Home // BLOG // DEEPFAKES & AI

Deepfakes and artificial intelligence: how forensics identifies manipulated content

How forensic examination identifies cloned voices and AI-manipulated video and images, and what to do upon receiving suspicious content.

Deepfakes & AI · June 29, 2026 · 7 min read

Illustration on deepfakes and forensic examination of AI-generated content

Thirty seconds of audio. In a demonstration conducted for a television report, that was enough material to clone a journalist's voice with a free, easy-to-use application. The synthetic voice carried a phone call without raising immediate suspicion, and with two minutes of recording the result would have been even more convincing. The experiment, performed in a controlled environment, illustrates what criminals already practice at scale: fraud involving fake voices, images, and videos generated by artificial intelligence grew 126% in Brazil in a single year.

Real cases show the reach of the problem. In one, the partner in a pharmacy received audio messages with the cloned voice of the other partner, requesting Pix transfers from the company's cash account. The resemblance was strong, and the loss was only avoided because the recipient found the request odd, noticed the changed profile picture, and called to confirm. In another, a criminal group in the Federal District used artificial intelligence to defeat facial recognition systems and break into more than 500 bank accounts. The question has ceased to be technological and become evidentiary: how to distinguish, with method, the authentic from the fabricated.

How the manipulations are produced

Voice cloning starts from short speech samples, harvested from social media audio, messaging app voice notes, or public interviews. Synthesis models reproduce timbre and intonation and generate sentences the person never uttered. For faces, a recurring method is to lure the victim into a video call: the recording of that call is later reused to authenticate against services protected by facial biometrics, such as banking apps. Image and document forgeries, in turn, combine graphic editors, photos obtained from public databases, and automatic translators. In every scenario, the technical material comes wrapped in social engineering: the scammer gathers information about the victim and the context to lend credibility to the fake content.

"The deepfake is rarely perfect: manipulation leaves technical and contextual traces, and methodical examination exists to expose them."

The traces the examination looks for

Voice. The forensic phonetics examination compares the questioned audio with authentic samples of the attributed voice: prosody, speech rhythm, breathing pauses, ambient noise, and artifacts characteristic of synthesis. Cloned voices tend to show artificial regularity in intonation, abrupt transitions between segments, and the absence of the natural micro-events of spontaneous speech, elements that spectral analysis brings to light.

Video and image. In manipulated videos, the examination looks for inconsistencies in lighting and shadow, lip-sync failures, irregular edges around the face region, and compression artifacts incompatible with the rest of the frame. In still images, analysis of editing layers identifies inserted or retouched regions, such as a superimposed face or a blurred stretch of text over the original photo.

Metadata and origin. Every digital file carries information about its creation: dates, generating software, conversion history, and forwarding chain. Confronting this data with the presented narrative frequently reveals the fraud even before the content examination. Preservation with an integrity record (hash) ensures that the material examined is the same material that was received.

Context. A case examined in a news report illustrates the weight of this axis. A poster that supposedly offered a reward for the death of a member of parliament, attributed to a foreign group, showed text with the typical marks of machine translation, an amount expressed in Brazilian reais (rather than in the currency one would expect from the alleged origin), a photo taken from a Brazilian public database with editing over the mouth, and, the decisive element, a QR Code that pointed to a tip line service in Rio de Janeiro, inherited from the image used in the montage. The set of incongruities demonstrated it was a fabricated piece, without prejudice to it still constituting a legally relevant threat.

What to do upon receiving suspicious content

The first step is to preserve. The original file must be kept on the device and in the conversation where it arrived, without forwards that degrade quality and metadata, and without edits. It is worth recording the date, time, origin, and context of receipt. The second is to confirm through another channel: a direct call to the person supposedly depicted, with questions about facts only they would know, usually dismantles the scam in minutes, because the criminal rarely masters the history of the relationship between the parties.

On the preventive side, the basics apply: do not send selfie-mode photos to unknown contacts, much less holding documents; restrict video calls to trusted people; and adopt a second authentication factor beyond biometrics, such as a password or token, since a face and a fingerprint cannot be replaced once compromised.

When to engage the forensic expert

The forensic examination becomes necessary when the suspicious content produces consequences: consummated financial fraud, harm to honor or image, blackmail, use in judicial or disciplinary proceedings. The expert report documents the method applied, the traces identified, and the chain of custody of the material, elements that sustain the evidentiary debate in court. The work serves both sides of the question: to demonstrate that an audio or video is fabricated, and equally to sustain the authenticity of a legitimate recording that the opposing party tries to dismiss as a deepfake.

There is, finally, the matter of counter-proof. The same technology that fabricates the fake feeds a new defense: claiming that genuine content is a deepfake. The forensic answer is symmetrical in both directions, and that is why the examination never starts from the conclusion the party desires: it starts from the traces. Authentic material exhibits a coherence that fabrication cannot yet fully reproduce, and fabricated material betrays the process that generated it. Between the accusation and the denial, what decides is the examination.

The sooner the material reaches examination, the greater the chances of preserving the traces intact. Faced with suspicious content with litigation potential, the natural path is the Forensic Phonetics practice or an initial feasibility consultation, at no cost, to assess what the case requires.

VALLIM

Adriano Vallim

Forensic expert specializing in digital crimes, working across computer forensics, handwriting and document examination, and forensic phonetics. He combines technical, academic and institutional credentials that place him among the most complete references in the field in Brazil. See the full background →

Read next

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination