Live data from Hacker News

Fawkes: Image “Cloaking” for Personal Privacy

sandlab.cs.uchicago.edu

51–60 of 122 posts

Re: Fawkes: Image “Cloaking” for Personal Privacy

#51

I wonder what consequences it would have if I would use a cloaked photo for my passport...

You would likely get flagged at most international terminals when returning to the US. This would mean that you will be pulled out of line, and have your documents manually checked by customs. That image would be then added to the database as an image match for you, and the cloaking would be pretty useless until you replaced the passport. (10 years give or take)

Re: Fawkes: Image “Cloaking” for Personal Privacy

#52
post #35

As an ML outsider, I'm surprised classifiers are so hyper-sensitive to pixel level inputs that this would work.

Some are some aren't, there is a vast vast array of different methods, many are not publicly disclosed so I highly doubt the effectiveness of most of these studies.

This may stop some internet marketers, but don't expect it to be effective against large corps and governments.

Re: Fawkes: Image “Cloaking” for Personal Privacy

#53
post #36

An easier option: don't post photos on Facebook and Twitter. And discourage your friends and family from doing so.

That's like saying to prevent STDs or pregnancy, don't have sex.

I'd agree if the phrase you used was "don't have sex in an exploitative relationship".

Re: Fawkes: Image “Cloaking” for Personal Privacy

#54
post #30

Once this technique gets enough attention, a detector for it will be built. Even if the face cannot be recognized, a profile with such picture may be flagged for more scrutiny. This reminds me of using TOR that hides what you visit, and yet likely puts you into a watchlist for surveillance. I think that a simpler and more robust strategy to achieve good privacy is avoid posting personal information online and social…

"Not standing out" isn't very scalable.

Re: Fawkes: Image “Cloaking” for Personal Privacy

#55
> The difference, however, is that if and when someone tries to use these photos to build a facial recognition model, "cloaked" images will teach the model an highly distorted version of what makes you look like you. The cloak effect is not easily detectable, and will not cause errors in model training. However, when someone tries to identify you using an unaltered image of you (e.g. a photo taken in public), and tries to identify you, they will fail.

Do different photos of the same person produce unique results where even a comparison between two cloaked will result in a mismatch? The article mentions that only the comparison between unaltered and cloaked images will result in a mismatch. If that is the case, what's stopping someone from using this algorithm to generate a cloaked image from the unaltered one and then using both in order to identify you?

Re: Fawkes: Image “Cloaking” for Personal Privacy

#56
post #8

Color me extremely skeptical. A low-pass filter will make short work of any "tiny, pixel-level" changes designed to thwart ML. After all, one of the most tell-tale identifiers (space between eyes/nose/mouth) is still plainly observable and unaltered in the "cloaked" image. If a human's neural network can correctly correlate the before/after examples, so can a computer's. They might have found an issue with some moder…

> If a human's neural network can correctly correlate the before/after examples, so can a computer's. color _me_ skeptical, but this is like saying we have functioning AGI; that artificial NNs are the same as the ones we have in our skulls. This to me, is an effect of the over-anthropomorphization of machine learning. It's a bad intuition to have. However, I do agree. This is just one step in an arms race, and one it…

That bit was more of a forward-looking statement about the future capabilities of image recognition, but yes it is somewhat hyperbolic in the general case. I don't believe we'll ever achieve AGI, but I do believe we'll have super reliable application-specific classifiers that vastly outperform humans and won't be fooled by tricks like this.

Re: Fawkes: Image “Cloaking” for Personal Privacy

#57
post #8

Color me extremely skeptical. A low-pass filter will make short work of any "tiny, pixel-level" changes designed to thwart ML. After all, one of the most tell-tale identifiers (space between eyes/nose/mouth) is still plainly observable and unaltered in the "cloaked" image. If a human's neural network can correctly correlate the before/after examples, so can a computer's. They might have found an issue with some moder…

Or more simply, what if you just take a real life photo of the image and scan it back in and use the same classification techniques?

Reproducing the image in this way is essentially a manual low-pass filter (although with little control over the parameters), so it's certainly one valid data point with which to test the hypothesis.

Re: Fawkes: Image “Cloaking” for Personal Privacy

#58
What we really need is Fawkes face paint. A little makeup/lotion that you apply to the face. It would apply random cloaking directly to your skin. This way the cloaking is automatic and applies to images that are not under your control.

I can be as careful as I want to be with my own media. That doesn't stop my wife from uploading the family photo to Facebook or a public camera capturing my image.

Re: Fawkes: Image “Cloaking” for Personal Privacy

#59
post #10

Smart but not wise. Certainly another tool in the privacy toolkit if you absolutely must surrender your likeness to someone else’s computer, but worth bearing in mind that this does not provide (and doesn’t purport to provide) the kind of privacy that strong encryption (or better yet, absent data) can provide. Edited to add: it’s still damn cool.

Or better yet, burning Google and Facebook to the ground.

Technical solutions have never solved this sort of societal problem. Expecting a few individuals to fight against massive institutions with a little clever math is not going to work.

Re: Fawkes: Image “Cloaking” for Personal Privacy

#60
I wonder if it works against clearview.ai

https://www.youtube.com/watch?v=q-1bR3P9RAw

It's very important that it works 'cos clearview is so creepy. It's not creepy because of its technology, it's creepy because the justifications of its existence that are given by its CEO are sooo weak. "we can do it because it's not worse than google" (ie. we entirely skip the moral argument), "we can do it because it's for law enforcement" (let's frame our stuff in a way that it's only positive) , "we can do it because we ensure that those who use our tool are strictly controlled" (yeah, we're above the states), "all images are public therefore I can do whatever I want", etc.

Post reply on HN