting unused header fields, timing channels, or protocol redundancies. This topic explains common network steganography techniques, detection through traffic analysis and protocol anomaly detection, and their relevance to insider threat and malware command-and-control investigations.13 min
Metadata and provenance
EXIF, container metadata, and provenance standards such as C2PA.
Start module- EXIF and Container Metadata ForensicsImage and video files embed rich metadata including GPS coordinates, timestamps, device make and model, and software identifiers that can corroborate or contradict claimed provenance. This topic explains how examiners extract, interpret, and cross-validate EXIF, XMP, IPTC, and container-level metadata, and how common editing tools alter these fields.13 min
- C2PA and Content Credentials: Cryptographic Provenance StandardsThe Coalition for Content Provenance and Authenticity specifies a manifest format that cryptographically binds authorship, capture device, and editing history to media files using signed assertions. This topic explains the C2PA trust model, how Content Credentials are created and verified, and the practical limits of this standard when content is re-shared or re-encoded.13 min
- Blockchain and Distributed Ledger Approaches to Media ProvenanceSome provenance systems register media hashes or ownership tokens on distributed ledgers to create tamper-evident records. This topic evaluates blockchain-based provenance schemes for forensic purposes, distinguishing what a ledger entry actually proves from the broader claims made about media origin and authenticity.13 min
Compression and error-level analysis
How compression artifacts reveal manipulation.
Start module- JPEG Compression Artifacts and Error Level AnalysisError level analysis re-compresses an image at a known quality setting and measures the pixel-level difference, exploiting the fact that regions saved at different quality levels or re-compressed a different number of times show distinct residual magnitudes. This topic explains the theoretical basis of ELA, its correct interpretation, and the common misreadings that arise when it is applied without understanding JPEG quantisation.13 min
- DCT Block Boundaries and Quantisation Grid AnalysisJPEG and video codecs divide content into fixed blocks before applying the discrete cosine transform, leaving a grid of block-boundary artifacts that encode information about the quantisation table used. This topic explains how inconsistencies in blocking artifact phase and strength reveal spliced regions or double-compression at misaligned block grids.13 min
- Compression History Estimation in Video StreamsEstimating the number of encoding generations a video has undergone and the parameters of each generation can reveal whether footage was recorded directly or assembled from previously encoded material. This topic covers macroblock mode statistics, quantisation parameter traces, and machine-learning regressors for compression history estimation in H.264 and H.265 streams.13 min
Presenting media authenticity in court
Reporting and testifying on authenticity findings.
Start module- Writing a Media Authenticity Examination ReportAn authenticity report must clearly state the exhibit received, the methods applied, the findings at each analytical step, and the conclusion drawn, without overstating the certainty of probabilistic results. This topic covers report structure, appropriate hedging language for statistical findings, and how to communicate the limitations of deepfake detectors and ELA to a non-specialist reader.13 min
- Expert Witness Testimony on Media EvidenceCourts in multiple jurisdictions apply distinct admissibility frameworks, including Daubert, Frye, and equivalents in Commonwealth and civil law systems, to evaluate whether scientific methods meet evidentiary standards. This topic examines how media authentication examiners qualify as experts, respond to cross-examination on tool validation, and address the jury instruction challenges posed by AI-generated evidence.13 min
- Standards and Validation Frameworks in Media ForensicsProfessional credibility depends on method validation, tool certification, and adherence to published standards from bodies such as SWGDE, NIST, and ISO. This topic surveys existing guidance documents for digital multimedia evidence, explains how method validation studies are designed, and discusses the ongoing challenge of validating rapidly evolving AI-based detection tools.13 min