Sick of AI engines scraping your pics for facial recognition? Here's a way to Fawkes them right up
- Reference: 1595448757
- News link: https://www.theregister.co.uk/2020/07/22/defeat_facial_recognition/
- Source link:
The project, named Fawkes in reference to the mask in the V for Vendetta graphic novel and film depicting 16th century failed assassin Guy Fawkes, is described in a paper scheduled for presentation in August at the USENIX Security Symposium 2020.
Fawkes consists of software that runs an algorithm designed to "cloak" photos so they mistrain facial recognition systems, rendering them ineffective at identifying the depicted person. These "cloaks," which AI researchers refer to as perturbations, are claimed to be robust enough to survive subsequent blurring and image compression.
The paper
[1]PDF
, titled, "Fawkes: Protecting Privacy against Unauthorized Deep Learning Models," is co-authored by Shawn Shan, Emily Wenger, Jiayun Zhang, Huiying Li, Haitao Zheng, and Ben Zhao, all with the University of Chicago."Our distortion or 'cloaking' algorithm takes the user’s photos and computes minimal perturbations that shift them significantly in the feature space of a facial recognition model (using real or synthetic images of a third party as a landmark)," the researchers explain in their paper. "Any facial recognition model trained using these images of the user learns an altered set of 'features' of what makes them look like them."
The boffins claim their pixel scrambling scheme provides greater than 95 per cent protection, regardless of whether facial recognition systems get trained via transfer learning or from scratch. They also say it provides about 80 per cent protection when clean, "uncloaked" images leak and get added to the training mix alongside altered snapshots.
Don't want AWS training its AI systems from your pics, text, audio, code? It's now easier to opt out of the slurp [2]READ MORE
They claim 100 per cent success at avoiding facial recognition matches using Microsoft's Azure Face API, Amazon Rekognition, and Face++. Their tests involve cloaking a set of face photos and providing them as training data, then running uncloaked test images of the same person against the mistrained model.
Fawkes differs from adversarial image attacks in that it tries to poison the AI model itself, so it can't match people or their images to their cloaked depictions. Adversarial image attacks try to confuse a properly trained model with specific visual patterns.
The researchers have posted [3]their Python code on GitHub, with instructions for users of Linux, macOS, and Windows. Interested individuals may wish to try cloaking publicly posted pictures of themselves so that if the snaps get scraped and used to train to a facial recognition system – as [4]Clearview AI is said to have done – the pictures won't be useful for identifying the people they depict.
Fawkes is similar in some respects to the recent [5]Camera Adversaria project by Kieran Browne, Ben Swift, and Terhi Nurmikko-Fuller at Australian National University in Canberra.
Camera Adversia adds a pattern known as Perlin Noise to images that disrupts the ability of deep learning systems to classify images. Available as an [6]Android app , a user could take a picture of, say, a pipe and it would not be a pipe to the classifier.
The researchers behind Fawkes say they're working on macOS and Windows tools that make their system easier to use. ®
Get our [7]Tech Resources
[1] http://people.cs.uchicago.edu/~ravenben/publications/pdf/fawkes-usenix20.pdf
[2] https://www.theregister.com/2020/07/15/aws_ai_data/
[3] https://github.com/Shawn-Shan/fawkes/tree/master/fawkes
[4] https://www.theregister.com/2020/03/09/ai_roundup_march6/
[5] https://benswift.me/assets/documents/preprints/browne_et_al_2020_camera_adversaria.pdf
[6] https://play.google.com/store/apps/details?id=com.kieranbrowne.cameraadversaria
[7] https://whitepapers.theregister.com/
"16th century failed assassin Guy Fawkes"
For those who need to be told who Guy Fawkes was, this is an odd way to describe him. He was indeed born in the 16th century but the plot without which he would have remained in obscurity was a 17th century event. And assassination usually means the targeted killing of an individual, while the Gunpower Plot was more like what we would now call terrorism. Although I don't think there's an English word that does justice to the murder of the head of state and the entire legislature in one go.
Re: "16th century failed assassin Guy Fawkes"
A stroke of good luck?
A busy day in Hell's reception?
Herbicide?
Silver cloud with a diamond encrusted lining?
Yeah! Just what is the term for temporarily freeing the masses from their incompetent masters?
Re: "16th century failed assassin Guy Fawkes"
"Does justice" is one way to describe what happened to Fawkes and Co. It got pretty medieval in their last few hours breathing. Who can forget the old rhyme:
Remember, remember the fifth of November, gunpowder treason and plot.
Rip, rend, tear, crush and burn the fuckers ... lol
Penny for the Guy mister?
That's already been done by Magritte
Available as an Android app, a user could take a picture of, say, a pipe and it would not be a pipe to the classifier.
Ceci n'est pas une pipe.
So, now they have to retrain the set again to account for this "pseudo-gan"... Ah well, just another dataset augmentation, nothing new...
I would like to run this on the photos I submit for my passport and driving license.