Skip to content

Error Level Analysis (ELA)

Error level analysis amplifies the per-pixel difference between an image and a freshly re-saved copy to reveal regions with inconsistent compression history. This topic explains the operating principle, correct interpretation, known limitations, and the confounding artefacts that generate false signals.

Last updated:

Share

Error level analysis (ELA) detects inconsistencies in JPEG compression history by re-saving an image at a known quality level, then computing and amplifying the per-pixel absolute difference between the re-saved and original versions. Regions already at compression equilibrium appear dark; regions with a different compression history appear bright. ELA can indicate that a region was added or edited after the original save, but it cannot distinguish this from naturally high-frequency content such as sharp edges, fine textures, and text, which are legitimately bright in any authentic image. The method must always be corroborated by other forensic techniques before any conclusion about manipulation is drawn.

Error level analysis (ELA) is a passive image forensics technique that re-saves a JPEG at a chosen quality level, computes the per-pixel absolute difference against the original, and amplifies the result. Regions already at compression equilibrium appear dark. Regions that have not reached equilibrium, either because they were introduced from a source with a different compression history or because they contain fine detail that resists equilibration, appear bright.

ELA converts an invisible statistical difference into a visible map. That accessibility also makes it prone to misinterpretation. ELA maps can look alarming for entirely innocent reasons, and they can look clean for images that have been carefully manipulated. Misuse of ELA has produced false claims of forgery in genuine photographs, including documented cases involving news photography.

By the end of this topic you will be able to:

  • Explain the JPEG quantisation ratchet and why repeated saves drive a region toward compression equilibrium.
  • Interpret an ELA map correctly by comparing relative brightness across same-texture regions, not by treating absolute brightness as a forgery indicator.
  • Identify the camera and post-capture processing conditions (in-camera HDR, smartphone portrait mode, screenshots, resampling) that produce false-positive ELA signals.
  • Select an appropriate re-save quality level by estimating the original compression quality from the JPEG quantisation table, and explain why a mismatch degrades the analysis.
  • State the conditions under which ELA must not be used as a standalone finding and identify which corroborating techniques should be applied.
Key terms
ELA (Error Level Analysis)
A passive image forensics technique that re-saves the input image at a chosen JPEG quality and amplifies the per-pixel absolute difference to reveal regions at different compression equilibria.
Compression equilibrium
The state of an image region after sufficient JPEG compression cycles at a given quality: further compression at the same quality produces minimal additional change. Regions at equilibrium appear dark in an ELA map.
ELA amplification factor
The multiplier applied to the per-pixel difference before display. A higher factor reveals subtle differences but also amplifies noise, making regions look manipulated when they are not. The standard FotoForensics factor is around 10x.
High-frequency detail
Fine textures, sharp edges, and small text that JPEG compresses poorly. These regions inherently show high ELA values in authentic, unmodified images and must be distinguished from manipulation signals.
False positive (ELA)
An ELA anomaly in a region that was not manipulated, typically caused by high-frequency texture, JPEG artefacts in the original, or camera processing rather than post-capture editing.
Saturation
In ELA context, the condition where a region's error level has reached near-zero, indicating it has already been compressed to near-equilibrium. A re-saved region from a high-quality source may not saturate and therefore appears bright.

The operating principle of ELA

The underlying logic is rooted in the ratchet-like nature of JPEG quantisation. When you first save an image as JPEG at quality Q, the DCT coefficients are divided by the quantisation table and rounded. Some precision is lost. When you save the same image again at the same quality, the coefficients are divided and rounded again, but they are already very close to multiples of the quantisation step. The second rounding changes them by very little. With enough iterations, the values stop changing at all: they have reached equilibrium for that quality setting.

ELA measures how far a region is from that equilibrium. Take the image, re-save it at a fixed quality (commonly 95% in FotoForensics), compute the per-pixel absolute difference, and multiply by an amplification factor. Regions at equilibrium produce small differences: they appear dark. Regions not at equilibrium, because they were recently added, recently edited at a different quality, or simply contain fine detail that never fully equilibrates, appear bright.

Original JPEGRe-save at Q=95Per-pixel diffELA heat mapamplify x10
ELA workflow from input image to heat map output.

The intuition behind the forensic use is that an authentic image has a uniform compression history: every region passed through the same camera processing pipeline, the same JPEG encoder, and the same save step. A manipulated image has at least one region with a different history. That region may not be at the same equilibrium point as the rest of the image and will therefore appear brighter or differently-textured in the ELA map.

Correct interpretation of ELA maps

The first principle of correct ELA interpretation is that absolute brightness means nothing: what matters is relative brightness between comparable regions. A bright sky should look uniformly bright. Uniform grass should look uniformly dim or uniformly bright. An anomaly is a region whose brightness is inconsistent with its neighbours and with its texture complexity.

The second principle is that high-frequency content is naturally bright. Sharp edges, fine text, fabric textures, and granular detail never reach compression equilibrium fully at high quality settings because each re-save still changes the high-frequency coefficients measurably. A genuine image of a newsprint page will show uniformly high ELA values across the text and this is not a forgery signal; it is a texture signal.

ELA observationInnocent explanationForgery-consistent explanation
Bright rectangular patchThumbnail or embedded preview with different qualityPasted region from higher-quality source
Uniformly bright text or labelsHigh-frequency content never at equilibriumLabels composited from a different source
Dark flat-colour regionSolid fill compresses to near-zero error normallyCould be either
Bright edges only (not interiors)JPEG blocking artefacts at block boundariesSplice boundary where two images meet
Inconsistent brightness compared to same-texture neighbourUnlikely without causeConsistent with localised editing
Bright region detected in ELA mapQ1: Is the region high-frequency content? (edges, text, finetexture, face detail)YES: Likely texture signal, not forgery. Compare to asimilar-texture area in the same image.Q2: Does provenance indicate screenshot, HDR merge, AIportrait, or prior resize?YES: Likely camera or pipeline artefact. Obtain a referenceimage from the same device.Q3: Is the region anomalously bright compared tosame-texture neighbours?NO: No anomaly. Consistent with authentic image compressionat this texture level.If NO to Q1If NO to Q2If YES to Q2If NO to Q3
ELA interpretation decision tree: a bright region passes four sequential checks (texture type, provenance, neighbour comparison, re-save quality) before a forgery-consistent finding can be reported.

Camera-processed and screenshot artefacts that mimic ELA signals

Several entirely innocent image-production pathways produce ELA patterns that could be mistaken for splicing or editing. Each pathway must be considered before interpreting an ELA map.

  • In-camera HDR processing: cameras that merge multiple exposures internally produce images where tone-mapped regions may have different local compression characteristics. The ELA map can show irregular bright patches that have nothing to do with post-capture editing.
  • Screenshots: a screenshot of a webpage or another application captures elements rendered by a GPU pipeline, which produces flat colours, sharp edges, and composited layers. All of these produce unusually high ELA values because they represent a different production pathway than a camera-captured scene. A screenshot of a photograph is not a forgery of the photograph, but ELA may flag it heavily.
  • Smartphone AI processing: modern smartphones apply segment-aware sharpening, noise reduction, and portrait-mode depth effects that treat different regions of the image with different processing. The processing boundary, for example between a blurred background and a sharp foreground in portrait mode, can produce an ELA edge that looks like a splice.
  • Re-sampled or resized images: any image that has been downsized and re-saved will have a compression history that differs from an image captured at that resolution. The resampling interpolation redistributes energy across the frequency spectrum and changes the ELA response.

The practical implication is that ELA findings must always be checked against the claimed provenance. If the image is alleged to be a smartphone portrait, the analyst should obtain a known-genuine image from the same device model and compare ELA responses before concluding that the depth-processing boundary is an edit.

The role of the re-save quality level

FotoForensics uses a re-save quality of 95 as its default, and most published ELA analysis uses this convention. But the choice of re-save quality changes the map. At higher re-save qualities, all regions retain more of their original values and the differences are larger overall; subtle anomalies become more visible but so does noise. At lower re-save qualities, aggressive quantisation pushes all regions toward equilibrium quickly and the differences are smaller.

The forensically safe approach is to run ELA at the same quality as the estimated original compression quality. If the source image was compressed at quality 80, re-saving at quality 80 provides the most meaningful equilibrium comparison. Re-saving at quality 95 on an image that was originally compressed at quality 60 will show high ELA values for the entire image, because the image is far from equilibrium at 95, which is mostly uninformative.

Known limitations and when ELA should not be used

ELA has a specific and limited scope. It detects differences in JPEG compression history. It says nothing about manipulation in lossless-format images (PNG, TIFF). It provides no evidence of manipulation in cases where the edit was applied before the first JPEG save, or where the attacker used a tool that brings the edited region to the same compression equilibrium as the surrounding image. It cannot distinguish object removal or inpainting from authentic content, because neither operation necessarily disturbs the compression history if done carefully.

  • Do not use ELA on PNG or TIFF files: ELA measures JPEG compression history. Applying it to lossless formats by converting to JPEG first introduces artefacts that invalidate the analysis.
  • Do not use ELA to authenticate faces or text independently: these are naturally high-ELA regions in virtually every photograph.
  • Do not present ELA as a standalone finding: corroborate with at least JPEG ghost analysis, noise analysis, or geometric consistency before drawing conclusions.
  • Do not share the ELA map without quantitative context: a bright patch looks alarming without knowing what the surrounding baseline level is. Always compare the suspect region to same-texture reference regions in the same image.

Tools: FotoForensics and offline implementations

FotoForensics, built by Neal Krawetz, is the most widely known ELA implementation and runs as a web service, combining ELA, JPEG quality analysis, and several metadata views for rapid triage. For casework, uploading evidence to a web service creates chain-of-custody concerns: the image is transmitted to a third-party server, logged, and potentially visible to others. Practitioners should use offline implementations for anything that could become court evidence.

Offline ELA requires only a JPEG encoder library and a few lines of code. In Python, the standard approach uses Pillow to re-save the image and NumPy to compute the per-pixel difference, then amplifies and saves the difference image. This can be reproduced, audited, and documented as part of the casework record in a way that a web service cannot.

Check your understanding
Question 1 of 4· 0 answered

Why do regions at compression equilibrium appear dark in an ELA map?

Key Takeaways

  • ELA re-saves the image at a reference quality and amplifies per-pixel differences; regions near compression equilibrium appear dark, regions with a different compression history appear bright.
  • Absolute brightness is not a forgery indicator; relative brightness compared to same-texture regions is what matters, because fine detail and sharp edges are legitimately bright in any authentic photograph.
  • Screenshots, in-camera HDR, smartphone AI processing, and resampled images all produce ELA patterns that mimic manipulation signals and must be considered before drawing conclusions.
  • The re-save quality should match the estimated original compression quality for the most informative comparison; the original quality can be estimated from the quantisation table in the file header.
  • ELA is a hypothesis-generating tool, not a standalone conclusion; findings must be corroborated by JPEG ghost analysis, noise analysis, or other methods before being presented as evidence of manipulation.
How does error level analysis work?
ELA re-saves the image at a known JPEG quality level, then computes and amplifies the per-pixel absolute difference between the re-saved version and the original. Regions already at compression equilibrium show small differences (dark). Regions with inconsistent compression history show larger differences (bright).
Why do unmodified areas appear darker in an ELA image?
An original JPEG has already been quantised to near-equilibrium for its quality setting. Re-saving at the same quality rounds the coefficients again, but they change very little. The per-pixel difference is therefore small, appearing dark after amplification.
What are the main limitations of ELA?
ELA is sensitive to the chosen re-save quality. Solid-colour regions and low-detail areas show low error regardless of manipulation. Screenshots and composited graphics show high ELA values uniformly. Camera-processed images vary in baseline response. ELA should never be used as a standalone authentication method.
What is FotoForensics?
FotoForensics is a web-based image analysis service implementing ELA and other forensic tools, created by Neal Krawetz. For casework, offline implementations are preferred to avoid chain-of-custody concerns with uploading evidence to a third-party service.
Can ELA reliably detect all types of image manipulation?
No. ELA is specifically useful for detecting regions with inconsistent JPEG compression history. It is less effective against lossless-edited files, global adjustments affecting the whole image uniformly, and sophisticated retouching that brings the edited region's error level to match the surrounding image.

Test yourself on Forensic Audio, Video and Image Analysis with free, timed mocks.

Practice Forensic Audio, Video and Image Analysis questions

Found this useful? Pass it along.

Share

Spotted an error in this page? Report a correction or read our editorial standards.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.