7 ms·
Without sold proof this is not possible to circumvent, this maybe more dangerous than not. Here’s an example of AI being able to identify a blurred face: https
by billme 6y ago
Without sold proof this is not possible to circumvent, this maybe more dangerous than not.
Here’s an example of AI being able to identify a blurred face:
https://twitter.com/ak92501/status/1267609424597835777 https://twitter.com/ak92501/status/1267609424597835777
Identifying an individual is not just about a face, but number of factors that are much more complex and very hard to account for in a systematic way.
—-
If Signal is really concerned about allowing individuals to control the information they leak, they need to prioritize releasing the feature that will allow users to use Signal without providing phone numbers; one of their staff recently publicly stated this is finally likely to become a feature. Not to mention stop repeatedly asking for the user to provide their name, access to contacts lists, etc.
- StavrosK 6y agoThat's not removing blur, that's making a face (out of millions) that matches the same pixellization. There's no telling what the original face was, and it's disingenuous that they don't show you the original photo.
- deleted 6y ago[deleted]
- tommyderami 6y agoThey have a sandbox you can run the code yourself--I don't think we're at dystopian surveillance level just yet https://imgur.com/a/IfdLWau https://imgur.com/a/IfdLWau
- felideon 6y agoAt the end of the video they posted[1], they show the original photos of the authors, the downscaled inputs, and the outputs. [1] https://twitter.com/ak92501/status/1267609090689323008 https://twitter.com/ak92501/status/1267609090689323008
- geoelectric 6y agoYou could, however, probably tile the downscale "rainbow table" in a way that would let you predict some degree of novel original from a sufficient number of tile samples. Thing about downscale blur is that it's nearest-neighborish, so can be addressed with divide+conquer as blur effects stay local. You'd end up with a fairly large combination of potential tiles. Some wouldn't be viable faces, but we have classifiers for that already. Entire combination trees can be culled that way to make the problem radically smaller, as long as you know it's supposed to be a face, so I don't know how hard it would really be. It's possibly pretty easy to come up with the N possible original faces with enough certainty to then match with potential targets of interest and make N small enough to use.
- StavrosK 6y agoIsn't that exactly what the paper is doing?
- geoelectric 6y agoI only made it through the abstract but it looks like they’re matching the entire given LR image to a known entire HR image. I’m saying with enough data you could potentially create a more predictive “magic sharpening” algorithm that didn’t strive to match a known original picture, but instead used that matching on divide & conquer subtiles of the original LR image against of a rainbow table of reduced HR tiles to predict a set of plausible HR images. Basically if you can figure out with whatever context you have that the 4x4 brown smudge is very likely a brown cat, you can replace it with a brown cat. And if you know that, the orange/white/black smudge next to it is probably a calico, so stitch it in. Of course the source image would have to be bigger than this, so it couldn’t be CSI-enhance icon to landscape, really more like a really good AI upscaler. You’d need a strong way to identify plausible scenes too. We can generate novel faces now, think this fuses the two concepts.
- brnt 6y agoWhat is left to prove about (Gaussian) blurring?
- billme 6y agoThe intent of the blur is to hide the identity of the individual face that has been blurred. Average human sees a blurry face and assumes the person’s identity is safe. Research has repeatedly should this is false, especially when combined with other data. Here’s another example of such research: https://www.wired.co.uk/article/facial-recognition-systems-can-identify-you-even-if-your-face-is-blurred https://www.wired.co.uk/article/facial-recognition-systems-c... >> “researchers said only 10 fully-visible examples of a person's face were needed to identify a blurred image with 91.5 per cent accuracy.“
- brnt 6y agoA Guassian blur is not reversable, information is lost. No research shows otherwise, because it's a mathematical property of the Gaussian transform. Some methods can be used to find one of many solutions to the blur, where certain high frequency information is preferred over others because we know the end results looks like a human face, and not just any solution. But that only means you can get out many possible faces; if your reconstruction tool only gives you want it was simply over-trained. [edit] You just updated your post. If you have tagged, unblurred photos of the face in your blurred photo, you can (as expected) constrain the end solutions further. WHat's not clear to me from the paper is whether or not the blurred face was tagged as well. Scenario S3 seems most likely the type of scenario encountered in surveillance programs, where the results are nowhere near 91% accurate.
- pfortuny 6y agoWait: informations is lost if the blur is truly a gaussian process. The simulation of blur by means of a convolution can perfectly well be reversible. Image blur is not a gaussian process.
- 6y ago
- Krasnol 6y agoBesides the fact that Signals "blur" doesn't even look remotely close to your example, they're working on the phone number issue: > PINs will also help facilitate new features like addressing that isn’t based exclusively on phone numbers, since the system address book will no longer be a viable way to maintain your network of contacts. https://signal.org/blog/signal-pins/ https://signal.org/blog/signal-pins/
- TJSomething 6y agoThe resolutions on those are way higher than what Signal is doing. It's not surprising that a neural network can give a decent guess at what a face can look like. Faces don't have that much entropy. But you can blur them out if you get it down to like 4x4 pixels. Anyway, if you want scarier panopticon stuff, you should look into gait recognition, which is way harder to censor.
- lelandbatey 6y agoI think this feature may not do as good a job of blurring faces as people expect in some cases, especially if the faces is large in the frame. I tested it and got results that were noticeably less obfuscated than the image advertised on the announcement page by Signal: http://lelandbatey.com/projects/signal_blur_comparison/ http://lelandbatey.com/projects/signal_blur_comparison/
- move-on-by 6y agoI too tested this out immediately and noticed the surprisingly minimal blur. However, I’ve gotten another update since then and it appears to be extremely blurry now. Actually, when I first did it after the update, I thought it was just a solid color. After blurring the majority of the photo I could tell it wasn’t a solid, just extremely blurry.
- stabbles 6y agoInverse problems are ill-posed, you cannot just invert the kernel, information is lost.