Threat Image Projection (TIP)

How projected threat images keep X-ray screeners alert — and what TIP can and cannot measure

TIP stands for Threat Image Projection. It is software built into airport security X-ray machines that occasionally inserts a stored X-ray image of a threat item — a gun, knife or bomb component — into the image of a real passenger bag as it passes through the scanner. The screener does not know which threats are real and which are projected. TIP keeps screeners alert, gives them feedback and lets managers measure detection performance on the live checkpoint.

How TIP works

  1. A library of threat images. The system stores X-ray images of threat items scanned on the same type of machine — firearms, knives, improvised explosive devices and their components, and other prohibited items, in many orientations.
  2. Projection into real bags. At irregular intervals the software selects a threat image and merges it into the X-ray image of a real bag, adjusting for the bag's contents so the threat appears to be inside it.
  3. Screener response. The screener inspects the image as usual. If they flag the area containing the projected threat, the system shows a message confirming it was a TIP test, and the bag continues normally.
  4. Missed TIPs. If the screener clears the bag, the system shows a message that a projected threat was missed, displays where it was, and records the miss.
  5. Real alarms are still real. If the screener flags a bag where no TIP was projected, the bag is handled as a genuine alarm.

FTI and CTI: two kinds of TIP image

  • Fictional Threat Image (FTI): an image of a threat item on its own, projected into the image of a real bag. This is the common form of TIP on cabin-baggage X-ray machines.
  • Combined Threat Image (CTI): an image of a complete bag that already contains a threat item, shown instead of a real bag. CTIs are used where FTI projection is not practical, for example with some hold-baggage screening workflows.

The EU aviation security rules (Implementing Regulation (EU) 2015/1998, section 12.5) use these terms and set requirements for TIP systems; the detailed technical specifications sit in a non-public implementing decision. Among the published requirements is that the TIP library should be large enough that a screener is not shown the same image again within twelve months.

Why TIP exists: the low-prevalence effect

Real threats are extraordinarily rare at a checkpoint. Laboratory research on visual search has shown that when targets are rare, people miss them far more often than when targets are common — the low-prevalence effect. In a widely cited 2005 study in Nature, Wolfe, Horowitz and Kenner found that miss rates for targets in a baggage-like search task rose sharply when targets appeared in only 1% of trials compared with 50%.

TIP counters this in three ways: it raises the effective prevalence of threats seen by the screener, it provides immediate feedback on hits and misses, and it exposes screeners to a wider variety of threat appearances than they would ever see in real bags. Research by Schwaninger, Hofer and colleagues at the University of Applied Sciences and Arts Northwestern Switzerland has examined how TIP data can be used to measure and improve screener performance.

What TIP data is used for

  • Performance monitoring: hit rates and false alarm rates per screener, per team and per checkpoint.
  • Targeted training: identifying categories of threat a screener tends to miss and assigning focused practice.
  • Quality control: spotting drops in performance linked to fatigue, shift patterns or new equipment.
  • Recurrent training credit: under EU rules, on-the-job TIP training can be used as part of screeners' recurrent image-recognition training under specified conditions.

TSA uses TIP at U.S. checkpoints as part of its screener performance programme. Specific projection rates, library sizes and pass marks are security-sensitive and are not published; figures quoted on some websites are not from official sources.

Limits of TIP

  • Realism. Projected threats can look slightly different from real ones — for example lacking the clutter around a genuinely packed item — and experienced screeners may learn to spot projections. Research has examined how realistic TIP images are and how to improve them.
  • Library coverage. Performance on TIP only measures detection of the items in the library.
  • CT systems. Projecting threats convincingly into 3-D CT volumes is harder than in 2-D images. 3-D TIP is an active area of development.
  • Not a substitute for testing. Regulators also use covert tests with real test items carried by testers.

For the broader skill of reading X-ray images, see X-ray image interpretation; for how screeners are certified, see screener training and certification; and for the colours you see on screen, see X-ray image colours. You can also try our screening practice quiz.

Frequently asked questions

What does TIP stand for in TSA X-ray screening?

TIP stands for Threat Image Projection: software that projects stored images of threat items into X-ray images of real bags to keep screeners alert and measure their performance.

What happens when a screener detects a TIP image?

The system displays a message confirming that the threat was a projected test image, and the bag continues through screening normally.

What is the difference between FTI and CTI?

A Fictional Threat Image (FTI) is a single threat item projected into a real bag image. A Combined Threat Image (CTI) is a complete stored image of a bag that contains a threat, shown in place of a real bag.

Why is TIP needed?

Because real threats are very rare, and people miss rare targets more often (the low-prevalence effect). TIP increases exposure to threats, provides feedback and gives an objective performance measure.

Sources and further reading

Last reviewed on 2026-10-04.