The pipeline separates collection, inspection, and scoring so each provider can change without turning the result into a black box.
The submitted image is decoded into a safe working copy. SourceTrace computes a SHA-256 hash, perceptual hash, dimensions, MIME type, and file size, then searches the normalized working image. When app chrome obscures a screenshot, it can generate temporary recovery crops in memory without adding extra stored files. Dimensions and crop geometry are calculated after applying image orientation.
Reverse-image-search APIs return public candidate URLs. In live mode, one request combines visual web lookup and visible-text extraction to reduce cost. SourceTrace first performs its local relevance checks; if no locally verified lead survives, it makes only the remaining budget on screenshot-aware regions or a fuller locally verified media match. This bounded fallback is useful for edited composites and is labeled in the report. Mock mode returns a realistic set of Pixiv, Bluesky, Reddit, Pinterest, X, and aggregation-page fixtures.
When configured, a second replaceable visual-search API can run once when the primary search has weak source coverage. Its automatic region focus helps with cropped artwork and screenshots. Cached provider results are allowed to reduce repeated cost, and every returned page still has to pass the same local image comparison and source inspection rules.
Live candidates must include a full or partial matching-image URL. SourceTrace safely downloads that public candidate image and independently compares aspect-preserving luminance, edge structure, and perceptual hashes against the upload and any temporary recovery crop. Transparent images are compared on light and dark backgrounds, and featureless images are not accepted as meaningful verification merely for sharing a flat color. Major regions of larger candidate images are also compared, so a submitted crop can be verified against the complete work it came from. SourceTrace checks every result in the configured bounded provider set: finding one exact repost no longer stops later artist pages or credited sources from being verified. Visually unrelated pages are rejected before attribution scoring. Results clearly say when this local verification could not be performed.
Weak partial matches, low-context social listings, and ordinary video-thumbnail associations face stricter thresholds. Before a provider request, SourceTrace can also reuse a completed local report for an exact file or a same-dimension image with the same perceptual fingerprint. Cache reuse is disclosed as neutral evidence and never raises the score.
Candidate pages are inspected for public metadata and sanitized textual context: author identifiers, public profile images, dates, image dimensions, outbound source links, authorship language, credits, and process material. Recognized creator profile links can be inspected one public hop further to find clearly associated social profiles.
Direct media hosts such as X, Pinterest, Reddit, or social CDN image URLs are treated as pixel evidence, not source posts. If the provider returns only a media file, SourceTrace can use its exact filename, visible handles, and verified pixels to look for a canonical parent post. The report links to the recovered public post when one can be verified and never promotes the CDN file itself as the artist.
When accessible metadata omits an author, supported public post URLs can still expose a posting identity on Threads, Bluesky, TikTok, X, or Reddit. This is labeled as URL-derived evidence. Same-looking handles on different platforms remain separate unless a public profile link connects them. Reddit crossposts and explicit earlier-source links are treated as repost context. When ordinary public Reddit JSON exposes an attribution in a comment, SourceTrace can follow that credited source as a new bounded candidate and independently verify its image. It does not bypass Reddit access controls when that public data is unavailable.
A public artwork-index adapter can also recognize a trusted Danbooru CDN file hash found in a provider result, resolve its public metadata, and follow the indexed source post. This can recover artist tags and source handles that a generic page omits. Danbooru is a third-party index, so these credits are presented as corroborating leads rather than proof of authorship.
Explicit phrases such as “art by,” “illustrated by,” and “credited to” are extracted separately from ordinary mentions. OCR words near image edges are considered possible signature fragments, but they affect attribution only when they align with a discovered creator identity.
OCR text and visible account handles remain available as manual search clues even when no candidate page is found. A translator or reposter watermark identifies redistribution context, not necessarily the original artist, so it is shown as neutral or cautionary evidence rather than creator attribution.
The inspector does not execute page scripts or bypass access controls. For Reddit, it first tries the ordinary public JSON representation. When a page is blocked, SourceTrace may still recover a posting handle or timestamp that is explicitly encoded in the public post URL or search-index title. That identifies the posting account, not necessarily the artist, and is labeled as limited evidence.
A deterministic score from 0 to 100 weighs earliest discovered upload, independently verified visual similarity, direct post permalinks, highest resolution, authorship claims, signature matches, independent credits, linked profiles, artwork history, and process evidence. Aggregation behavior, earlier-source links, and cropping can reduce the score. A strong source lead does not automatically identify its creator.
Source-match strength and creator-attribution strength are calculated separately. An excellent pixel match can therefore coexist with an inconclusive creator identity. A verified match on a public artist account can support a likely-artist result, while high confidence requires creator-specific convergence such as a signature, process material, multiple verified credits, or strongly cross-linked public identities.
Posting accounts are ranked separately from credited creators. A repost account receives little identity weight merely for hosting a match, while repeated independent credits, signature alignment, authorship language, and process material carry more creator-specific weight.
Previously supported public artist identities can be reused only when the current evidence exposes the exact normalized handle. This strengthens profile linking and artwork-history context without allowing a merely similar username to inherit another artist's attribution.
The number is a ranking aid, not a probability or measure of scientific certainty. The full contribution trail is retained for operator review and correction analysis.
“Earliest discovered post” means exactly that: earliest among pages the current providers could access. An older post may have been deleted, made private, de-indexed, or posted on an unsupported platform.
A completed report can accept a direct public post URL as new evidence. SourceTrace inspects the page and independently compares its exposed image with the retained working image before adding the source or recalculating attribution.
When Reddit exposes the posting account but blocks its post image, a user may also provide an i.redd.it or preview.redd.it image address. The pixels are still verified, while the post-to-image relationship is explicitly labeled as community-supplied. Similar handles that differ only by trailing platform punctuation remain alias leads and do not automatically establish authorship.
Every report accepts corrections for the artist, original source, inaccessible pages, or other evidence. Corrections are stored for review and do not silently override the original analysis.