In plain words: Neural networks were trained to recognize faces, objects, and handwritten digits from images that were pixelated, blurred, or scrambled by encrypting key parts of the file. They still identified the subjects correctly, showing these privacy tricks do not hide images from AI.
Abstract
We demonstrate that modern image recognition methods based on artificial neural networks can recover hidden information from images protected by various forms of obfuscation. The obfuscation techniques considered in this paper are mosaicing (also known as pixelation), blurring (as used by YouTube), and P3, a recently proposed system for privacy-preserving photo sharing that encrypts the significant JPEG coefficients to make images unrecognizable by humans. We empirically show how to train artificial neural networks to successfully identify faces and recognize objects and handwritten digits even if the images are protected using any of the above obfuscation techniques.
Richard McPherson, Reza Shokri, Vitaly Shmatikov
arXiv:1609.00408 · cs.CR, cs.CV · submitted Sep 1, 2016 · updated Sep 6, 2016
abstract · pdf · html