Contents
Overview
Sightova V3 is the model behind every AI-image check on Sightova, in the dashboard and through the API. It detects images from all of the major AI image generators, including OpenAI's GPT Image, Google's Nano Banana, FLUX, Midjourney, Stable Diffusion, Seedream, Qwen-Image and Grok. Unlike most AI image detectors, it also detects AI edits of real photos and deepfakes and face swaps, and it shows a heatmap of the regions it believes were changed.
False accusations do real harm, so we tuned V3 to be conservative. On 49,907 pre-2022 images from ReLAION, a diverse sample of the public web, V3 wrongly flags 0.34% as AI.
We publish our methodology, our results and our failure cases below. We don't publish the composition of our training data.
Why now?
AI-generated images have become photorealistic. Counting fingers or looking for garbled text no longer works: current models follow instructions precisely and render hands, text and lighting convincingly.
The most common fake we see in 2026 isn't a fully generated image. It's a real photo that someone changed with an AI editor: a new background, a different outfit, another person placed into the scene, a forged receipt. Commercial editors make this a one-line prompt. A detector that only recognises fully generated images misses exactly the fakes trust-and-safety, fraud and identity teams care about most.
Watermarks help but aren't enough. OpenAI and Google embed invisible watermarks, and Sightova decodes them (see Watermarks). But most generators don't watermark at all, metadata is stripped by every major platform, and watermarks can be removed. A missing watermark tells you nothing, so a detector has to work from the pixels alone.
What V3 detects
- Fully AI-generated images from current and older generators: GPT Image, Nano Banana, Nano Banana Pro, FLUX, Midjourney, Stable Diffusion, DALL·E, Imagen, Seedream, Ideogram, Recraft, Qwen-Image, Z-Image, Grok and GAN-based models.
- AI edits of real photos, from editors that regenerate the whole image (GPT Image, Nano Banana, Qwen-Image-Edit) as well as inpainting tools that only change one region.
- Deepfakes and face swaps, including face-swap, face-reenactment and talking-head methods.
- A heatmap of the regions the model believes were changed. It's trained on masks of real edits, so it points to the edited region rather than just repeating the overall verdict.
- Forged documents (IDs, passports, receipts, forms) with a separate model. See Document forgery.
An image is labelled AI-generated when the model's probability is at least 0.85. Every detection and false positive rate in this report uses that production threshold.
How we built it
Architecture
V3 builds on DINOv3, Meta's self-supervised vision foundation model. DINOv3 learns general properties of images from a very large collection of photographs without labels, by teaching a "student" network to match a "teacher" across different views of the same image. The resulting features capture both fine local texture and global structure, which is exactly what AI image detection needs.
We use the large ViT-L/16 variant and fully fine-tune the whole network, not just a classifier on frozen features, so the representation itself adapts to the difference between camera and generator pixels. V3 looks at the whole image at 512 × 512, more than twice the resolution of our previous model, and has two outputs: an overall probability that the image is AI-generated, and a 32 × 32 map of which regions were edited.
Training
The composition of the training data matters more than anything else we tried. V3 is trained on a large, balanced mix of genuine and AI images:
- Genuine images covering everyday and web photography, people and portraits, landscapes, and unprocessed camera originals from a wide range of phones and cameras.
- AI images from GAN, diffusion, flow-matching and autoregressive generators released between 2018 and 2026, from both open-weight models and commercial APIs.
- AI edits with pixel masks, so the model learns what a locally edited region looks like and the heatmap learns where it is.
- Face swaps and reenactments, alongside genuine face video, so that faces alone never become evidence of AI.
Images are distorted in many ways as they're shared online, so during training we layer strong augmentations: JPEG and WebP recompression, resizing, blur, noise, colour shifts, screenshots and social-media style recompression. We apply them equally to genuine and AI images, so compression can never become a shortcut for either answer.
Before any image enters training, we compare it against every image in our evaluation sets by exact hash and perceptual hash and reject near-duplicates. None of the third-party benchmarks below contributed training images.
Evaluation and testing
We evaluate every model release on the same frozen, hash-pinned image sets, using the exact production weights and preprocessing. We use one global threshold (0.85): no per-benchmark tuning and no test-time tricks.
False positives
The false positive rate is the share of genuine images that V3 wrongly labels as AI. It's the number we optimise for first.
| Genuine images (n) | False positives |
|---|---|
| ReLAION, pre-2022 web images (49,907) | 0.34% |
| Smartphone portraits (5,236) | 0.52% |
| Museum art (prints, drawings, paintings) (4,509) | 0.84% |
| ForenSynths real photos (45,169) | 1.80% |
| DailyBench real photos (129,390) | 4.18% |
| WikiArt paintings (2,000) | 7.85% |
Ordinary photographs, including smartphone photos of people, are flagged well under 1% of the time. Human-made art is the main exception; we cover it below.
AI image generators
Share of each generator's images that V3 labels as AI:
| Generator | Detected | Source |
|---|---|---|
| FLUX.1 | 99.3% | DailyBench |
| Nano Banana | 99.1% | Nano Banana 1500 |
| Qwen-Image | 97.7% | DailyBench |
| Nano Banana 2 | 97.1% | DailyBench |
| Nano Banana Pro | 97.0% | Nano Banana Pro |
| Stable Diffusion 3.5 | 95.7% | DailyBench |
| GPT Image 2 | 94.5% | DailyBench |
| FLUX.2 | 87.8% | DailyBench |
| Z-Image | 86.1% | DailyBench |
| GAN models (ProGAN, StyleGAN 1/2, BigGAN, GauGAN, …) | 99.0% | ForenSynths |
AI edits
A real photo with one AI-edited region is the hardest case for any detector, because most of the pixels are authentic. Editors that regenerate the whole frame are detected reliably. Editors that change only a small region and leave every other pixel untouched are detected far less often; for those, the heatmap is often more informative than the overall verdict.
| Editor (DailyBench ManipulationBench) | Detected |
|---|---|
| Qwen-Image-Edit | 89.8% |
| GPT Image 2 | 86.3% |
| Step1X-Edit | 49.4% |
| FLUX, object insertion | 38.9% |
| FLUX, random region inpainting | 36.4% |
| Nano Banana 2, region edits | 27.2% |
| FLUX.2 Klein | 25.4% |
AI-edited portraits
We keep an internal hold-out set of genuine smartphone portraits and AI edits of them made with three commercial editors, the kind of fake photo of a real person that platforms see every day. One of the editors, Qwen-Image 2.1, was deliberately kept out of training to test how V3 handles an editor it has never seen.
| Detected / false positives | |
|---|---|
| GPT Image 2.5 edits | 93.1% |
| Nano Banana 2 edits | 96.6% |
| Qwen-Image 2.1 edits (never seen in training) | 97.0% |
| Genuine portraits (false positives) | 0.5% |
Deepfakes and face swaps
We score individual face frames from the standard deepfake benchmarks, one frame per image, without any temporal information.
| Benchmark | Detected | False positives | AUROC |
|---|---|---|---|
| Celeb-DF v2 | 95.6% | 5.2% | 0.987 |
| DF40 (InSwapper, SimSwap, SadTalker) | 94.0% | 7.6% | 0.980 |
| DFDC | 93.1% | 22.5% | 0.940 |
| FaceForensics++ | 79.1% | 11.2% | 0.914 |
| DeepFakeDetection | 51.4% | 7.3% | 0.831 |
Most false positives here come from the genuine frames of these 2019–2020 video datasets, which are small, blurry and heavily compressed. Ranked against ordinary web photos instead, the fakes from every one of these datasets reach an AUROC of 0.97 or higher.
Human art
We know that wrongly calling an artist's work AI causes real harm. Photographs of physical artworks from public-domain museum collections are rarely flagged (0.8%). Digital scans of paintings are harder: on 2,000 WikiArt paintings, V3 flags 7.8%. That's not good enough, and it's the first thing our next release fixes; the model in validation today cuts it to 4.6%.
Third-party benchmarks
Document forgery
Document checks use a separate model with the same architecture, trained at a higher resolution (768 × 768) so that small text edits stay visible. It returns a probability that the document was tampered with and a heatmap of the tampered region.
| Benchmark | Detected | False positives |
|---|---|---|
| DocTamper (text tampering) | 99.2% | — |
| IDNet (identity documents) | 97.3% | 1.0% |
| SIDTD (identity documents) | 93.6% | 0.2% |
| Genuine receipts (CORD, WildReceipt) | — | 0.4–0.5% |
| Genuine ID specimens (PRADO) | — | 1.0% |
It's strong on the manipulations fraud teams see most: text tampering, ID photo replacement and face morphing. It's weaker on documents edited with the newest commercial AI editors and on manual edits made in desktop paint programs, and we're working on both.
Watermarks
GPT Image outputs carry an invisible watermark. Sightova detects it on every check and reports it separately from the model verdict. A detected watermark is strong evidence; a missing one is no evidence of authenticity.
| Images | Result |
|---|---|
| Native GPT Image outputs (972) | 100% detected |
| … after JPEG compression, resizing or light cropping | 100% detected |
| Genuine photos, paintings and 28 other generators (4,213) | 0 false positives |
Google's SynthID watermark in Nano Banana images is in validation and not yet part of the product.
Limitations
- Small local edits to an otherwise genuine photo are often missed by the overall verdict. A negative result doesn't rule out a partial edit; check the heatmap.
- Digital art and scans of paintings are flagged more often than photographs.
- Heavily compressed video stills of real faces can be flagged, which matters when checking frames from old or low-quality video.
- New generators may evade detection until they're represented in training. We re-test every release against the sets in this report.
- Adversarial attacks built specifically against V3 haven't been evaluated.
- Very small images (under 256 px) carry little evidence, and video is analysed frame by frame.
What's next
Our next release is already in validation. It substantially reduces false positives on human-made art and adds more of the newest editors. We'll keep pushing the false positive rate down, improve detection of small local edits, and bring Google SynthID decoding into the product.
If you're a researcher or an enterprise team and want to test V3 on your own data, get in touch.
References
- Siméoni, O. et al. DINOv3. Meta AI, 2025.
- Bammey, Q. Synthbuster: Towards Detection of Diffusion Model Generated Images. IEEE OJSP, 2023.
- Gushchin et al. NTIRE 2026 Challenge on Robust AI-Generated Image Detection in the Wild. CVPR Workshops, 2026.
- Wang, S.-Y. et al. CNN-generated images are surprisingly easy to spot… for now (ForenSynths). CVPR, 2020.
- Rössler, A. et al. FaceForensics++: Learning to Detect Manipulated Facial Images. ICCV, 2019.
- Li, Y. et al. Celeb-DF: A Large-scale Challenging Dataset for DeepFake Forensics. CVPR, 2020.
- Dolhansky, B. et al. The DeepFake Detection Challenge (DFDC) Dataset. arXiv, 2020.
- Yan, Z. et al. DF40: Toward Next-Generation Deepfake Detection. NeurIPS Datasets and Benchmarks, 2024.
- DailyBench (FakeBench and ManipulationBench), 2026.
- Gowal, S. et al. SynthID-Image: Image watermarking at internet scale. arXiv:2510.09263, 2025.