Deepfake images can be easily manipulated to remove ‘AI fingerprints’, making it difficult to know if an image has been AI-generated, a new study from Edinburgh Uni researchers has found.
With genAI tools now capable of creating images nearly indistinguishable from real photos, “AI fingerprinting” has emerged as a possible solution to the abundance of deepfake imagery now being used in scams and misinformation campaigns.
AI fingerprinting uses a group of techniques that detect the unique, invisible traces that AI models leave in their images, helping identify the specific generator that produced them.
To test this process, scientists from the University’s School of Informatics undertook a security evaluation of common fingerprinting techniques, developing adversarial attacks that aimed to remove or forge fingerprints across a range of scenarios.
These scenarios ranged from powerful attackers with full access to the inner workings of the image generator to low-resource attackers with no special access. Researchers simulated these attacks on twelve image generators and used 14 fingerprinting methods to determine which systems were easily traceable.
While many of the fingerprinting methods were found to achieve high accuracy in detecting unaltered deepfake images, performance dropped dramatically once the image was attacked.
In several cases, simple changes to an image, such as JPEG compression, resizing or blurring, were enough to ‘smudge’ the fingerprints.
“We were surprised to find just how fragile these AI fingerprints truly are,” said Kai Yao, PhD student at the University of Edinburgh and the study’s author.
“We expected that sophisticated attacks would be effective, but seeing that simple, everyday image edits could effectively ‘smudge’ the forensic evidence was a real wake-up call.
“It suggests that many of the deepfake detection methods based on image fingerprinting might fail the moment an image is shared or edited in the real world.”
Fingerprint removal was also found to be highly effective, often achieving more than 80% success for attackers with full knowledge of an image generator and over 50% for simple attacks that required no knowledge of an AI generator’s inner workings.
All attacks were imperceptible to the human eye, leaving no visible evidence on the images. None of the evaluated fingerprinting techniques delivered both high accuracy and resistance to attacks across all threat scenarios.
The study found it was also possible for hackers to change an image’s AI fingerprint so it falsely appears to come from a different model, with researchers warning this technique could be used to blame legitimate tech companies for harmful images their systems never created.
This fingerprint forgery was less effective than removal overall, but half of the image generators evaluated were vulnerable to this kind of attack, raising fears that the AI industry’s current safeguards won’t hold up against real‑world misuse for much longer.
Recommended reading
- Is It Now Practically Impossible To Identify Deepfakes?
- UK Partners with Microsoft for Deepfake Detection Framework
- Too Authentic to be Synthetic: The Psychology Behind AI Voice Scams
While removing fingerprints would hinder forensic investigations into deepfakes, the Edinburgh team say improvements in AI fingerprinting techniques, combined with the watermarking of AI images, would strengthen deepfake detection.
“If fingerprinting is to be used to hold bad actors accountable, it must ensure that fingerprints cannot be easily removed or forged, as any accountability tool will itself become a target for attack,” said Dr Marc Juarez, co-author and lecturer in cybersecurity at the University of Edinburgh.
“The community must therefore move beyond optimising for performance alone and incorporate adversarial robustness into their evaluation methodology.”
Image Designed by Balintseby / Freepik





