A side comment: AFAICT what the Signal developers have done is take code that was developed so that the phone camera could autofocus on faces, and and used that code to defocus faces. What a sweet hack.
Blurring is better than nothing but the best picture when it comes to avoid being traced is the picture that was never taken.
I'm not sure whether the large number of photos nowadays is a net negative, though. That's also what finally stopped Derek Chauvin.
And even then law enforcement are already filming them (cctv + from the air) and tracking their phones, the last thing you have to worry about is a 100% blurred face that no amount of technical power would be able to process or match back to you.
picture B of a blurred individual from later on in the same protest, wearing the exact same clothes, commiting questionable acts, is circumstantially incriminating.
You could definitely take signals code, and run it over the set of test images and find which output matches closest to the target image.
https://www.androidpolice.com/wp-content/uploads/2020/06/04/... is blurred by Signal. Suppose that you have all the photos that have been posted to Facebook, and that both of those women are on Facebook, and lastly that you have resources enough to run all of those through the Signal code. How would you match those other photos to the blurred part of this one?
To your eyes, maybe. To a machine, you have an array of pixels, each with different values which, using an algorithm, could be adjusted into something your eyes can resolve into a unique face.
That said, the whole point of my post was that humans are really bad at judging this. Many blur algorithms can be reversed because they just modify the color values of the pixels in a reversible way. You can't always tell by looking at a picture what data is still there, in much the same way you can't see the stars in an ISO 200 picture of the night sky. It's not until you open it in GIMP and crank the exposure up to max that you see just how much data is there that your eyes couldn't perceive.
Suggestion for an algorithm:
* start with the blur
* sample the four colors at the four corners of the blurred region
* quantize them
* fill in the region with bilinear interpolation.
Then your whole region can only reveal these four quantized color values. If you only blur then you will have a harder time proving the leaked information content. * detect (or get the user to select) faces
* replace the pixels in the face bounding box with a generic face
* blur the bounding box edges
* do whatever blur you think ends up "looking nice"(From the examples in the Signal blog post, I don't think that grey gradient box is gonna be able to specifically imply white or POC faces...)
But like others have pointed out, you can achieve (allmost) the same effect, if you remove enough information before blurring, or just drawing a smooth gradient, but this alone is harder to make it look as nice, as blurring the actual image.
They appear to use "com.google.firebase:firebase-ml-vision-face-model:20.0.1" to detect the faces.
The actual blur appears to be done here: https://github.com/signalapp/Signal-Android/blob/514048171bf...
Not sure what "ScriptIntrinsicBlur" stands for exactly, it appears to come from the android SDK itself: import android.renderscript.RenderScript;
EDIT: https://developer.android.com/reference/kotlin/android/rende...
It's a gaussian blur filter with a radius of 25px if I understand the code correctly.
Thanks for digging.
EDIT: come to think of it, you can generate random noise using a palette from the color in the blur area (say, take four or five colors and mix them).
Applying convolutional blur for anonymizing is very very risky. Because you might end up with something either invertible or nearly so.
https://news.ycombinator.com/item?id=23422993
In fact it almost seems like the actual blur used in the app is different from what they show in the article.
I wonder why Signal didn't do something like that...
It's okay for still images, but videos have a lot of information to leak. Just black everything out.
Note that if you blur the pixelated region, it'll be just as aesthetically pleasing as the reversible Gaussian blur.
Edit: Turns out it's a 25px Gaussian blur. There's some downsampling beforehand, but not much, and no color discretization. In other words, they use a bad blur, but compensate with a large security margin. I wouldn't be surprised if this was vulnerable to "if I have a thousand photos of faces and I think one of them matches the blurred face, I can figure out which one with high confidence", and they can get basically the same aesthetic effect if they heavily pixelate and discretize colors before blurring.
Is that actually a practical attack here? I can see it working if you have 1000 passport photo or mugshot frames photos, and a blurred photo with the same level/front-on framing. But is there a practical attack for non direct-facing-camera blurred pictures? (Assuming the scale of "locals at a local protest" instead of "Find Edward Snowden's blurred face from any BLM protest, no matter what the cost!!!")
But I've been surprised by impressive digital forensics before—what if you can determine lighting and orientation from the rest of the photo, and then simulate them on each passport photo/mugshot? I'd still feel much more comfortable if they pixelized and color-discretized before blurring, and I still think the aesthetic effect would be much the same.
2017: https://arxiv.org/pdf/1702.00783.pdf (Pixel Recursive Super Resolution)
2020: https://venturebeat.com/2020/01/22/researchers-use-ai-to-deb...
Edit: Most face recognition software works by down-sizing and blurring an image to faster detect face features. So in theory it is very easy to detect face features from a blurred image. A deblur tool can then use this information to better deblur a face.
So the ridiculous „Enhance!“ one sees in TV show crime dramas could one day actually become true.
Edit: The images in the Signal article don't look like images of blurred faces. They look like blurry images overlaid onto faces. If you don't blur the face, how can it be unblurred?