Skip to content

1B – Professional Verification

Professional Verification is the thirty-minute desk pass a fact-checker runs after First-Line Triage has flagged a case as worth more time. The work happens at a laptop with browser tools, sometimes on an offline machine when source-protection requires it, and produces an evidentiary record of an image, a video, an audio clip, or a textual claim before it heads to a desk editor or a coalition partner. The intended reader is a working journalist or OSINT operator on a typical assignment day – Watchdog Sri Lanka mid-investigation, Rappler verification on the morning queue, MAFINDO desk staff stepping in after Kalimasada tipline routing. What this section gives you: the five 1B cells, the toolkit's editorial position on detector reliability at this tier (it is unreliable, and we say so), the discipline that pairs each detector signal with non-detector evidence under Architectural Anchor 2, and the onward routes to 1C Institutional Analysis and to 2A AI-Assisted Workflows.

When this tier applies

A video clip flagged at 1A as not yet resolved – reverse search produced nothing decisive, the deepfake tab returned a mid-range probability, no Content Credentials manifest was present – lands on a desk reporter's queue in Manila. The reporter has thirty minutes before the next editorial check-in and runs the full InVID-WeVerify pass: keyframes pulled, reverse search across five engines, WACZ archive captured, EXIF and metadata extracted, deepfake tab invoked only after the non-detector modules surface no resolution. That is the standard 1B.1 workflow.

A press release shared through a CekFakta partner's tipline reads as suspiciously fluent for the named ministry's usual voice. The desk editor wonders whether the text was AI-generated. 1B.2 provides the productive answer: text-detection tools are structurally unreliable, especially on non-English material; the right move is to treat any detector verdict as one weak signal and pair it with claim-extraction work in 2B.2 and source-reliability scoring in 1B.5. The 1B.2 cell is deliberately thin because the detector class is thin.

A Lao political voice clip reaches a Watchdog operator from a diaspora source. 1B.3 is the productive ceiling for audio work at this tier: three viable detectors, all weak, all paired with a binding "no public claim without a non-detector signal" framing. The pass produces a defensible case file for editorial review, not a verdict.

A still image extracted from a Facebook Group repost shows EXIF-stripped metadata. 1B.4 reads the absence of metadata as a signal in itself – most platforms strip EXIF on upload, and recognising that pattern matters as much as reading what metadata remains. ELA, copy-move detection, and metadata extraction round out the cell.

The article the editor wants to vet was published by an outlet the desk does not recognise. 1B.5 is the source-history pillar in its purest 1B form: pull existing fact-check work via Google Fact Check Explorer, check outlet reliability via NewsGuard, reach for the AI Disinfo Hub knowledge layer when the case warrants it.

How techniques in this tier connect

1B.1 is the hub. Most cases enter through it because the multi-tool plugin pass produces the broadest non-detector signal set in the shortest time. From 1B.1 cases route laterally to 1B.4 when metadata anomalies surface, to 1B.3 when an audio track needs forensic work, to 1B.5 when the question shifts from "is this content AI-generated" to "is the outlet reliable", and to 1B.2 in the (limited) cases where text generation is at issue. The decision trees codify these routes: T1 image triage, T2 video triage, and T3 audio triage all flow into 1B work after their first-line gates close, and T5 escalation is the conflict-resolution layer when detectors disagree or when 1B work surfaces a case that needs institutional-grade tooling.

The toolkit's editorial position at this tier is the same one Anchor 2 enforces everywhere else, but it bites harder here because the detector class is more present in working journalists' minds at 1B than at any other tier. Two non-detector signals are required before any synthetic label is published. Multi-detector consensus counts as one signal class under Anchor 3 – running InVID's deepfake tab plus a separate Deepware run produces one detector reading, not two. The productive 1B pass spends most of its thirty minutes on reverse-image work, archived versions, metadata, and source-reliability lookup, and reaches a detector tab only after non-detector signals have been exhausted.

Source-protection is load-bearing at 1B because the cell-level tool choice often turns on whether the source file can leave the user's machine. 1B.1 ships four tools precisely so that the user can match the tool to the threat model: InVID-WeVerify as the cloud-mitigated default, ExifTool at the command line for batch work, Sherloq for offline desktop when upload itself is the risk, MetadataKit for the browser-WASM alternative when the user wants metadata locally without server contact. T6 source-protection is the binding routing layer here – read it alongside any 1B work where the source file is identifying or where the user operates in a surveillance-environment country.

What this tier produces

A defensible evidentiary record of an image, a video, an audio clip, or a textual claim that an editor, a coalition partner, or a desk lawyer can read without re-deriving the chain of custody. The record carries the non-detector signals that drive the case – reverse-image hits with URLs and timestamps, archived versions, metadata extraction with timestamps, fact-check database hits – plus any detector reading wrapped as one weak signal class. A 1B pass that closes the case ends with a publishable verification note. A 1B pass that does not close the case ends with a clean handover to 1C or to a coalition partner, with the evidence already structured.

When to escalate, when to stop

Escalate to 1C Institutional Analysis when the case requires institutional-grade evidence – broadcaster-level deepfake certification, a defamation-defence pixel map, partner-mediated access to enterprise tooling, or coordinated-inauthentic-behaviour analysis on a network of accounts and posts. Move sideways to 2A AI-Assisted Workflows when 1B has confirmed AI generation and the next step is a counter-disinformation response – prebunking outputs, archived material for downstream reporting, transcription for the editorial pipeline. Move forward to 2B Collaborative Verification when the case is one of many similar incoming claims and the productive next step is tipline-grade routing and AI-assisted claim extraction.

Stop when 1B has produced a defensible verification note and the case does not warrant the kinds of institutional weight 1C provides. Most 1B work closes at 1B; the T5 escalation tree makes the gate explicit so a reporter under deadline pressure does not slide into rabbit-hole institutional work that the case does not need.

The cells in detail

1B.1 – Multi-tool plugins

This is where a working fact-checker spends most desk time. The multi-tool plugin pass is the assembly line of Pillar 1: keyframes pulled in one tab, reverse-image work running in the next, EXIF and metadata captured in a third, archived versions snapshotted to WACZ in a fourth, deepfake tab invoked only if the non-detector modules surface no resolution. Four tools cover the cell, each anchored to a specific source-protection posture.

InVID-WeVerify is the cloud-mitigated default and the documented workhorse of AFP Fact Check, Bellingcat, VERA Files, and Rappler's Doc Willie Ong pipeline. Its non-detector modules (reverse-image, archived versions, metadata, OCR) operate without uploading the source file to InVID-controlled servers, while the deepfake tab uploads frames to CERTH with a 30-day retention window – which is why the S1 source-identifying upload override binds on the deepfake tab specifically and is rendered as a !!! danger admonition on the InVID card. ExifTool is the command-line standard for batch work and scripted archival pipelines; non-destructive metadata extraction with no upload, low-risk by design. Sherloq is the offline desktop alternative for Sri Lanka and Lao surveillance-environment work where the source file cannot leave the machine. MetadataKit is the browser-WASM alternative when the user wants metadata locally without server contact.

All four are non-detector signal generators under Architectural Anchor 1 and combine cleanly across Anchors 2 and 3. The binding caveat on every 1B.1 card is source-protection mitigation – every tool card in this cell carries an explicit S1 mitigation note, because the cell sits at the interface between cloud-friendly Western OSINT practice and the surveillance-environment reality of much of the toolkit's audience. T6 source-protection is the routing layer; read it before invoking any cloud-tier 1B.1 tab on identifying material.

Worked case: four signals on one clip

A video clip flagged at 1A as not yet resolved lands on a desk reporter's queue, thirty minutes before the next editorial check-in. Run it as a four-signal pass.

  • Provenance. No Content Credentials manifest is present, so provenance has nothing to read.
  • Source-history. Reverse search across five engines returns nothing decisive; a WACZ archive captured, EXIF and metadata extracted, and still no prior-circulation match.
  • Behaviour. Not engaged here, by design. One artefact on one queue gives no coordination signal to run; behaviour-class work (CIB, account clusters) belongs at 1C.1 and 2C, not in a single-clip desk pass.
  • Cautious-detector. The deepfake tab, invoked only after the non-detector modules surface no resolution, returns a mid-range probability. It counts as one detector signal class under Anchor 3.

Decision. The case does not close. A mid-range detector reading is one weak signal, and Anchor 2 needs two non-detector signals from different pillars before any synthetic label. With provenance absent and source-history inconclusive, that floor is not met: the defensible output is "tool flagged for review", and the pass hands the structured evidence to 1C or a coalition partner.

Reasoning. A detector verdict on its own never earns a synthetic label; the publishable call here is "insufficient evidence", not "deepfake".

1B.2 – AI text detection

The user reaches this cell asking "can I prove this article or social-media post was written by an LLM" and the toolkit's answer is plain: not reliably, especially in non-English. AI text detection sits at this tier because it is desk-grade work – nobody runs GPTZero in a five-minute phone scan and treats the result as evidence – but the detector class is structurally unreliable enough that the cell ships only two tools, both as cautionary cases, with a binding "do not use as standalone evidence" framing across both.

Pangram AI is the more defensible current vendor, with documented multilingual coverage; the vendor claim of 99%+ accuracy is paired against the Deepfake-Eval-2024 benchmark finding that no independent assessment has been located. GPTZero is the alternative, kept in the toolkit as the clearest cautionary tale: the Stanford 2023 study found a 61% false-positive rate on non-native English writing, the Perkins 2024 figure runs at 26.4%, and neither tool has been independently benchmarked on Bahasa Indonesia, Lao, Malay, Filipino, Sinhala, Tamil, or Thai.

The productive move when text generation is at issue is to combine a 1B.2 detector reading with non-detector signals from 2B.2 claim extraction – the cell where Watchdog's Dissect, MAFINDO's Yudistira, and Meedan Alegre actually live – and source-reliability scoring from 1B.5. The 1B.2 detector verdict is one weak signal class under Anchor 2 and never sufficient on its own for a public claim. The T5 escalation tree routes 1B.2 cases through T5.9 (text professional) when the case warrants more than a desk read; there is no 1C cell for text detection because no tool earns it.

1B.3 – Audio deepfake forensics

When a Lao political voice clip, a Thai scam call, or a Tagalog candidate-impersonation audio reaches a fact-checker for a thirty-minute desk pass, this is where it lands. The category remains constrained by the DW Innovation Synthetic Audio Detectors Put to the Test audit (September 2025), which tested the leading vendors across a ten-sample multilingual dataset and confirmed that no single detector handles SEA-language audio reliably. Three tools and one framework anchor the cell.

Deepfake Total is the strongest audited single-tool option (7-of-10 correct in the DW audit). Hiya Loccus is the press-button SEA option integrated into the InVID voice-clone module; the DW audit returned 4-of-10 correct, 3-of-10 mis-id, 3-of-10 inconclusive – the figures the toolkit's content policy makes binding on the Hiya card. TrueMedia / Georgetown is the beta-gated escalation option following the McCourt School revival announced in May 2026. DW Innovation Audit sits in the cell as the editorial reference – not a detector itself but the framework the toolkit cites when explaining why the detector class is the way it is.

In workflow terms, the desk pass runs Deepfake Total first, runs Hiya in parallel through InVID, and requests TrueMedia beta access only when the case warrants institutional-grade aggregation. Per Anchor 3 the three together count as one detector class signal; per Anchor 2 a publishable claim still requires a non-detector signal alongside – a caller-verification interview, a platform-of-origin check, a voice-comparison call with someone who knows the subject. The honest gaps the cell carries are multipart and binding: no Lao-language audio detector exists; Sinhala and Tamil sit on opposite sides of the documented Sinhala/Tamil asymmetry (Sinhala has neither tool nor corpus at this tier, Tamil leans on pan-Tamil resources); WhatsApp and LINE codec compressions remain untested in any public audit. The T3 audio triage tree routes the work; the escalation is to 1C.2 for enterprise voice-clone platforms when institutional-grade chain of custody is required.

1B.4 – Metadata / ELA forensics

Once 1B.1 has surfaced a still image worth deeper inspection, this cell is where Error Level Analysis, EXIF reading, and metadata-spoofing checks happen. Three tools cover the cell at three different source-protection postures.

ExifTool is the command-line standard – non-destructive metadata extraction, no upload, low-risk. Sherloq is the offline desktop alternative for surveillance-risk countries (Sri Lanka, Laos) where the source file cannot leave the machine. FotoForensics is the cloud ELA option for low-sensitivity material; the upload-classification gate at S1 is binding on the FotoForensics card because the cloud route is the cell's only tool that requires hosted processing.

All three are non-detector source-history signals under Anchor 1. Metadata is spoofable, so the cell carries a verbatim metadata-spoofable caveat on every card – a metadata anomaly is one weak signal, never a verdict. The bigger insight the cell teaches is the absence pattern: most images encountered through WhatsApp, Facebook, or TikTok have already had EXIF stripped on upload, and the absence of metadata where there should be some is a signal in itself, not a tool failure. The fact-checker who recognises EXIF absence as a signal saves time at 1B.4 and routes faster to reverse-image work. Escalation from 1B.4 climbs to 1C.3 explainable AI forensics when ELA suggests manipulation but the case requires legal-grade visual justification.

1B.5 – News-reliability scoring

When the question shifts from "is this AI-generated" to "is the outlet that published it reliable", this is the cell. The source-history pillar in its purest 1B form. Three tools cover the cell at three different layers of depth and access.

Google Fact Check Explorer is the default first stop – it returns existing fact-check work and ClaimReview metadata across languages, including Bahasa Indonesia. NewsGuard is the paid reliability-scoring service that covers 16 languages, with Indonesian, Tagalog, and Thai inside its scope; the 1B.5 use is to query an unfamiliar outlet's reliability rating before any further verification work. AI Disinfo Hub is the EU DisinfoLab knowledge layer for institutional readers when the case warrants the broader actor-mapping context.

Per Anchor 2 a reliability-score signal is one non-detector signal class and combines with claim extraction (2B.2) or behavioural pattern analysis (2C.1) before any public characterisation of an outlet. The cell-level honest gap binds the toolkit's Sri Lanka / Laos work: NewsGuard does not cover Sinhala or Lao outlets, so Watchdog, Hashtag Generation, FactSeeker, and Fact Crescendo Sri Lanka rely on the local fact-check ecosystem plus Google Fact Check Explorer plus their own Sinhala / Tamil OSINT capacity. The bridge downward is to 1B.2 if the question is about generated text and not outlet reliability; the bridge upward is to 2C.1 automated claim monitoring when the case scales to cross-platform pattern work.

Cross-references

Sources

  • DW Innovation. Synthetic Audio Detectors Put to the Test. Deutsche Welle, 29 September 2025. innovation.dw.com/articles/synthetic-audio-detectors-tested. (Hiya 4-of-10, Deepfake Total 7-of-10; Lao audio gap; WhatsApp / LINE codec failure at 1B.3.)
  • Perkins, M. et al. GPT-4 Is Slightly Helpful for Peer-Reviewers: Experimental Evidence. 2024. (GPTZero 26.4% false positive rate; baseline for AI-text-detection caveats at 1B.2.)
  • LIRNEasia. Misinformation and Language Resources. LIRNEasia, 2025. lirneasia.net/themes/misinformation-and-language-resources. (Sinhala / Tamil asymmetry; Watchdog stylometric pipeline at 1B.1.)
  • Agence France-Presse. AFP Chulalongkorn InVID Digital Verification Training. AFP, August 2025. afp.com/en/agency/facts. (AFP Chulalongkorn August 2025 InVID training context for 1B.1.)
  • Country pages: Philippines (Rappler / VERA Files pipeline through 1B.1), Sri Lanka (Watchdog desk practice; surveillance-environment 1B.1 / 1B.4).
  • Architectural Anchors — Anchors 1, 2, and 3 as operationalised across the 1B cells.