cs.CVOct 5, 2026

Certification of Real Images through Calibrated Content Authentication

Authors: Sarim Hashmi, Abdelrahman Elsayed, Mohammed Talha Alam, Samuele Poppi, Nils Lukas

Organizations: Mohamed bin Zayed University of Artificial Intelligence Mabuhay, Abu Dhabi, UAE

Abstract

Generative models can synthesize high-quality inauthentic multimedia content that is already being misused at scale. We evaluate twenty deepfake detectors against ten generators released in the last four years and find accuracy decreasing over time, from near-perfect 99.5% to 76%. Adversarial perturbations further reduce every baseline detector to below 2% accuracy, effectively inverting the detector's assigned label. We argue that this unreliability reflects a fundamental ambiguity: generators can reproduce authentic content exactly (e.g., through memorization), so content alone cannot reveal the true provenance label.For this reason, content produced by a generator must admit a faithful reconstruction by that same generator, and finding such a reconstruction makes synthetic provenance plausible and authenticity plausibly deniable.We therefore propose and evaluate a detection paradigm that outputs a calibrated prediction of whether authenticity is plausibly deniable: a faithful reconstruction by any known generator establishes plausible deniability, while calibration bounds how often content from known generators fails to be reproduced. Our evaluation shows that (i) our detector can be calibrated so that at most 1% of generated content is wrongly certified, an operating point at which most baseline detectors reach near-zero recall, including the strongest with 93% accuracy; (ii) calibrating a stricter security threshold on attacked samples preserves this bound against adaptive adversaries within the evaluated bounded-perturbation attack space, whose perturbations break every baseline, but does not cover arbitrary adversarial transformations; and (iii) post-hoc verifiability is eroding, as 1,116 of 3,000 Reddit images resist reproduction by a 2022 generator, but only 55 to 79 resist reproduction by 2024 generators.

Figures & tables

Appendix figures & tables15 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Deepfake Media Generation and Detection in the Generative AI Era: A Survey and Outlook

    Nov 29, 2024Florinel-Alin Croitoru, Andrei-Iulian Hiji, Vlad Hondru +7Deepfake DetectionUnsupervised Detection

  2. SSAFE: Simple and Strong AI-Generated Image Detection via Frozen Vision Encoders

    Jun 7, 2026Seunghyun Lee, Byoungkwon Kim, Jaehyun Nam +2Ai-Generated Image DetectionDeepfake Detection

  3. The Calibrated Deepfake Trust Score (CDTS): Competence-Coupled Trust Degradation Across Deepfake Detectors

    Jun 28, 2026Md Anas BiswasDeepfake DetectionAI Trustworthiness