List of all team members: Varvara Boboc, Lonneke van der Velden, Jess Young, Momo Sakai, Victor H. Ábrego, Alexandru Tiță, Jon Nealon, Adrian Bîrzescu, Ángeles Briones
Facilitators: Varvara Boboc, Lonneke van der Velden
Designer: Ángeles Briones
Evidentiary slop a notion that we advance through the insights discovered in our findings. We define it as visual slop that has taken on a forensic cloak: synthetic, manipulated, miscontextualized, or technically disputed imagery presented as proof of a crisis event, or as proof that another image is real or fake, without a transparent and reproducible evidentiary chain. The main takeaway from our results is that slop appropriates the visual language of open-source verification in an attempt to appear evidentiary.
Another takeaway is that forensic ambiguity is a mechanism of delivery; we find that biased information being delivered under guise of neutrality by means of various forensic cues, such as technical traces (i.e., watermarks, tool logos, heatmaps, satellite imagery or other tool outputs) or POV-like content to imitate on-the-ground reporting. Additionally, we note the method of altering the context of the source, such as its claimed location or time.
An interesting angle we explored is noticing absence: what is missing becomes an interpretive clue. We found a systematic absence of people, which normalizes state violence, alongside the presence of technical forensic authenticity cues.
One of the most important implications of our project is the critical importance of interpretative deconstruction. Guided by OSI experts’ insights into fake forensic analysis, we found that interpretative deconstruction and qualitative inspection are fundamental to establish authenticity. Disassembling the slop became a necessary step for verification. Based on our most relevant indicators of synthetic or fake forensic traces, we developed a series of categories to plot the splat: a multi-axis measurement of forensic cues that provides unique signatures, which we call the Slopaganda Index.
Given the experimental nature of our project, we branched into several mini-case studies: we explored the usability of LLMs as tools in the analysis of slopaganda; qualitatively analysed slopographics in terms of visual grammatical orders that produce exoticizing imageries of difference; forensically analysed content items to verify their technical authenticity; and used linguistic analysis to infer political grammars within our dataset. The shared conclusion is that automated workflows are not fit for dealing with evidentiary slop on their own. The layers of verification are complex and qualitative, requiring deep contextual and technical understanding of the dataset at hand.
Evidentiary slop is visual slop that has taken on a forensic cloak: synthetic, manipulated, miscontextualized, or technically disputed imagery that is presented as proof of a crisis event, or as proof that another image is real or fake, without a transparent and reproducible evidentiary chain. The term is not used here in the strict legal sense of admitted evidence, but to describe material that performs evidentiary authority in public circulation.
Against this backdrop, this project advances an open-source investigations approach on a corpus of social media posts or related online materials focused on Iran-related crisis imagery. These items may include alleged strike imagery, explosion footage, protest-related material, infrastructure damage claims, military or propaganda visuals, images challenged as fake, and posts that include AI-detection or forensic-looking claims. The project treats each item as a ‘visual claim package’: an image or video still, caption, source, platform context, circulation trail, implied truth claim, and any attached “forensic” or AI-detection claim.
The project investigates how crisis visuals participate in what we might call the destabilization of verifiable reality: the process through which images, captions, technical-looking analyses, and platform circulation make it harder to determine what can be known, verified, or responsibly left unresolved. The purpose is to produce a typology of Iran-related crisis slop strategies, with particular attention to fake forensic authority, miscontextualization, authenticity aesthetics, and the ways visual evidence is made to support more claims than it can bear.
This project is situated at the intersection of digital methods, OSI verification, visual AI critique, disinformation research, and public epistemology. It responds to a growing concern that generative AI is both producing synthetic crisis imagery, but also changing the conditions under which images are trusted, challenged, or dismissed. Traditional OSI workflows have relied on techniques such as source tracing, geolocation, chronolocation, and source triangulation to strengthen the evidentiary status of visual material. However, the spread of AI-generated content, AI-manipulated images, and AI-detection claims complicates these assumptions. A geolocated image does not automatically prove that the attached claim is true. A real event does not guarantee that a specific image is authentic. A technical-looking detection result does not necessarily provide reliable documentation.
Iran-related crisis imagery is a useful case because it concentrates several of these tensions. Visual materials connected to strikes, explosions, protests, military action, infrastructure damage, or propaganda claims may circulate in highly polarized information environments. At the same time, images may be challenged through claims that they are AI-generated, manipulated, fabricated, or technically disproven. In this setting, “verification language” itself can become part of the struggle over reality. Heatmaps, screenshots of AI tools, metadata claims, authenticity scores, or forensic-looking overlays may be used not to clarify evidence, but to produce doubt, denial, or narrative advantage.
The project is guided by a verification approach that treats media as material connected to specific claims. Participants ask: what exactly is being claimed; which parts of the claim can be checked; what visual or contextual evidence is available; and where does the evidence remain insufficient? This is especially important in crisis contexts, where a single image may be used to imply location, timing, perpetrator, weapon, victim group, authenticity, and intent all at once.
The project draws on work carried out by journalists, OSI investigators, fact-checkers, platform researchers, human rights documenters, civil society groups, and publics encountering crisis imagery online. Thus, it aims to contribute with both empirical and methodological layers: by investigating Iran-related crisis slop while also testing a feasible workflow for analyzing visual claim packages under conditions of AI-driven uncertainty.
The initial dataset consists of 24 posts from X (formerly Twitter), ranging from 14 June 2025 to 24 June 2026. It includes various Iran-related war events across this one-year period; the posts were selected to reflect a variety of content typologies (i.e., synthetically produced content, miscontextualized images, etc. — see Table 1 in Methodology) and to include several iterations of claims within the body of the post (i.e., event, location, time, forensic claims, etc. — see Table 3, Claim verification pipeline, in Appendix). The corpus was then qualitatively analysed during the summer school, with a focus on deconstructing the claims and assessing how synthetic forensic cues appear evidentiary.
Core research question
Through which strategies do synthetic, manipulated, miscontextualized, or technically disputed Iran-related crisis images take on evidentiary appearance?
Core aim
The project investigates a bounded but flexible corpus of Iran-related crisis image claims circulating on social media and adjacent online spaces. Each item is treated as a visual claim package: image or video still, caption, source, platform context, circulation trail, implied truth claim, and any attached “forensic” or AI-detection claim.
The aim is not to decide whether images are real or fake. Instead, the project examines how crisis visuals participate in the destabilization of verifiable reality, especially when AI-generated content, authentic footage, miscaptioned material, and fake or weak forensic analysis circulate together.
The project focuses on several questions:
The methodological design accounts for open-source verification workflows such as visual inventories, claim verification and source tracing, as well as qualitative approaches to analyze how synthetic or miscontextualized forensic cues articulate to form evidentiary appearance and authority.
Figure 1. Visual representation of the methodological workflow
Figure 1 represents a mind map of the methodological workflow. The workflow was supported by a collection of editable templates and typologies that were regularly reassessed against the findings and used during the collaborative coding phase. This allowed us to produce a customized and streamlined working progress inductively aligned to the specific data set and research needs. The following part breaks down the content of each step and clarifies how the decision-making was carried out. The first step was compiling a record of the most important information for each post: metadata, content typology (table 1) and missing elements — such as geolocation references, mentions of people affected by the actions presented, officials and other discrepancies. This preservation step also represents an adjusted archival effort, resembling conventional open-source investigations methodology.
| Content typology category | Working definition |
| AI-generated or suspected synthetic Iran-related crisis images/videos | Visual material connected to an Iran-related crisis claim that appears to be fully or partly generated by AI, or is credibly suspected of being synthetic. The key feature is that the image/video is presented as crisis evidence while its visual origin is uncertain or artificial. |
| Authentic or likely authentic images challenged as fake/manufactured | Visual material that appears to have a real-world source or verification trail, but is publicly challenged as fake, staged, AI-generated, or manipulated. The key feature is not fakery itself, but the attempt to discredit potentially authentic evidence. |
| Miscontextualized or recycled crisis images | Real or previously circulating visual material reused with a false or misleading claim about time, location, event, actor, or context. The image may be authentic, but the attached claim is wrong or misleading. |
| Images with attached fake, weak, or questionable forensic analysis | Visual material circulated together with technical-looking claims such as AI-detection scores, heatmaps, metadata screenshots, chatbot outputs, comparison panels, or “expert” annotations that are unreliable, opaque, non-reproducible, or disproportionate to the claim. |
| Other (i.e., memes) | Humorous, satirical, symbolic, or remix-based visual material related to Iran-related crisis claims that may not function as direct evidence, but still shapes interpretation, doubt, ridicule, or narrative framing around the event. |
Table 1. Content typology categories and definitions
The next step was to further deconstruct the content in each post in the form of a visual inventory (table 2 in Appendix), breaking down each identifiable element from the content item, from the immediately visible scene, to clues on crisis, location, time, human subjects, infrastructure and architecture, natural environment, detectable text / symbols, audio. Additionally, we developed categories to capture how posts appear technically mediated and evidentiary: platform traces such as screenshots, watermarks, repost markers, compression, and embedded captions; forensic-looking elements such as heatmaps, boxes, scores, metadata, and AI-detection labels; and uncertainties created by blur, cropping, ambiguity, or visual details that invite unsupported or competing interpretations claims. Based on the outcome of the deconstruction, we determined viable verification leads, meaning the pointers that emerged from the close analysis of each content item. We also noted what elements remain unclear, purposefully or not, to account for ambiguity and to infer of overinterpretations.
While these first steps aimed to deconstruct the visual package claims, the following ones reconstruct the meaning by piecing together the resulting insight. Thus, step 3 — the claim verification pipeline, which is a widespread open-source verification practice — aimed to analyze all claims made in each post (table 3 in Appendix). This process was meant to clarify and test the claims attached to the visual material. It combines claim clarification with technical or forensic-claim checking, as well as geolocation, chronolocation, metadata checks, tracing provenance, authenticity verification through fact-checking and verifying for contextual markers that suggest authenticity. Thus, this step brings together the preserved post, the visual inventory, and the source analysis.
With all the information accumulated, the last step of the preservation endavour was to assign a resulting strategy of verifiable reality collapse (table 4). The categories developed are representative for the dataset of the study, and have emerged from inductive engagement with the analysis conducted in previous steps.
| Strategy | Description |
| Synthetic substitution | AI-generated or suspected synthetic images/videos are used to stand in for real crisis events. |
| Miscontextualized or recycled evidence | Real images are reused with wrong time, place, event, or attribution claims. |
| Authenticity aesthetics | Low-quality, CCTV-style, timestamped, “leaked,” compressed, or platform-native aesthetics make images feel evidentiary. |
| Fake forensic authority / detection theatre | Heatmaps, AI-detection screenshots, model outputs, metadata claims, or forensic-looking overlays are staged as proof despite unclear or weak methods. |
| Evidence questioning | Authentic material becomes harder to trust because it circulates alongside synthetic, manipulated, recycled, or technically disputed material. |
Table 4. Strategies of verifiable reality collapse
In line with the experimental nature of the study, several categories of the visual inventory became central to assessing how the strategies of verifiable reality collapse are reflected in the claim verification. Thus, based on the most recurrent hints of fake forensic authority, inductive categories were developed in order to produce spider charts that correlate the relevant traces of evidentiary slop. They were selected as the core categories for a Slopaganda Index. Each post is scored across a common set of axes; including synthetic suspicion, crisis spectacularity, point-of-view filming signs, device and tool signals, apparent consumption effort, apparent production effort, and political artificiality. These axes are not independent judgements but interlocking dimensions of a single question: what does this post ask its audience to believe, and what is it actually able to demonstrate?
Figure 2. Splat chart categories of the The Slopaganda Index and their definitions (definitions also presented in table 5 of the Appendix)
The Slopaganda Index approaches each post as a multidimensional object. Rather than asking whether a post is true or false, it asks: along which dimensions does this post make claims it cannot support, and how do those dimensions combine to produce a specific epistemic risk profile?
The study employed a structured evaluation framework to compare the performance of six AI models (Gemini 3.1 Pro, Gemini 3.5, ChatGPT 5.5, Claude Sonnet 5, Kimi 2.6 Thinking, and GLM 5.2) in processing a 31.6-second "Slopaganda" video as a visual inventory assistant. A standardized prompt was designed to simulate an Open Source Intelligence (OSINT) workflow, strictly prohibiting authenticity verdicts, blame attribution, or definitive geolocation. The models were assessed across 10 specific criteria graded on a 0–4 scale, yielding a maximum possible score of 40. Criteria included heading compliance, observation/interpretation distinction, confidence labeling, constraint adherence, and the absence of hallucinations. The qualitative analysis involved cross-verifying outputs to identify unique strengths, such as forensic-cues enumeration or transparency in frame-sampling methodologies, with all data meticulously documented.
Figure 3. Criteria descriptions
The construction of semantic frameworks in highly radicalized and-or political crises contexts results in the production of systematic biases against certain groups or states. A corpus linguistics analysis of social media posts in these contexts may show what Lohghi calls syntactic "templates" that "should be a way to observe ideological structures" in public speech. Powered up by AI generated content, these templates perform as part of rhetorical devices that use technical language, present false proof attribution, calls to fake authority, and synthetic substitutions, in order to create narratives, not to describe situations.
In this case, responses to one publication by “The Iran Watcher” on X show templates around a synthetic infographic of supposedly hidden weapon infrastructure in Iran. These responses contain well-established combinations of nouns and verbs that work as “a way of presenting reality, which immediately influences interpretation and forces listeners/readers to adopt a certain view of the world” (Longhi).
This case study applied SLURRY, an open-source multi-axis physical signal analysis protocol, to a video circulating on X during the Iran-Israel conflict purporting to show a shoulder-mounted missile strike on a helicopter from a naval vessel. Rather than assessing visual plausibility, SLURRY measures physical properties of the video signal itself; specifically sensor noise variance, spectral artifact frequency, and noise floor temporal stability, computed frame by frame across the full clip duration. These signals were then mapped against the video's visual timeline to identify convergent discontinuities: moments where multiple independent physical measurements shift simultaneously in ways inconsistent with continuous footage from a single camera source. The analysis was conducted using a Python implementation running on extracted video frames, producing normalized time-series measurements and a synchronized visual timeline for interpretation alongside conventional OSI verification methods.
This case study combined reverse-image searching with qualitative content analysis to trace how slopographics evolve and acquire authority through digital circulation. Rather than assessing visual authenticity directly, or attempting to reconstruct a single “original” version, we treated each slopographic as a visual claim package: image composition, text, platform context, attribution, and circulation across accounts. To make this traceable, the graphics featured in the viral X post by Iran Watcher were first broken down into their constituent elements, including primary visual motifs, textual annotations, watermarks, supporting graphics, and secondary visual details. Reverse-image searches were then conducted with the InVID -WeVerify VeraAI tool across Google, Bing and Yandex, alongside caption matching and side-by-side comparison of translated or visually similar versions. This made it possible to identify continuities and discontinuities across iterations, such as recurring mountain structures, shifted flag attributions, swapped place names, layout tweaks, altered annotations, and changes in language or source framing. The aim was to follow how these graphics moved between accounts, across platforms and over time, and to observe how motifs were reassembled with each circulation. This approach allowed us to analyse the morphology of slopographics and to show how their evidentiary authority is produced through repetition, recombination and platformed circulation.
The visual inventory allows for a detailed analytical breakdown of the elements presented in Table 2, and by placing them onto a composite visualisation (figure 4), connections can be established. We note the present, as well as the missing – as indicated in the cutouts from the composite, we notice a systematic absence of mentions to people affected by several war devices is part of a political frame that normalises state violence without problematizing social consequences. The visual inventory shows that the corpus relies heavily on crisis cues such as smoke, flames, rubble, damaged buildings, infrastructure disruption and weapons-like objects. However, these cues rarely allow the specific event, location or timing to be established from the image alone. Location and time cues are often weak or ambiguous: maps, satellite views, distinctive buildings, shadows or timestamps appear in some cases, but many items lack usable geolocation or chronolocation markers. Human subjects are often absent or appear only as anonymous crowds or military figures. Architecture, infrastructure and generic natural environments provide visual backdrops for damage, but seldom enable unique identification. Text, symbols, flags, logos and watermarks mostly signal affiliation or source identity. Very importantly, platform/interface cues and forensic-looking elements, such as CCTV aesthetics, AI-tool screenshots, heatmaps and authenticity scores, help produce an appearance of evidentiary authority. When looking at the deconstructed elements visualised, several critical insight sites emerge: Landscape images and satellite images, People and Infographics (or Slopographics).