Verification Guides

What Screenshots and JPEG Compression Changed in Our 60-File AI Image Detection Test

A reproducible 12-source, 60-file case study of screenshots, resizing, JPEG compression, metadata re-encoding, C2PA credentials and visual model outputs.

Article cover featuring the title: What Screenshots and JPEG Compression Changed in Our 60-File AI Image Detection Test

Screenshots, resizing and JPEG compression do not merely make a file smaller. They create a different file, can remove embedded provenance, and can move a visual detector's score. We ran a controlled 60-file case study to show how those changes appeared in one small, fully recorded sample.

What we tested

We selected 12 source images from the public AI Detector Arena sample repository: four camera photos, four Flux-generated images and four visibly edited derivatives of the camera photos. The four topics were animals, art, food and landscapes.

Each source produced five versions:

  • the byte-identical original;
  • a real browser screenshot rendered in Chrome at 1280 by 900 pixels;
  • a resize with the longest side limited to 1024 pixels;
  • a JPEG export at quality 60;
  • a PNG re-encode with metadata omitted.

For every version we recorded its SHA-256 hash, format, dimensions, byte size, EXIF field count, C2PA result and the raw output from AIFakeScan's local visual model. The run used c2patool 0.26.60 and `community-forensics-384.onnx` on September 25, 2026.

Download the 60-row results CSV. Download the source inventory. Download the run settings.

What happened to the visual model output

The table reports the mean raw score across four files in each cell. These are observations from this sample, not accuracy rates and not calibrated probabilities.

Source groupOriginalScreenshotResizedJPEG quality 60Metadata stripped
Camera photos0.00360.00210.01150.00200.0036
Visibly edited photos0.00630.00140.01450.00310.0063
Flux-generated images0.99680.85690.71510.52260.9968

The generated group changed most. One generated art image moved from 0.9978 in the original to 0.3240 after resizing and 0.0093 after JPEG compression. A generated landscape moved from 0.9900 to 0.4344 in the screenshot. Other generated files remained close to 1.0 after the same transformations.

This variation is why a score from a screenshot cannot be treated as the score for an unseen original. It also shows why editing a file until a detector gives a preferred answer is not a valid review method.

What happened to Content Credentials

All four generated originals contained a C2PA manifest that declared generated content. c2patool reported the manifest as valid, but its signing credential was not in the local trust list, so the recorded outcome was valid but untrusted.

The screenshot, resized JPEG, compressed JPEG and metadata-stripped version of each of those four files had no embedded Content Credential. The eight camera and edited source files also had no credential in any tested version.

This result applies to these export paths. It does not mean every resize or editor must remove C2PA. A credential can be preserved or replaced by a C2PA-aware workflow. It also does not mean a file without a credential is authentic.

What happened to metadata

None of the 12 selected originals exposed EXIF fields through Pillow. The metadata-stripped versions therefore cannot demonstrate removal of camera EXIF in this sample. They do demonstrate that a pixel-equivalent re-encode changes the file hash and container even when the local visual model output remains the same to six decimal places.

This limitation is part of the result. We did not substitute a claim that metadata was removed when the selected originals had none to remove.

What we did not test

The selected files were not documented as products of a supported proprietary watermark provider. We therefore did not run an official SynthID or other vendor watermark check, and those fields remain blank in the record. Blank means not run, not absent.

We also did not upload these files to social platforms. No conclusion here describes what a particular platform preserves or removes.

How to check your own versions

  1. Preserve the earliest file you have before opening it in an editor.
  2. Hash and label each version. Do not overwrite the original.
  3. Use the C2PA checker on each file to see whether a credential is present and whether validation completed.
  4. If Google AI is the suspected source, follow the SynthID verification route for each relevant version.
  5. Run the AI image detector and record the full report and limitations instead of copying only one score.
  6. Describe a result as applying to the exact file checked.

Limits of this case study

The sample contains four images per source group and four topics. It was selected to demonstrate a reproducible method, not to estimate population accuracy. The edited group used one visible edit recipe. The local model is one detector version. Vendor watermarks and social-platform delivery were not tested. The full row-level record should be used when checking any summary above.

Frequently asked questions

Does a screenshot defeat every AI image detector?

No. In this sample some generated screenshots stayed near the original score while others moved substantially. A screenshot is a new input and should be reported as such.

Does missing C2PA prove that an image is real?

No. It means no usable credential was found in that file. Many authentic and generated files have no embedded credential.

Is the raw visual score an accuracy percentage?

No. It is a model output observed for one file. This experiment does not estimate sensitivity, specificity or general accuracy.

Sources

  1. AI Detector Arena benchmark dataset — AI Detector Arena
  2. C2PA public test files and verifier context — C2PA
  3. c2patool release 0.26.60 — Content Authenticity Initiative
  4. AIFakeScan 60-row experiment record — AIFakeScan