Research · September 2026

Sightova V3: how our AI image detector performs

How we built our newest detection model, how we test it, and where it still falls short.

Contents
  1. 01Overview
  2. 02Why now?
  3. 03What V3 detects
  4. 04How we built it
  5. 05Evaluation and testing
  6. 06Document forgery
  7. 07Watermarks
  8. 08Limitations
  9. 09What's next
  10. 10References
01

Overview

Sightova V3 is the model behind every AI-image check on Sightova, in the dashboard and through the API. It detects images from all of the major AI image generators, including OpenAI's GPT Image, Google's Nano Banana, FLUX, Midjourney, Stable Diffusion, Seedream, Qwen-Image and Grok. Unlike most AI image detectors, it also detects AI edits of real photos and deepfakes and face swaps, and it shows a heatmap of the regions it believes were changed.

0.34%
false positive rate on real-world web images
about 1 in 293
99.0%
of GAN-generated images detected
ForenSynths
95.7%
of AI-edited portraits detected
0.5% false positives
0.987
AUROC on Celeb-DF v2 face swaps

False accusations do real harm, so we tuned V3 to be conservative. On 49,907 pre-2022 images from ReLAION, a diverse sample of the public web, V3 wrongly flags 0.34% as AI.

We publish our methodology, our results and our failure cases below. We don't publish the composition of our training data.

02

Why now?

AI-generated images have become photorealistic. Counting fingers or looking for garbled text no longer works: current models follow instructions precisely and render hands, text and lighting convincingly.

The most common fake we see in 2026 isn't a fully generated image. It's a real photo that someone changed with an AI editor: a new background, a different outfit, another person placed into the scene, a forged receipt. Commercial editors make this a one-line prompt. A detector that only recognises fully generated images misses exactly the fakes trust-and-safety, fraud and identity teams care about most.

Watermarks help but aren't enough. OpenAI and Google embed invisible watermarks, and Sightova decodes them (see Watermarks). But most generators don't watermark at all, metadata is stripped by every major platform, and watermarks can be removed. A missing watermark tells you nothing, so a detector has to work from the pixels alone.

03

What V3 detects

  • Fully AI-generated images from current and older generators: GPT Image, Nano Banana, Nano Banana Pro, FLUX, Midjourney, Stable Diffusion, DALL·E, Imagen, Seedream, Ideogram, Recraft, Qwen-Image, Z-Image, Grok and GAN-based models.
  • AI edits of real photos, from editors that regenerate the whole image (GPT Image, Nano Banana, Qwen-Image-Edit) as well as inpainting tools that only change one region.
  • Deepfakes and face swaps, including face-swap, face-reenactment and talking-head methods.
  • A heatmap of the regions the model believes were changed. It's trained on masks of real edits, so it points to the edited region rather than just repeating the overall verdict.
  • Forged documents (IDs, passports, receipts, forms) with a separate model. See Document forgery.

An image is labelled AI-generated when the model's probability is at least 0.85. Every detection and false positive rate in this report uses that production threshold.

04

How we built it

Architecture

V3 builds on DINOv3, Meta's self-supervised vision foundation model. DINOv3 learns general properties of images from a very large collection of photographs without labels, by teaching a "student" network to match a "teacher" across different views of the same image. The resulting features capture both fine local texture and global structure, which is exactly what AI image detection needs.

We use the large ViT-L/16 variant and fully fine-tune the whole network, not just a classifier on frozen features, so the representation itself adapts to the difference between camera and generator pixels. V3 looks at the whole image at 512 × 512, more than twice the resolution of our previous model, and has two outputs: an overall probability that the image is AI-generated, and a 32 × 32 map of which regions were edited.

Training

The composition of the training data matters more than anything else we tried. V3 is trained on a large, balanced mix of genuine and AI images:

  • Genuine images covering everyday and web photography, people and portraits, landscapes, and unprocessed camera originals from a wide range of phones and cameras.
  • AI images from GAN, diffusion, flow-matching and autoregressive generators released between 2018 and 2026, from both open-weight models and commercial APIs.
  • AI edits with pixel masks, so the model learns what a locally edited region looks like and the heatmap learns where it is.
  • Face swaps and reenactments, alongside genuine face video, so that faces alone never become evidence of AI.

Images are distorted in many ways as they're shared online, so during training we layer strong augmentations: JPEG and WebP recompression, resizing, blur, noise, colour shifts, screenshots and social-media style recompression. We apply them equally to genuine and AI images, so compression can never become a shortcut for either answer.

Before any image enters training, we compare it against every image in our evaluation sets by exact hash and perceptual hash and reject near-duplicates. None of the third-party benchmarks below contributed training images.

05

Evaluation and testing

We evaluate every model release on the same frozen, hash-pinned image sets, using the exact production weights and preprocessing. We use one global threshold (0.85): no per-benchmark tuning and no test-time tricks.

False positives

The false positive rate is the share of genuine images that V3 wrongly labels as AI. It's the number we optimise for first.

Genuine images (n)False positives
ReLAION, pre-2022 web images (49,907)0.34%
Smartphone portraits (5,236)0.52%
Museum art (prints, drawings, paintings) (4,509)0.84%
ForenSynths real photos (45,169)1.80%
DailyBench real photos (129,390)4.18%
WikiArt paintings (2,000)7.85%

Ordinary photographs, including smartphone photos of people, are flagged well under 1% of the time. Human-made art is the main exception; we cover it below.

AI image generators

Share of each generator's images that V3 labels as AI:

GeneratorDetectedSource
FLUX.199.3%DailyBench
Nano Banana99.1%Nano Banana 1500
Qwen-Image97.7%DailyBench
Nano Banana 297.1%DailyBench
Nano Banana Pro97.0%Nano Banana Pro
Stable Diffusion 3.595.7%DailyBench
GPT Image 294.5%DailyBench
FLUX.287.8%DailyBench
Z-Image86.1%DailyBench
GAN models (ProGAN, StyleGAN 1/2, BigGAN, GauGAN, …)99.0%ForenSynths

AI edits

A real photo with one AI-edited region is the hardest case for any detector, because most of the pixels are authentic. Editors that regenerate the whole frame are detected reliably. Editors that change only a small region and leave every other pixel untouched are detected far less often; for those, the heatmap is often more informative than the overall verdict.

Editor (DailyBench ManipulationBench)Detected
Qwen-Image-Edit89.8%
GPT Image 286.3%
Step1X-Edit49.4%
FLUX, object insertion38.9%
FLUX, random region inpainting36.4%
Nano Banana 2, region edits27.2%
FLUX.2 Klein25.4%

AI-edited portraits

We keep an internal hold-out set of genuine smartphone portraits and AI edits of them made with three commercial editors, the kind of fake photo of a real person that platforms see every day. One of the editors, Qwen-Image 2.1, was deliberately kept out of training to test how V3 handles an editor it has never seen.

Detected / false positives
GPT Image 2.5 edits93.1%
Nano Banana 2 edits96.6%
Qwen-Image 2.1 edits (never seen in training)97.0%
Genuine portraits (false positives)0.5%

Deepfakes and face swaps

We score individual face frames from the standard deepfake benchmarks, one frame per image, without any temporal information.

BenchmarkDetectedFalse positivesAUROC
Celeb-DF v295.6%5.2%0.987
DF40 (InSwapper, SimSwap, SadTalker)94.0%7.6%0.980
DFDC93.1%22.5%0.940
FaceForensics++79.1%11.2%0.914
DeepFakeDetection51.4%7.3%0.831

Most false positives here come from the genuine frames of these 2019–2020 video datasets, which are small, blurry and heavily compressed. Ranked against ordinary web photos instead, the fakes from every one of these datasets reach an AUROC of 0.97 or higher.

Human art

We know that wrongly calling an artist's work AI causes real harm. Photographs of physical artworks from public-domain museum collections are rarely flagged (0.8%). Digital scans of paintings are harder: on 2,000 WikiArt paintings, V3 flags 7.8%. That's not good enough, and it's the first thing our next release fixes; the model in validation today cuts it to 4.6%.

Third-party benchmarks

Coming soon
We are finishing the evaluation of V3 on Synthbuster + RAISE-1k, NTIRE 2026, MIRAGE and AI Detector Arena, and will publish the results here.
06

Document forgery

Document checks use a separate model with the same architecture, trained at a higher resolution (768 × 768) so that small text edits stay visible. It returns a probability that the document was tampered with and a heatmap of the tampered region.

BenchmarkDetectedFalse positives
DocTamper (text tampering)99.2%—
IDNet (identity documents)97.3%1.0%
SIDTD (identity documents)93.6%0.2%
Genuine receipts (CORD, WildReceipt)—0.4–0.5%
Genuine ID specimens (PRADO)—1.0%

It's strong on the manipulations fraud teams see most: text tampering, ID photo replacement and face morphing. It's weaker on documents edited with the newest commercial AI editors and on manual edits made in desktop paint programs, and we're working on both.

07

Watermarks

GPT Image outputs carry an invisible watermark. Sightova detects it on every check and reports it separately from the model verdict. A detected watermark is strong evidence; a missing one is no evidence of authenticity.

ImagesResult
Native GPT Image outputs (972)100% detected
… after JPEG compression, resizing or light cropping100% detected
Genuine photos, paintings and 28 other generators (4,213)0 false positives

Google's SynthID watermark in Nano Banana images is in validation and not yet part of the product.

08

Limitations

  • Small local edits to an otherwise genuine photo are often missed by the overall verdict. A negative result doesn't rule out a partial edit; check the heatmap.
  • Digital art and scans of paintings are flagged more often than photographs.
  • Heavily compressed video stills of real faces can be flagged, which matters when checking frames from old or low-quality video.
  • New generators may evade detection until they're represented in training. We re-test every release against the sets in this report.
  • Adversarial attacks built specifically against V3 haven't been evaluated.
  • Very small images (under 256 px) carry little evidence, and video is analysed frame by frame.
09

What's next

Our next release is already in validation. It substantially reduces false positives on human-made art and adds more of the newest editors. We'll keep pushing the false positive rate down, improve detection of small local edits, and bring Google SynthID decoding into the product.

If you're a researcher or an enterprise team and want to test V3 on your own data, get in touch.

10

References

  1. Siméoni, O. et al. DINOv3. Meta AI, 2025.
  2. Bammey, Q. Synthbuster: Towards Detection of Diffusion Model Generated Images. IEEE OJSP, 2023.
  3. Gushchin et al. NTIRE 2026 Challenge on Robust AI-Generated Image Detection in the Wild. CVPR Workshops, 2026.
  4. Wang, S.-Y. et al. CNN-generated images are surprisingly easy to spot… for now (ForenSynths). CVPR, 2020.
  5. Rössler, A. et al. FaceForensics++: Learning to Detect Manipulated Facial Images. ICCV, 2019.
  6. Li, Y. et al. Celeb-DF: A Large-scale Challenging Dataset for DeepFake Forensics. CVPR, 2020.
  7. Dolhansky, B. et al. The DeepFake Detection Challenge (DFDC) Dataset. arXiv, 2020.
  8. Yan, Z. et al. DF40: Toward Next-Generation Deepfake Detection. NeurIPS Datasets and Benchmarks, 2024.
  9. DailyBench (FakeBench and ManipulationBench), 2026.
  10. Gowal, S. et al. SynthID-Image: Image watermarking at internet scale. arXiv:2510.09263, 2025.