
We covered a wholly invented document in an earlier post - a mark sheet with no real student behind it at all. This one is the opposite kind of fake: a document that's genuinely real in every respect except one field, changed after the fact.
Here's a degree certificate we built for the same test library. The institution, the student, the enrolment number, the programme - all invented, same as before. But this time only one value on the page was edited after the document was finished: the CGPA.

Read it top to bottom and nothing jumps out. The layout is consistent. The serial number looks plausible. The dates line up - admitted 2021, completed 2026, issued a couple of months after. A CGPA of 9.81 for a "First Class with Distinction" is exactly the kind of number you'd expect. This is what a tampered document is supposed to look like: unremarkable.
The tell is right there, once you know where to look
Zoom into the row with the grade, though, and compare it to the rows around it.

Every other data value on this certificate that should be emphasised is bold - the years, the date of issue. The CGPA isn't. It's not just a shade lighter; it's a visibly different typeface, dropped into the one field that happens to carry the number a forger most wants to change. That mismatch is the entire story: someone took a real, finished document and edited a single value, and the edit didn't quite match the original render.
This is the classic shape of document tampering: the document is real, the edit is small, and it's confined to exactly the field that matters most to whoever made it. Grades, totals, dates, and amounts are edited far more often than logos or letterheads, because they're the fields a forger actually needs to change.
Why this is a different problem to a wholly fake document
An invented document - the kind we covered previously - has no genuine original anywhere. There's nothing to compare it against; it's consistent because a model or a script produced every field at once.
A tampered document is the opposite case: a real original exists, and one region of it was changed later, by a different process than whatever produced the rest of the page. That's exactly what shows up here - a font that doesn't match, rendered at a different point in time than everything around it. Document tampering detection has to look for that kind of localised inconsistency: one region of an image that was produced differently from the rest of it, even when the difference is a few pixels of font weight.
This is also why "fake certificate detection" and "AI-generated document detection" aren't the same problem wearing two names. One asks whether a document was ever a real, physical original. The other asks whether a specific part of a real original was changed after the fact. A tool built only for one will miss the other.
What shows up when it's flagged
In practice, this is what a finding like this looks like once it reaches a reviewer: the document lands in a queue alongside everything else submitted that day, gets marked with a verdict, and the specific field is called out rather than left for someone to find by eye.

That's the point of putting AI document processing in front of a review queue at all: not to replace the reviewer's judgement, but to point it at the one field out of dozens that's actually worth their time, with the reason spelled out rather than a bare pass/fail.
See what gets flagged on your own documents
Upload a certificate, ID, or statement and get back a verdict with the specific field called out - not just a score. $5 in free credits, no contract.
Test a fake document →FAQ
- How does document tampering detection actually work?
It looks for a region of a document that was produced differently from the rest of it - a different compression history, a font that doesn't quite match, edges that don't blend the way the rest of the page does, or a value that's inconsistent with the fields around it. A tampered document is real everywhere except the edited region, so detection is largely about finding where the page stops being internally consistent.
- What's the difference between fake certificate detection and AI-generated document detection?
Fake certificate detection, in the sense of tamper detection, looks for edits made to a real, previously-issued document - a changed grade, a swapped date, a pasted signature. AI-generated document detection asks whether the document was ever a real original at all. Both produce a "not genuine" verdict, but they're different failure modes and need different checks - a tool built only to catch splices will miss a document that was fabricated wholesale, and vice versa.
- Can a font or formatting mismatch really give away a tampered document?
Yes, and it's one of the more common tells. Most tampering happens with different tools or at a different time than the original document was produced - a value pasted in from an image editor, or a field retyped in a PDF editor that defaults to a slightly different font. Even a careful edit rarely matches the original render's font, anti-aliasing, and compression exactly, which is why a close comparison between a suspect field and the rest of the page is one of the most reliable manual checks available.
- What does a flagged document look like in an AI document management dashboard?
A useful one shows more than a pass/fail score: the document in a review queue, a verdict, and the specific region or field responsible for the verdict, called out directly rather than left for a reviewer to find. That turns a review from "study the whole document for anything unusual" into "check this one flagged field" - which is the difference between a dashboard that speeds up review and one that just adds another number to distrust.
- Is a single suspicious field enough to reject a document outright?
Not on its own, which is why a good verdict comes with the evidence attached rather than just a label. A font mismatch on one field is strong enough to route a document to human review; whether it's enough to reject outright depends on the field, the stakes, and whether other checks on the same document agree. That's a judgement call worth leaving to a reviewer with the finding in front of them, not automating away entirely.
Add fake certificate and document tampering detection to your pipeline
TamperCheck.ai flags exactly the kind of localised, field-level tampering shown here - alongside AI-generation detection - on every certificate, ID, or statement you send it, with the specific region called out.
- AI KYC - deepfake & forgery detection - the forensic layer for KYC stacks
- KYC & identity verification use case - how teams deploy it
- Run a tamper check on a document - add $5, start with $10 in credits
- We Invented a Student, a School, and a Report Card. Here's Why It's Fake. - the wholly-fabricated version of this problem
- Credential Fraud: Detecting Fake Degrees and Certificates - the fraud pattern this fixture is modelled on