Suggestion for an algorithm:
* start with the blur
* sample the four colors at the four corners of the blurred region
* quantize them
* fill in the region with bilinear interpolation.
Then your whole region can only reveal these four quantized color values. If you only blur then you will have a harder time proving the leaked information content. * detect (or get the user to select) faces
* replace the pixels in the face bounding box with a generic face
* blur the bounding box edges
* do whatever blur you think ends up "looking nice"(From the examples in the Signal blog post, I don't think that grey gradient box is gonna be able to specifically imply white or POC faces...)
A side comment: AFAICT what the Signal developers have done is take code that was developed so that the phone camera could autofocus on faces, and and used that code to defocus faces. What a sweet hack.
Blurring is better than nothing but the best picture when it comes to avoid being traced is the picture that was never taken.
I'm not sure whether the large number of photos nowadays is a net negative, though. That's also what finally stopped Derek Chauvin.
And even then law enforcement are already filming them (cctv + from the air) and tracking their phones, the last thing you have to worry about is a 100% blurred face that no amount of technical power would be able to process or match back to you.
picture B of a blurred individual from later on in the same protest, wearing the exact same clothes, commiting questionable acts, is circumstantially incriminating.
You could definitely take signals code, and run it over the set of test images and find which output matches closest to the target image.
https://www.androidpolice.com/wp-content/uploads/2020/06/04/... is blurred by Signal. Suppose that you have all the photos that have been posted to Facebook, and that both of those women are on Facebook, and lastly that you have resources enough to run all of those through the Signal code. How would you match those other photos to the blurred part of this one?
To your eyes, maybe. To a machine, you have an array of pixels, each with different values which, using an algorithm, could be adjusted into something your eyes can resolve into a unique face.
That said, the whole point of my post was that humans are really bad at judging this. Many blur algorithms can be reversed because they just modify the color values of the pixels in a reversible way. You can't always tell by looking at a picture what data is still there, in much the same way you can't see the stars in an ISO 200 picture of the night sky. It's not until you open it in GIMP and crank the exposure up to max that you see just how much data is there that your eyes couldn't perceive.
But like others have pointed out, you can achieve (allmost) the same effect, if you remove enough information before blurring, or just drawing a smooth gradient, but this alone is harder to make it look as nice, as blurring the actual image.