Fawkes, a tool developed by researchers at the University of Chicago, disguises photos with pixel-level changes that confuse facial recognition systems
Researchers at the University of Chicago want you to be able to post selfies without worrying that the next Clearview AI will use them to identify you.
Context & Ripple Effects
Fawkes is the University of Chicago's answer to the scraping economy that produced Clearview AI: instead of waiting for courts or regulators to constrain face databases, it gives individuals pixel-level camouflage they can apply before uploading. The move lands mid-arc in facial recognition coverage — after Facebook research showed recognition working even on hidden faces and after [[a:948800|researchers demonstrated 3D masks and photos deceiving systems at Alipay, WeChat Pay and Schiphol]] — establishing that both attack and defense now run through adversarial image manipulation.
First-order effects
- Anyone who applies Fawkes before posting changes what a future scrape yields: their face enters databases like Clearview's as noise, degrading matches for them specifically rather than requiring platform-wide takedowns.
- Clearview AI, already fighting litigation and struggling to land major federal contracts while pivoting toward border and Pentagon buyers, now faces a supply-side threat — its core asset is scraped photos, and a free tool lets subjects poison that asset voluntarily.
Second-order effects
- Recognition vendors must respond by training on cloaked imagery or building robustness to perturbations, an arms race mirrored on the defense side by Facebook AI Research's system modifying faces in live video — pushing costs up for every player scraping or matching.
- If cloaking spreads among privacy-conscious posters, scrapers' effective yield drops unevenly, biasing face databases toward the least-protected populations and complicating accuracy claims sold to police and border customers.
Third-order effects
- The pattern points toward identity protection becoming a personal technical practice rather than a legal guarantee: as the class-action route shows limits — Clearview's proposed settlement offers only a 23% equity stake to the people in its database — tools like Fawkes fill the enforcement gap with self-help cloaking.
- Platforms and photo-sharing services eventually inherit the question of whether to host, strip, or flag adversarially modified images, since widespread cloaking degrades not just surveillance but any downstream service built on face matching.
The trend: Facial recognition is settling into an adversarial arms race where individuals wield free cloaking tools against scrapers, and each side's countermeasures set the terms for the next.