What Transmission Channels Secretly Do to Your Documents
Ruslan Mishyn · Plica — Independent Forensic Boutique · May 2026

What Transmission Channels Secretly Do to Your Documents
Ruslan Mishyn · Plica — Independent Forensic Boutique · May 2026
You photograph your passport on an iPhone and send it to a bank for verification. You believe the bank received exactly what you submitted.
What the AI detector actually receives is a different object.
A transmission channel is not a passive wire. It is a mutation pipeline that can destroy the original physical properties of a file before any verification system sees it. This is Pipeline-Induced Provenance Loss, or PIPL. It begins the moment you press send.
Messengers: a pixel grinder
WhatsApp and similar messengers often rebuild the image through the system JPEG encoder of the OS, causing the file to lose part of its original structure.
In the process, the following may disappear:
- Apple MakerNotes
- GPS tags
- Original quantisation tables
- Correct resolution metadata
- The signals that underpin forensic provenance
PRNU — the unique sensor noise pattern that forensic analysis uses to identify a specific camera — frequently drops below the detection threshold after aggressive re-encoding. DCT statistics, which record the compression history of the file, are also rewritten.
For a KYC detector, the result looks like stripped provenance: no camera model, no GPS, no reliable origin history. Forensically, this can appear sterile — almost like a synthetic object. The detector raises a flag — not because the document is fake, but because the channel erased the signals of authenticity.
Telegram adds another choice that most users don’t realise they’re making: send as photo or send as file.
- Send as photo: the image is recompressed, and the physical signals of origin degrade.
- Send as file: the original is preserved, and the forensic record survives.
One passport. One iPhone. Two transmission paths. Two different objects at the other end.
Email: hidden byte surgery
Corporate email infrastructure does not simply forward attachments. Depending on policy, file size, and type, gateways may perform CDR, antivirus scanning, and re-saving of attachments.
What this means in practice:
- The file is opened on the server
- It is scanned
- It is re-saved
- Its SHA-256 hash changes
- Its original JPEG history may be lost
The file that arrives at the verification system is no longer the file that was sent. The chain between submission and analysis breaks silently — no error, no notification, no trace for the user.
If the bank stores the hash of the received file and a regulator later requests the original submission, the hashes may not match. The audit trail will be intact. The evidence chain will not.
Cloud and CDN: mutation in transit
Object storage does not necessarily mutate files by itself. Mutation typically happens in the surrounding stack: through CDN, edge image optimisation, upload pipelines, preview generation, Lambda@Edge, imgproxy, and similar mechanisms.
This is where the following occur:
- Conversion to WebP or AVIF
- Automatic compression for screen size
- Device-based resizing
- Thumbnail generation
Thumbnails are particularly destructive. They smooth textures, normalise noise, and create derivative copies that bear little forensic resemblance to the original. Each thumbnail is a new file with a new hash and no full provenance link to the original upload.
The compounding effect
The problem is not one channel. The problem is the chain.
A file that has passed through a messenger, then email, then a corporate portal has gone through several independent mutation cycles. Each step may look reasonable in isolation. Together, they produce an artifact that no longer carries reliable forensic signals.
The KYC detector at the end of this chain is not evaluating the customer’s document. It is evaluating a derivative of a derivative. And the signals that would distinguish a genuine document from a synthetic one have already been erased by the transmission infrastructure.
This is not a detection problem. It is an infrastructure problem.
What this means for AI verification
The standard response to document fraud is to improve the detector: add training data, tune the model, increase sensitivity.
But this does not solve the problem.
If the physical signals that distinguish genuine documents from AI-generated ones have already been destroyed before the detector runs, sensitivity adjustments are irrelevant. The model is working with a forensically blank object. It cannot distinguish a degraded genuine document from a well-crafted synthetic one, because after reprocessing both look identical at the pixel level.
Two symmetrical failures emerge:
- False rejections of real customers
- Fraud passing through on the same degraded signal
A false rejection is not fraud detection. It is an infrastructure failure billed to the customer.
The only way out
Trying to catch AI fakes after they have passed through this pipeline is like testing water quality downstream of a factory that has already discharged upstream.
The intervention point must be upstream — at intake, before any channel operation.
What is needed:
- Hash at first byte
- EXIF snapshot before the pipeline touches the file
- Transform event log for every subsequent operation
- Witness check at the point of inference, confirming that the artifact is explained by the intake record plus documented transforms
This is what the VEBA specification addresses: sealing the original physics of the document at intake, so that everything the transmission channel does afterward is documented — not lost.
The question for any verification stack is not how good our detector is.
The question is which object our detector is actually evaluating.
If you don’t know the answer — Phase 0 is a free 48-hour intake audit: send a labelled sample and receive a signal-level breakdown of what your stack catches, misses, and loses at the provenance layer.
Truth lives in the layers.
Ruslan Mishyn is the founder of Plica, an independent forensic boutique for evidence integrity in regulated file workflows, and the author of SDB-26 — an open benchmark framework for measuring synthetic document bypass rate in identity verification systems.
ruslanm@plicaforensic.com · plicaforensic.com · sdb26.com
메타데이터
- post_id
- 4af8f23acd84
- slug
- what-transmission-channels-secretly-do-to-your-documents-4af8f23acd84
- url
- https://medium.com/@sevrusik/what-transmission-channels-secretly-do-to-your-documents-4af8f23acd84
- canonical_url
- https://medium.com/@sevrusik/what-transmission-channels-secretly-do-to-your-documents-4af8f23acd84
- author_url
- https://medium.com/@sevrusik
- status
- ok
- fetched_at
- 2026-06-09 15:37:30