A technology ``Fawkes'' that prevents AI from confusing AI by subtle processing that humans do not understand and facial images are used arbitrarily


by SAND Lab, University of Chicago

' Fawkes ', a technology that prevents profile pictures posted on SNS and blogs from being collected by a third party and profiled with personal information, was announced. Named after

Guy Fawkes , a symbol of anonymous protesters, this technology allows facial portraits to be subtlely processed by humans, confusing the AI of face recognition systems. It can be made unrecognizable.

Fawkes
http://sandlab.cs.uchicago.edu/fawkes/

This Tool Could Protect Your Photos From Facial Recognition-The New York Times
https://www.nytimes.com/2020/08/03/technology/fawkes-tool-protects-photos-from-facial-recognition.html

If you post an image on the Internet, anyone in the world can access the photo, so you need to keep that in mind when uploading your face photo to SNS. However, in recent years, it has been reported that a new AI company has collected more than 3 billion face pictures from the Internet and handed them over to the police along with personal information, so due to the development of AI face It is expected that the number of cases where photographs will be used will increase.

Google, YouTube, Venmo, LinkedIn, etc. demand that data usage be stopped by ``Clearview AI'' which develops a face recognition application from more than 3 billion face pictures on the net-GIGAZINE


by Steven Lilley

An example of ``face pictures uploaded on the net are arbitrarily collected with personal information'' is reported-GIGAZINE



Therefore, SAND Lab , which is researching security at the University of Chicago, has developed software 'Fawkes' for PC and Mac that can prevent AI from collecting face pictures even by individuals.

The following is an actual photo of Fawkes using actress Jessica Simpson (left), Gwyneth Paltrow (center), and actor Patrick Dempsey (right), each processed into three pieces. Of the two pictures, the left is the original picture and the right is the one using Fawkes, but I do not understand how it differs even if I take a closer look.


by SAND Lab, University of Chicago

Even if people do not understand the difference, AI will not know who is reflected in the picture at all. SAND Lab actually verified the effect of Fawkes with the latest face recognition technology such as Microsoft's

Azure Face API , Amazon's Rekognition , Face++ also used by Chinese public security authorities, and there is a 100% probability of accurate recognition. It was confirmed that it was no longer possible.

SAND Lab said about the mechanism of Fawkes, ' Deep learning has a phenomenon of adversarial sample in which the process of classifying data changes greatly even if there is a small change in the input data. The basic mechanism of Fawkes is Draw with the same mechanism that causes the adversarial sample to occur.'

As mentioned above, Fawkes is a feature that even individuals can use PCs. SAND Lab publishes the source code for engineers on GitHub and also publishes executable files for Windows and macOS on the Fawkes official site .



However, at the time of writing the article, it freezes even when using the executable file version for Windows, so I could not process the image properly. The version of the executable file is still '0.3', and it is said that it is updated frequently, so I would like to expect future updates. SAND Lab is also currently preparing a program to verify that the protection features at Fawkes are actually working.

in Software, Posted by log1l_ks