Research & Papers

Blurring Faces for Privacy Isn't Enough — Researchers Found a Fix

That blurred face in street maps and videos may still be identifiable. Here's why it matters.

Deep Dive

Companies and governments blur or scramble faces before publishing photos and video — think Google Street View, medical records, dashcams, and public CCTV footage. This process, called de-identification, is the main thing standing between you and being recognized in footage you never agreed to appear in. A team of researchers decided to test how well it actually holds up, and the answer is: not as well as we'd hope.

The attack works a bit like a counterfeit key. An attacker builds a fake AI face-recognition system of their own — a stand-in for whatever the target is really using — and crafts tiny, invisible pixel changes designed to fool it. Because these tricks often transfer between systems, the attacker's fake key can unlock the real one. The result: the privacy filter runs, the image looks properly scrambled, but the identity inside it can still be pulled out by a sensitive face-matching system. In plain terms, a blurred face is not automatically an anonymous face.

So what actually helps? The researchers tested two remedies. First, training the privacy system on attack-style examples, which worked well against weather-like distortions such as simulated snow or fog. Second, and more elegantly, running a low-pass filter — essentially smoothing out the finest pixel noise — which blunted the attack without harming the quality of the protected image. Neither fix requires rebuilding the system from scratch.

For everyday life, this cuts two ways. On one hand, it's a warning: don't assume a blurred face means you're invisible, whether it's your kid in a school video or your car on a street-mapping service. On the other, it's a sign that privacy tools are being stress-tested and improved before, not after, something goes wrong. If you work somewhere that publishes footage — schools, hospitals, local government, media — this is the kind of finding worth passing along to whoever handles it.

Key Points
  • Blurring or scrambling faces is the standard way to protect privacy in published photos and video — and this study shows it can be defeated.
  • Attackers can build their own AI system to craft invisible pixel changes that trick the real privacy filter into leaking identities, using well-known face tools like CosFace and ArcFace.
  • Two simple defenses work: training on attack-style examples (helps with weather-like distortions) and a basic smoothing filter that removes the harmful pixel noise.

Why It Matters

Blurred faces could still identify you in maps, medical records and public footage — until these fixes reach real products.

📬 Get the top 10 AI stories daily