Checkobot

Can AI image detectors be fooled?

Yes. Every detector can be fooled some of the time, Checko included. The useful questions are how, how often, and what you do about it.

Updated

Why the answer is yes

A detector learns from examples. It sees many AI images and many genuine photos, and learns the statistical differences between them. Anything that hides those differences, or that looks unlike what it learned from, can slip past.

Generators also keep changing. New models arrive every few months, each with its own fingerprints, and each is a fresh test for every detector on the market. Detection is a moving target, not a solved problem.

What tends to slip through

  • Images from brand-new generators that no detector has trained on yet.
  • Heavily compressed, resized or screenshotted copies. Each step throws away fine detail, including the traces detectors look for. That's why Checkobot refuses images under 256 pixels on the short side and JPEGs below roughly quality 50, rather than guessing.
  • Small AI edits inside a large genuine photo: a removed sign, a changed face in a crowd, an added object. There is less for a detector to find.
  • Talking-head and lip-sync frames from new avatar engines. This is Checko's weakest area.
  • Images deliberately altered to confuse detectors. Researchers have shown that carefully crafted changes can push a model's score around, which is one reason no detector should be the only check.

Fooled the other way: false flags

Being fooled isn't only about missing AI. Detectors can also be tricked, usually by accident, into flagging genuine photos:

  • Strong beauty filters, skin smoothing and heavy retouching.
  • Heavily distorted or very low-quality photos: noise, blur, over-sharpening, aggressive compression.
  • Illustrations, cartoons, CGI and doll faces, which can trip a face model that learned from photographs.

AI edited photo detector

Why more than one detector helps

Checkobot doesn't rely on a single model. Whole-image analysis looks at the entire picture. Face analysis looks at a wide crop around the largest face, including the jaw, neck and hairline, where face swaps have to blend in. It also reads Content Credentials, the signed records some AI tools attach.

These look for different things in different places. Something that hides from one may still show up in another, and the result tells you which one fired. That makes fooling the whole check harder. It doesn't make it impossible.

Deepfake detector

So is a detector still worth using?

Yes, for the same reason locks are worth using even though locks can be picked. Most AI images in the wild aren't carefully engineered to beat detectors. They are straight out of a popular tool, lightly cropped and posted. A good detector catches a lot of those, quickly, and tells you where to look harder.

What a detector shouldn't be is the last word. A flag is a reason to check further. A No AI detected is a reason to keep your other checks, not to skip them.

When a result deserves a second look

Some results are more likely to be wrong than others. Slow down when you see one of these:

  • The verdict clashes with strong evidence: a flag on a photo with a named photographer and ten other angles, or a clean result on an image nobody can trace.
  • The face analysis fired on a drawing, a cartoon, a game character or a doll.
  • The image is a screenshot, a crop of a crop, or has been forwarded many times.
  • The face is small in the frame, so only the whole-image analysis could run.
  • The photo is an old print, a scan, or a picture of a screen.

How to check so one trick isn't enough

  • Find the source: who posted it first, and can anyone vouch for it?
  • Reverse image search: older copies or the original photo beat any score.
  • Get the best copy: the original file, not a screenshot or a forward of a forward.
  • Check Content Credentials: rare, but direct evidence when present.
  • Run a detector and read the reason, not just the verdict.
  • Check the context: places, dates, weather and other photos of the same event.
  • For high stakes, ask: request the original file, another photo, or a live video call.

What we do about it

We test on frozen benchmarks the model never saw in training, including face-swap tools held out of training entirely, to see how it copes with tools it doesn't know. Every check records the model and threshold version it was made with, so when we improve either, old results can still be traced.

We'll publish catch and false-flag rates, each with its dataset and thresholds, once our current test round is finished. Until then we'd rather say nothing than quote a number we haven't confirmed.

Questions

Does taking a screenshot fool detectors?

It can make detection harder, because screenshots add compression and remove Content Credentials. Small or heavily compressed screenshots are refused rather than judged.

Can I trust a No AI detected result?

As one signal, yes. As proof, no. It means neither detector found signs at its threshold, and some AI images score under it.

Can Content Credentials be removed?

Yes, easily. Many sites strip them on upload, and screenshots drop them. That's why a missing credential proves nothing, and why Checko only uses credentials that are present.

Is any detector impossible to fool?

No. Be wary of any tool that says otherwise, or that claims to catch all deepfakes.

Why would someone try to fool a detector?

Usually to get a fake profile, listing or post past a platform's checks. That's why platforms should combine a detector with account signals and human review, rather than letting one score decide.