Skip to content
Delete Image Metadata
AI Images

How AI Image Detectors Actually Work

They never look at the metadata. Understanding what they do look at explains both why stripping EXIF changes nothing and why real photographs keep getting accused.

9 min read

The short version

An AI image detector does not open the metadata. It never reads the EXIF block, the XMP packet, the C2PA manifest or the PNG text chunks. It decodes the file to a grid of pixels and makes a statistical judgement about those pixels.

This one fact answers the question most people arrive with. Removing metadata from an AI-generated image does not make it less likely to be called AI-generated, because the metadata was never part of the judgement. You can strip every field this site can strip, and a pixel-based detector will return exactly the same score it returned before.

It also answers the question fewer people ask but more people have: if detectors do not read metadata, why did one just accuse a photograph you took yourself?

What a detector is actually measuring

Generative models leave statistical traces in the pixels themselves. Not a watermark and not a signature — an accent, left by the way the image was constructed rather than captured.

Detectors are usually classifiers trained on large sets of known-real and known-generated images. Nobody hand-writes the rules; the model learns whatever separates the two sets. Researchers have identified several families of signal that such classifiers tend to latch onto:

  • Upsampling traces. Diffusion models generate at lower resolution and scale up, which leaves periodic regularities in the frequency domain that cameras do not produce.
  • Noise structure. A camera sensor produces a characteristic noise pattern that varies with the sensor, the ISO and the light. Generated images have noise that is too clean, too uniform, or wrong for the scene.
  • Frequency distribution. Photographs and generated images differ in how energy is distributed across spatial frequencies, particularly at the high end.
  • Local inconsistency. Physically impossible reflections, lighting that disagrees between subject and background, textures that repeat where they should vary.

Why removing metadata cannot move the needle

Metadata and pixels are separate parts of the file. Removing a metadata block deletes bytes that sit outside the compressed image data and leaves the image data untouched — that is the whole point of lossless metadata removal, and it is what makes it safe to run on a photograph you care about.

That safety is exactly why it is useless for evading detection. A process that provably does not alter a single pixel cannot alter the output of a process that reads only pixels.

People sometimes conclude that the answer is therefore to alter the pixels: re-encode heavily, add noise, crop, filter. This guide does not cover those techniques. What is worth knowing is that they trade against the thing you presumably wanted, because degrading an image enough to confuse a classifier degrades it visibly, and detectors are frequently retrained against exactly those manipulations.

Detectors are unreliable in both directions

The accuracy figures published by detection vendors are measured on their own test sets, usually against generators that existed when the classifier was trained. Those numbers do not survive contact with the open internet, where images have been screenshotted, re-compressed, filtered, cropped and passed through three platforms before anyone runs a check.

Two failure modes matter, and they are not symmetric in consequence:

  • False negatives. Generated images that pass as real. Embarrassing for the vendor, but the harm is diffuse.
  • False positives. Real photographs and real artwork labelled as machine-made. The harm here is concentrated on one person, who has to prove a negative.

When a real photograph gets flagged

This happens to photographers, illustrators and students constantly, and the properties that trigger it are often the marks of competence rather than fakery. Clean studio lighting resembles rendered lighting. Heavy retouching smooths the sensor noise a detector expects to find. Shallow depth of field produces the soft, gradient-heavy backgrounds that generators also produce. Aggressive denoising in modern phone cameras removes the exact signal a detector looks for.

If you are on the receiving end of such an accusation, the useful move is not to argue about the detector. It is to produce the evidence a detector never looked at.

  • The original file straight off the camera or phone, unedited and unexported.
  • The RAW file if your camera produced one. A generator does not output RAW, and it is the single strongest artefact you can present.
  • Intermediate saves and edit history from your editor, which show the image being built.
  • Bracketed frames, burst frames or the shots either side of the one in question.

Your metadata is the evidence, not the liability

This site exists to remove metadata, so take this as the exception it is: if there is any chance you will need to prove you made an image, do not strip it first.

The EXIF block on a camera original is the closest thing you have to a provenance record. Camera make and model, lens, exposure, ISO, focal length, the timestamp, the shutter count on some bodies — none of it is proof on its own, and all of it is forgeable by someone determined. But it is internally consistent in ways that are tedious to fake, and it is what an editor, a competition organiser or a platform appeals process will actually ask to see.

Strip it and you have thrown away your own supporting evidence to solve a problem the metadata was not causing.

The sequencing that works: keep untouched originals somewhere safe, and remove metadata from the copies you publish. Privacy on the public copy, evidence in the archive. Those goals only conflict if you keep one file.

What removing metadata from an AI image is genuinely good for

None of the above means AI images have no reason to be cleaned. The reasons are simply different from the one people search for.

  • Prompt confidentiality. Stable Diffusion writes the full prompt, negative prompt, seed, sampler and model hash into a PNG text chunk, and ComfyUI embeds the entire node graph. Publishing the file publishes your method.
  • Client work. An image delivered with a generator tag in the Software field or a C2PA manifest naming the tool tells your client which tool you used and how long it took.
  • File size. A ComfyUI workflow can add tens of kilobytes of JSON to every image.
  • Consistency. If everything else in a set has been cleaned, one file carrying a full generation record is an inconsistency.

One thing that genuinely cannot be removed

Some models embed an invisible watermark in the pixels themselves. Google's SynthID is the widely deployed example, and it is present in the image data, not in any metadata field.

No metadata tool removes it. This one does not, and any tool claiming otherwise is either mistaken about what it is doing or describing something else. It survives cropping, resizing, re-compression and colour adjustment by design, because surviving those is the entire specification.

Being honest about that boundary is the point. A tool that quietly let you believe otherwise would be worse than useless in the exact situation where you were relying on it.

See what an image actually contains

See exactly which AI markers an image carries before you publish it. This tool only reads — nothing is changed, and nothing is uploaded.

Open AI Metadata Checker

Frequently asked questions

Can I remove AI detection from an image?

Not by removing metadata. AI detectors classify the pixels, and metadata removal is lossless by design — it provably does not change a single pixel, so it cannot change what a pixel-based classifier concludes. Any tool advertising metadata removal as a way to defeat detection is describing something it does not do.

Does removing EXIF data make an AI image undetectable?

No. EXIF is a separate block of bytes from the image data, and detectors do not read it. Stripping it changes what the file says about itself and leaves the picture bit-for-bit identical, which is exactly why it has no effect on a detector's score.

Does removing the C2PA manifest help?

It removes the cryptographic provenance record, which is a real and readable statement that the image was generated. But it does not affect pixel-based detection, and on platforms that check for C2PA, a missing manifest can itself be treated as a signal worth noting rather than as a clean bill of health.

Can SynthID be removed?

Not by this tool or any metadata tool. SynthID is embedded in the pixels rather than in a metadata field, and it is specifically designed to survive cropping, resizing and re-compression. We would rather say so plainly than let you assume a cleaned file is free of it.

My photograph was flagged as AI-generated. What should I do?

Produce what the detector never examined: the untouched original off the camera, the RAW file if you have one, intermediate saves from your editor, and the frames shot either side of it. That evidence is far more persuasive to a human reviewer than arguing about a confidence score.

Should I strip metadata from my photos so detectors stop flagging them?

No, and it would work against you. Detectors are not reading the metadata, so removal changes nothing about the flag — while destroying the camera record that is your best evidence of authorship. Keep originals with metadata intact and publish cleaned copies instead.

Are AI image detectors accurate?

Less than their published figures suggest. Vendor accuracy is measured on in-house test sets against the generators available at training time, and it degrades on real-world images that have been re-compressed, cropped or passed through several platforms. False positives on heavily retouched or studio-lit photography are common.

Is there a legitimate reason to remove metadata from an AI image?

Several. Stable Diffusion writes your full prompt, seed and model into the file, and ComfyUI embeds the whole node graph — publishing the image publishes your method. Client deliverables often should not name the tool, and a workflow blob can add tens of kilobytes to every file.