Skip to content

Glossary · Digital forensics

Deepfake

Also called: Synthetic media, AI-generated media, Face swap

A deepfake is audio, image or video synthesised or altered by machine learning to depict something that did not occur. For litigation the significance is twofold: fabricated media offered as evidence, and the growing tendency of parties to dispute authentic recordings by claiming they are synthetic.

Two problems, and the second is larger

The obvious problem is fabricated evidence: a recording of a conversation that never happened, offered to prove it did.

The less obvious and currently more disruptive problem is the reverse. Because everyone now knows synthesis is possible, a party confronted with a genuine recording can simply assert it is fake. This shifts a burden that used to be trivial — authenticating a video — into a contested expert question, and it works even when the recording is real. Courts and commentators have taken to calling this the liar's dividend, and it is showing up far more often than actual fabricated exhibits.

How authenticity is assessed

No single test settles it, and any examiner claiming a definitive detector is overselling. What a competent analysis does is accumulate independent indicators:

  • Provenance. Where did the file come from, and what is the unbroken account of its handling? A recording produced from the original device with intact chain of custody is in a completely different position from one that arrived as a download.
  • Container and encoding artifacts. Files carry structural traces of the software that produced them. Re-encoding, editing and generation each leave characteristic signatures in the container structure that are distinct from a camera's native output.
  • Metadata. Creation records, device identifiers, and EXIF data. Weak on its own — metadata is editable — and useful in combination.
  • Signal-level analysis. Compression consistency across the frame, lighting and shadow coherence, physiological plausibility in faces, and in audio the room acoustics and background noise floor.
  • Corroboration. What independent records exist? Call logs, badge data, other people's devices, and location records are frequently more decisive than any analysis of the file itself.

What an honest expert will and will not say

Detection research advances alongside generation, and detectors trained on one generation of models degrade against the next. An examiner who testifies that a file is definitively synthetic on the strength of a detector's score has staked their credibility on a tool whose error rate against the specific model used is unknown.

The defensible opinion is usually narrower and more useful: this file's structure is inconsistent with the camera it purports to come from; this audio has been re-encoded in a way native recordings are not; these artifacts are consistent with synthesis. Stating limits plainly is what survives a Daubert challenge in a field moving this fast.

Practical guidance

If media matters to your case, get the original file from the original device, and get it early. A copy sent through a messaging app has been re-encoded and stripped of metadata by the platform, which removes most of what an examiner would have worked with — and does so in a way that is indistinguishable, at the file level, from evidence of tampering.

From our work

Dealing with deepfake in a live matter?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.