25 Years of Research Behind One Free Tool

▶ Watch (1:20)

Mike Raggo and Chad Hosmer have spent 25 years on image analysis research, from steganography to modern AI detection. That work ships as a free GPT inside ChatGPT called the Fake Image Forensic Examiner. Upload a suspicious image, start a prompt, and the tool runs metadata inspection, error level analysis, noise mapping, and edge anomaly checks. It exports a marked-up forensic PDF. The tool is prompt-driven, so investigators can follow up with reverse image searches and OSINT queries without leaving the conversation.

ICC Profiles and the Metadata That Survives Social Media

▶ Watch (7:01)

EXIF data is the first stop, but social media strips it on upload. ICC profiles survive more often. The International Color Consortium standard embeds color rendering data into image files. Android devices insert ICC profile information automatically. That data persists through many upload cycles. A hex editor pulls this fingerprint directly from the file header, revealing what device rendered the image and how it was generated. These artifacts appear even after posting to social media, long after full EXIF gets scrubbed.

Noise Maps and Error Level Analysis

▶ Watch (16:07)

A noise map filters out low-variance pixels and shows what remains. Authentic photos have consistent noise across their surface. Manipulated images leave thick, anomalous lines at boundaries where content was inserted. Raggo showed a Facebook image claiming to depict a fire at a Temu facility. Error level analysis on that image exposed pixelated clusters around the logo and fire elements, confirming superimposition. Each cluster signals a compression mismatch, the fingerprint left when a photoshopped element was dropped into the scene.

Edge Anomalies Expose AI Smoothing Failures

▶ Watch (19:40)

Photoshopping an object into a scene leaves imperfect edges the cut didn’t remove. Raggo demonstrated this with an AI-generated image of a woman on a horse. The horse had six toes, visible without any tool. Edge analysis also caught unnatural smoothing throughout the body, thick lines on the bridle, and deformed anatomy around the hands. MidJourney and DALL-E produce images that look realistic at first glance but fail at these boundary regions. The GPT tool flags these as synthetic by cross-referencing against training on real horse anatomy.

Breaking Video into Frames for Deepfake Detection

▶ Watch (24:19)

GPT-5’s video upload capability lets the Fake Image Forensic Examiner extend to video. It extracts key frames from the start, middle, and end of a clip, plus random intervals, then applies noise map, error level, and edge checks to each frame before producing a consolidated report. Raggo updated the GPT the morning of the talk to support this. Separately, his steganography research found adversaries embedding malicious code inside images to trigger LLM jailbreaks, causing models to spawn outbound email and exfiltrate data. Both attack surfaces are active research areas.

Nearest-Neighbor ML Catches Pixel-Level Manipulation

▶ Watch (30:05)

The Python toolkit breaks the image into a grid, from 100 squares to one million depending on the sensitivity slider, then compares each cell to its neighbors using a pre-trained ML model. Users can supply their own labeled corpora to retrain it. Raggo tested this on a circulated photo of Putin giving a thumbs-up alongside Trump. The tool clustered yellow dots around the thumbs-up hand. A reverse image search confirmed the hand was photoshopped in. Unexpectedly, the tool also flagged Putin’s eyes, later confirmed as colored contacts, and Trump’s front teeth, which have caps.

Q&A

Why did the tool flag Putin’s eyes and Trump’s teeth as anomalous? The tool detected Putin’s colored contacts and Trump’s dental caps as genuine physical features, not photoshop artifacts, confirmed through subsequent research. ▶ 35:22

Do natural physical anomalies like contacts or dental work count as false positives? Analysts can tune the sensitivity slider to filter them out, and such findings still prompt useful investigative questions even when later explained. ▶ 36:54

Does re-running AI enhancement on a fake image defeat detection? Multiple re-compressions usually expose more compression artifacts rather than concealing them. ▶ 40:13

Has the tool produced false negatives? One false negative was found with a celebrity photo; Raggo has not yet isolated why that image was missed. ▶ 42:19

Notable Quotes

25th Defcon and I still get nervous. Mike Raggo · ▶ 1:00

you see herds of dots, right? Mike Raggo · ▶ 18:46

six toes. Right? Mike Raggo · ▶ 20:42

we’re not talking about AI generation. Mike Raggo · ▶ 36:29

Key Takeaways

  • The free Fake Image Forensic Examiner GPT inside ChatGPT runs noise map, ELA, and edge analysis automatically.
  • ICC profile data survives social media uploads and can fingerprint the original image rendering device.
  • Nearest-neighbor ML on a pixel grid detects photoshopped elements with enough sensitivity to spot colored contacts and dental caps.

About the Speaker(s)

Michael T. Raggo brings over 30 years of security research to his work. He has uncovered and ethically disclosed vulnerabilities in products from Samsung, Checkpoint, and Netgear. He authored “Mobile Data Loss: Threats & Countermeasures” and “Data Hiding”, both published by Syngress. He presents regularly at Black Hat, DEF CON, RSA, SANS, OWASP, and DoD Cyber Crime, and received the Pentagon’s Certificate of Appreciation.