That rant aside I am curious if this technique will lead to more resilent facial recognition and image parsing techniques to find the shape. Obviously the fact humans can still recognize it is a hint there is some other algorithim possible.
Fawkes: Image “Cloaking” for Personal Privacy
11–20 of 122 posts
Re: Fawkes: Image “Cloaking” for Personal Privacy
#12I believe, Model trained on cloaked images would defeat its purpose and make this technique useless.
[0] Su, Jiawei, Danilo Vasconcellos Vargas, and Kouichi Sakurai. "One pixel attack for fooling deep neural networks." IEEE Transactions on Evolutionary Computation 23.5 (2019): 828-841.
[1] Guo, Chuan, et al. "Countering adversarial images using input transformations." arXiv preprint arXiv:1711.00117 (2017).
[2] Liu, Yanpei, et al. "Delving into transferable adversarial examples and black-box attacks." arXiv preprint arXiv:1611.02770 (2016).
Re: Fawkes: Image “Cloaking” for Personal Privacy
#13I wonder how this holds up when someone takes a photo of that 'protected image'. I can imagine that if these miniscule pixel-scaled changes aren't visible to the naked eye, my crappy 6 megapixel camera will overlook it as well. If I then proceed to feed that image into my image recognition algorithm, is it still protected?
Re: Fawkes: Image “Cloaking” for Personal Privacy
#14Also 7 days ago[1][2][3] but no upvote love so far. Which is curious given the (possibly short term, until these images join training corpus?) privacy benefits [1]: https://news.ycombinator.com/item?id=23845760 [2]: https://news.ycombinator.com/item?id=23842016 [3]: https://news.ycombinator.com/item?id=23837565
I personally would like to see tests done on facebook by uploading these images and checking if it can recognize it.
Re: Fawkes: Image “Cloaking” for Personal Privacy
#15Re: Fawkes: Image “Cloaking” for Personal Privacy
#16It'd be great to have an app on Android that applies this to every photo I take with my camera.
Agreed. I would use it, unless it was made by Facebook, Amazon, Google or Apple.
Re: Fawkes: Image “Cloaking” for Personal Privacy
#17Re: Fawkes: Image “Cloaking” for Personal Privacy
#18Re: Fawkes: Image “Cloaking” for Personal Privacy
#19Re: Fawkes: Image “Cloaking” for Personal Privacy
#20I was immediately was curious how it would protect against image compression and/or otherwise de-noising these protection pixel changes. Their paper does address this question, and for those that are interested: Even image compression cannot defeat our cloak. We use progressive JPEG [57], reportedly used by Facebook and Twitter, to compress the images in our dataset. The image quality, as standard by Independent JPEG…