/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Fawkes, a tool developed by researchers at the University of Chicago, disguises photos with pixel-level changes that confuse facial recognition systems

Researchers at the University of Chicago want you to be able to post selfies without worrying that the next Clearview AI will use them to identify you.

New York Times Kashmir Hill

Context & Ripple Effects

Fawkes is the University of Chicago's answer to the scraping economy that produced Clearview AI: instead of waiting for courts or regulators to constrain face databases, it gives individuals pixel-level camouflage they can apply before uploading. The move lands mid-arc in facial recognition coverage — after Facebook research showed recognition working even on hidden faces and after [[a:948800|researchers demonstrated 3D masks and photos deceiving systems at Alipay, WeChat Pay and Schiphol]] — establishing that both attack and defense now run through adversarial image manipulation.

First-order effects

  • Anyone who applies Fawkes before posting changes what a future scrape yields: their face enters databases like Clearview's as noise, degrading matches for them specifically rather than requiring platform-wide takedowns.
  • Clearview AI, already fighting litigation and struggling to land major federal contracts while pivoting toward border and Pentagon buyers, now faces a supply-side threat — its core asset is scraped photos, and a free tool lets subjects poison that asset voluntarily.

Second-order effects

  • Recognition vendors must respond by training on cloaked imagery or building robustness to perturbations, an arms race mirrored on the defense side by Facebook AI Research's system modifying faces in live video — pushing costs up for every player scraping or matching.
  • If cloaking spreads among privacy-conscious posters, scrapers' effective yield drops unevenly, biasing face databases toward the least-protected populations and complicating accuracy claims sold to police and border customers.

Third-order effects

  • The pattern points toward identity protection becoming a personal technical practice rather than a legal guarantee: as the class-action route shows limits — Clearview's proposed settlement offers only a 23% equity stake to the people in its database — tools like Fawkes fill the enforcement gap with self-help cloaking.
  • Platforms and photo-sharing services eventually inherit the question of whether to host, strip, or flag adversarially modified images, since widespread cloaking degrades not just surveillance but any downstream service built on face matching.

The trend: Facial recognition is settling into an adversarial arms race where individuals wield free cloaking tools against scrapers, and each side's countermeasures set the terms for the next.

Discussion

  • @katecrawford Kate Crawford on x
    Here's the latest on the efforts to cloak images from being used to train facial recognition software. But is it too late? Clearview says it only makes their system stronger. Great reporting from @kashhill and also @davegershgorn https://www.nytimes.com/...
  • @krusynth Bill Hunt on x
    Friends, there's no magic solution here. This is an arms race, if you create tools to circumvent recognition, they just end up making better algorithms. The only way to win is not to play. https://twitter.com/...
  • @normative Julian Sanchez on x
    Without having dived into the specs, this seems unwise. If they're still recognizable to humans, I'd assume eventually they'll be recognizable to a tweaked facial recognition algorithm. At which point everyone who uploaded “cloaked” images goes “whoops.” https://twitter.com/...
  • @ncweaver Nicholas Weaver on x
    There tools only work because the current ML-based face recognition is ML-crap. When face recognition systems are built around actual features rather than “features” these sorts of transformations won't work anymore. https://twitter.com/...
  • @alenasatoshi @alenasatoshi on x
    This “cloaking” technique managed to fool the facial recognition systems peddled by Microsoft, Amazon, and Google 100% of the time. #antisurveillance https://gizmodo.com/...
  • @hypervisible Doomscrolling Eternal on x
    The tool “converts an image — or ‘cloaks’ it, in the researchers' parlance — by subtly altering some of the features that facial recognition systems depend on when they construct a person's face print.” https://twitter.com/...
  • @kashhill Kashmir Hill on x
    Researchers have a tool to help you post photos of your loved ones online without feeling guilty about making them identifiable to face recognition systems: https://www.nytimes.com/...