{"id":19504,"date":"2022-01-03T12:00:00","date_gmt":"2022-01-03T20:00:00","guid":{"rendered":"https:\/\/www.privateinternetaccess.com\/blog\/?p=19504"},"modified":"2024-01-25T01:34:51","modified_gmt":"2024-01-25T09:34:51","slug":"hide-from-facial-recognition-software-with-fawkes","status":"publish","type":"post","link":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/","title":{"rendered":"How to Hide from Facial Recognition Software with Fawkes"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I recently wrote about <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/how-to-create-a-convincing-persona-to-hide-your-identity-online\/\">constructing a fake persona<\/a> to hide your identity online. I\u2019ll admit that for most people, it\u2019s a lot of trouble to go through. In most cases, it\u2019s completely over the top. Creating a fake person from scratch in order to preserve your privacy is the domain of the paranoid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You want to be able to live a normal life \u2014\u00a0to hang out on social media with your friends and family and occasionally post photos of trips to the beach, social gatherings (when they resume), and other life events \u2014\u00a0without the images being scraped and added to a facial recognition database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s a real problem, and since social media came into existence, service providers and other shady third parties have been using your data any way they please.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That said, because facial recognition features are so\u00a0<a href=\"https:\/\/www.theverge.com\/2019\/11\/27\/20985721\/google-photos-tagging-manual-people-face-pictures\" target=\"_blank\" rel=\"noopener\">easy to use<\/a>, many people <em>want<\/em> to use them. Being able to easily find photos of specific individuals from your tens of thousands of snaps is kind of useful \u2014 although you should probably consider how often you actually use this feature.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Facial Recognition Is a Risk to You<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The potential benefits of automatic recognition from a snapshot or video feed are limited: You can <a title=\"https:\/\/brinkshome.com\/smartcenter\/smart-door-locks-with-facial-recognition\" href=\"https:\/\/brinkshome.com\/smartcenter\/smart-door-locks-with-facial-recognition\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">unlock the front door<\/a> to your house, use your face to <a href=\"https:\/\/www.theguardian.com\/world\/2021\/oct\/15\/privacy-fears-moscow-metro-rolls-out-facial-recognition-pay-system\" target=\"_blank\" rel=\"noopener\">pay for your subway ride<\/a> in a number of cities, and easily find images of yourself in galleries and albums.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And that\u2019s basically it. Facial recognition technologies don\u2019t treat you as the user \u2014 you are just a data subject, and the real advantages are for organizations that sell access to services that can pinpoint a person from an image snatched on CCTV.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And while facial recognition may not allow you to purchase goods in stores, that doesn\u2019t mean that the stores aren\u2019t using it for their own ends.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Loyalty programs, personalized marketing, and in-store security all use facial recognition in order to get you to spend more, and ensure that you aren\u2019t stealing the stock.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From the point of view of a retailer, it\u2019s highly desirable to <a title=\"https:\/\/www.facewatch.co.uk\/\" href=\"https:\/\/www.facewatch.co.uk\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">recognize known or suspected shoplifters<\/a> as soon as they sidle through the sliding doors, but for everyone else, it\u2019s intrusive and an invasion of privacy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And if you think masks will work as a way of keeping your mugshot off the database, you can think again. As early as May 2020, retail oriented security-as-a-service providers, such as Facewatch, had updated their algorithms to <a title=\"https:\/\/www.facewatch.co.uk\/2020\/05\/11\/facewatch-launches-facemask-recognition-upgrade\/\" href=\"https:\/\/www.facewatch.co.uk\/2020\/05\/11\/facewatch-launches-facemask-recognition-upgrade\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">recognize individuals wearing Covid face coverings<\/a>, and they are currently working to \u201csupport persons adhering to religious customs such as niqabs to be provided an equal user experience when engaging with identification technology.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even if you don\u2019t mind personalized advertising, and would never dream of lifting a can of baked beans without paying the cashier, that doesn\u2019t mean that facial recognition technology is in any way ethical, or that the organizations that use it are acting in your best interests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The United States has a history of protests, demonstrations, and on-the-ground political action. It\u2019s a proud tradition that people will <a href=\"https:\/\/en.wikipedia.org\/wiki\/Boston_Tea_Party\" target=\"_blank\" rel=\"noopener\">revolt against injustice<\/a>, <a href=\"https:\/\/www.aarp.org\/politics-society\/history\/info-2018\/civil-rights-events-fd.html\" target=\"_blank\" rel=\"noopener\">demonstrate for their democratic rights<\/a>, and organize to <a href=\"https:\/\/www.nps.gov\/goga\/learn\/historyculture\/alcatraz-occupation.htm\" target=\"_blank\" rel=\"noopener\">fight the power<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Such demonstrations are pitted against some aspects of the establishment and the status quo. Naturally, the establishment pushes back with a mind-boggling array of technological toys such as <a href=\"https:\/\/www.forbes.com\/sites\/stephenrice1\/2019\/10\/07\/10-ways-that-police-use-drones-to-protect-and-serve\/\" target=\"_blank\" rel=\"noopener\">drones<\/a>, <a href=\"https:\/\/www.nbcnews.com\/id\/wbna41912754\" target=\"_blank\" rel=\"noopener\">tanks<\/a>, <a href=\"https:\/\/www.thesun.co.uk\/news\/12244081\/portland-arizona-texas-blm-protesters-garrett-foster\/\" target=\"_blank\" rel=\"noopener\">tear gas<\/a>, and of course, facial recognition.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"681\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/police-1024x681.jpeg\" alt=\"\" class=\"wp-image-19639\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/police-1024x681.jpeg 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/police-300x199.jpeg 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/police-768x511.jpeg 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/police-1200x798.jpeg 1200w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/police.jpeg 1280w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">On June 14th 2020, Derrick Ingram, co-founder of the non-violent activist group Warriors In The Garden, was involved in an incident with an officer of the NYPD, during which Ingram was alleged to have used a megaphone to shout into the ear of the officer. Flash forward two months, and <a title=\"https:\/\/www.nytimes.com\/2020\/08\/07\/nyregion\/nypd-derrick-ingram-protester.html\" href=\"https:\/\/www.nytimes.com\/2020\/08\/07\/nyregion\/nypd-derrick-ingram-protester.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">officers in riot gear, supported by police helicopters<\/a>, turned up at Ingram\u2019s apartment to arrest him.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ingram had been identified using facial recognition of an image captured at the protest that matched with one on his personal Instagram account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ingram\u2019s story is far from unique. <a href=\"https:\/\/www.clearview.ai\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Clearview AI<\/a> \u2014 a private company that provides facial recognition services to both private and public organizations \u2014 lists among its customers: ICE, the Department of Justice, FBI, Customs and Border Protection (CBP), Interpol, and more than 600 law enforcement agencies. As of February 2020, NYPD officers had run more than 11,000 facial recognition searches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s an argument that Derek Ingram shouting into an officer\u2019s ear-hole <em>is<\/em> technically assault, and the <a title=\"https:\/\/www.dailymail.co.uk\/news\/article-9864089\/FBI-use-phone-tracking-facial-recognition-arrest-man-dressed-George-Washington-Jan-6.html\" href=\"https:\/\/www.dailymail.co.uk\/news\/article-9864089\/FBI-use-phone-tracking-facial-recognition-arrest-man-dressed-George-Washington-Jan-6.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">individuals who were identified by facial recognition<\/a> after the January 6th 2021 Congress incident, were at least trespassing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But as an exceptionally law abiding citizen, you have nothing to worry about. Right?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Laws change almost every day. And what is permitted one day may be outlawed the next. A perfectly legal activity can be criminalized by federal and state lawmakers with the stroke of a pen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Texas State Senate Bill 8, which was signed by Texas Governor on 19 May and enacted September 1st 2021, effectively bans abortion as early as six weeks of pregnancy. The bill was condemned by UN human rights experts, who <a href=\"https:\/\/www.ohchr.org\/en\/NewsEvents\/Pages\/DisplayNews.aspx?NewsID=27457&amp;LangID=E\" target=\"_blank\" rel=\"noopener\">said<\/a>, \u201cThis law is alarming. It bans abortion before many women even know they are pregnant.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The bill prevents state officials from enforcing the law, but it authorizes private individuals to sue anyone who performs or assists a post-heartbeat abortion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although I haven\u2019t yet heard of facial recognition tech being used to identify staff at abortion clinics (or the women who use them), it doesn\u2019t seem far-fetched to say that it could be used to enforce gray-area laws.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">You Can\u2019t Keep Your Face Out of Recognition Databases<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/protest-1024x683.jpeg\" alt=\"\" class=\"wp-image-19637\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/protest-1024x683.jpeg 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/protest-300x200.jpeg 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/protest-768x512.jpeg 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/protest-1200x801.jpeg 1200w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/protest.jpeg 1280w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Since the dawn of social media and cloud-photo storage, billions of people have taken advantage of \u2018free\u2019 services that can store, catalogue, and tag their images \u2014 unaware that the services were being used to create the datasets that make facial recognition possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In November 2021, Meta (the company formerly known as Facebook) announced that it would be <a title=\"https:\/\/about.fb.com\/news\/2021\/11\/update-on-use-of-face-recognition\/\" href=\"https:\/\/about.fb.com\/news\/2021\/11\/update-on-use-of-face-recognition\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">shutting down the Face Recognition system on Facebook<\/a>, stating, \u201cThere are many concerns about the place of facial recognition technology in society, and regulators are still in the process of providing a clear set of rules governing its use. Amid this ongoing uncertainty, we believe that limiting the use of facial recognition to a narrow set of use cases is appropriate.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Meta statement does not rule out using facial recognition altogether, and on the surface, it seems to only make the experience more frustrating for end users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But Facebook was only ever a part of the problem. Clearview AI, the company so beloved by law enforcement agencies across the world, has historically scraped social media and other sites for faces and corroborative information rather than collaborating with the companies hosting the pictures. It is estimated that Clearview AI\u00a0<a title=\"https:\/\/www.nytimes.com\/2020\/01\/18\/technology\/clearview-privacy-facial-recognition.html\" href=\"https:\/\/www.nytimes.com\/2020\/01\/18\/technology\/clearview-privacy-facial-recognition.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">downloaded over 3 billion photos<\/a>\u00a0and used them to create facial recognition models of millions of citizens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019re going to have to accept that your pictures are already out there, that they\u2019re tied to your identity, and that there is no way to change that. Sure, you can keep new images of yourself off the web, but that doesn\u2019t change the fact that one or more privately owned machine learning tools can recognize you more accurately than a person can.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Use Fawkes to Fool an AI<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Facial recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features that make up your face. The fewer images available, the worse these tools will perform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another way to fool the systems is to feed them images that\u00a0<em>poison<\/em> the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While you <em>can<\/em> fill your social media feeds with images of people who aren\u2019t you, this rather defeats the object of having social media in the first place. A dozen pictures of Rick Astley in place of your own handsome mug at bachelor parties and beach vacations will just annoy people.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ideally, you want images that can be easily recognized by other people but will fool the machines and throw off their recognition algorithms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I have a profile picture on this site. It\u2019s the same image in the PIA slack channel, and the same one I use elsewhere. I\u2019m quite happy for it to be associated with my name and my identity. People I know can tell that it\u2019s me, but thanks to a process called \u2018cloaking\u2019, which involves making tiny, pixel-level changes that are invisible to the human eye, the models on which facial recognition rely are fed inaccurate information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every new photo of me that appears online goes through the same process \u2014 meaning that as time goes on, the ability of companies and law enforcement to recognize my image diminishes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The software responsible for this trickery is called <a href=\"https:\/\/sandlab.cs.uchicago.edu\/fawkes\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em>Fawkes<\/em><\/a>, and it was developed by the SAND Lab (Security, Algorithms, Networking and Data) at the University of Chicago to combat the ubiquity of facial recognition systems. The name is a deliberate pop culture reference, referring to to the Guy Fawkes mask worn by the protagonist of <em>V for Vendetta, <\/em>and ideally the software should afford users some degree of anonymity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After images have been altered by Fawkes, the inventors say that:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-style-large is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cYou can then use these \u2018cloaked\u2019 photos as you normally would, sharing them on social media, sending them to friends, printing them or displaying them on digital devices, the same way you would any other photo. The difference, however, is that if and when someone tries to use these photos to build a facial recognition model, \u2018cloaked\u2019 images will teach the model an highly distorted version of what makes you look like you. The cloak effect is not easily detectable by humans or machines and will not cause errors in model training. However, when someone tries to identify you by presenting an unaltered, \u201cuncloaked\u201d image of you (e.g. a photo taken in public) to the model, the model will fail to recognize you.\u201d<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s that easy. The only issue is how many cloaked images it will take to thoroughly poison a model.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Run Your Own Fawkes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Fawkes is open-source software, meaning that you can alter, distribute, and run it however you want. And while you <em>can <\/em><a href=\"https:\/\/github.com\/Shawn-Shan\/fawkes\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">build it from source<\/a>, the developers have provided ready-to-run binaries for <a href=\"https:\/\/mirror.cs.uchicago.edu\/fawkes\/files\/1.0\/fawkes_binary_windows-v1.0.exe\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">Windows<\/a>, <a href=\"https:\/\/mirror.cs.uchicago.edu\/fawkes\/files\/1.0\/fawkes_binary_mac-v1.0.zip\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">Mac<\/a>, and <a href=\"https:\/\/mirror.cs.uchicago.edu\/fawkes\/files\/1.0\/fawkes_binary_linux-v1.0.zip\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">Linux<\/a>. In case you\u2019re on a limited bandwidth connection, you should be aware that the download is almost 1 GB.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To give you an idea of the results, I generated a convincing face using <a href=\"http:\/\/thispersondoesnotexist.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">thispersondoesnotexist.com<\/a>, then ran it through Fawkes. After around 30 seconds, the cloaking process was complete. These are the results:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"514\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output-1024x514.jpg\" alt=\"Two visually identical images of a woman\" class=\"wp-image-19597\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output-1024x514.jpg 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output-300x150.jpg 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output-768x385.jpg 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output-1536x770.jpg 1536w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output-1200x602.jpg 1200w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/12\/fawkes_output.jpg 2042w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To me, both images are identical. If this person <em>did<\/em> exist, the people who knew her may be able to pick up some differences; but to most people, these would appear to be identical images.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To a facial recognition engine that already has a model built on thousands of images of this person, it is close enough to add to the model but different enough to fundamentally alter the basis of the model.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few hundred (or thousands) of Fawkes-processed images will see the model thoroughly poisoned.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Limitations of Fawkes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Think of how many pictures of you are already out there on the internet. There are probably more than a few dozen in existence, and they are accessible to Google, Facebook, or other third-party scrapers. This means that it will take a <em>lot<\/em> of Fawkes images to make you invisible to the software models that will be developed in the future. For models that are already in existence and no longer updating, it won\u2019t be effective at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using Fawkes also means that you will need to make changes to the way you upload photos. Many people have their photos set to upload to the cloud as soon as they are taken. If you plan on using Fawkes, you will instead need to upload photos from your phone onto your PC, run Fawkes (at around 30 seconds per photo), and then upload the images to your social media accounts or cloud storage provider of choice to be tagged.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You will also need to persuade your friends, family, or anyone else likely to tag pictures of you to do the same. But this may prove\u2026 more difficult.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also the unfortunate fact that facial recognition platforms evolve. They get better at what they do, and there are suspicions that certain vendors are working against Fawkes to make it less effective as a cloaking tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In January 2021, the University of Chicago revealed that a significant change made to Microsoft Azure tools <a href=\"https:\/\/sandlab.cs.uchicago.edu\/fawkes\/?ref=steemhunt\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">indicated<\/a> that, \u201cAzure has been trained to lower the efficacy of the specific version of Fawkes that has been released in the wild.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The current version of Fawkes (v 1.0) is no longer vulnerable to the Azure update, however there is no guarantee that upgrades on any of the facial recognition platforms could render Fawkes\u2019s protection less effective.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Can You Really Defeat Facial Recognition Software with Fawkes?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The answer is <em>probably. <\/em>Facial recognition makes a lot of money for the companies involved in it \u2014 Clearview AI, for instance, was estimated to be worth $100 million in 2020, and despite recent eight figure <a href=\"https:\/\/www.theguardian.com\/technology\/2021\/nov\/29\/us-facial-recognition-firm-faces-17m-uk-fine-for-serious-breaches-clearview-ai\" target=\"_blank\" rel=\"noreferrer noopener\">fines for data protection violations<\/a>, the company, and others like it, are unlikely to limit their activities so long as governments and police departments keep paying them. Their models will evolve, and Fawkes will evolve to keep ahead.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Currently, Fawkes is reckoned to be \u201c100% effective against state-of-the-art facial recognition models (Microsoft Azure Face API, Amazon Rekognition, and Face++).\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. Using Fawkes to keep an accurate model of your face out of their hands <em>is<\/em> a hassle, and it ultimately comes down to how much you value your privacy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I\u2019ve been using Fawkes for almost a year; every photo taken by anyone in my household is run through it, and I have upgraded with every new release.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For me, the peace of mind is worth the extra trouble. Plus, I\u2019ve automated the process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So take the time and do your own risk evaluation. How much do you value your privacy and anonymity?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform.<\/p>\n<p>Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.<\/p>\n","protected":false},"author":64,"featured_media":19642,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_stopmodifiedupdate":false,"_modified_date":"","footnotes":""},"categories":[12,845,1940,1941],"tags":[],"class_list":["post-19504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-guides","category-social-media","category-surveillance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How to Hide from Facial Recognition Software with Fawkes<\/title>\n<meta name=\"description\" content=\"Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform. Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Hide from Facial Recognition Software with Fawkes\" \/>\n<meta property=\"og:description\" content=\"Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform. Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\" \/>\n<meta property=\"og:site_name\" content=\"PIA\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/privateinternetaccess\/\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-03T20:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-25T09:34:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"David Rutland\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:site\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"David Rutland\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\"},\"author\":{\"name\":\"David Rutland\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/81e858f02c25a06ea360c64afb2cce2c\"},\"headline\":\"How to Hide from Facial Recognition Software with Fawkes\",\"datePublished\":\"2022-01-03T20:00:00+00:00\",\"dateModified\":\"2024-01-25T09:34:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\"},\"wordCount\":2352,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg\",\"articleSection\":[\"Cybersecurity\",\"Guides\",\"Social Media\",\"Surveillance\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\",\"name\":\"How to Hide from Facial Recognition Software with Fawkes\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg\",\"datePublished\":\"2022-01-03T20:00:00+00:00\",\"dateModified\":\"2024-01-25T09:34:51+00:00\",\"description\":\"Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform. Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.privateinternetaccess.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Hide from Facial Recognition Software with Fawkes\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"name\":\"PIA\",\"description\":\"Online privacy news from around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\",\"name\":\"Private Internet Access\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"width\":1200,\"height\":1200,\"caption\":\"Private Internet Access\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/privateinternetaccess\/\",\"https:\/\/x.com\/buyvpnservice\",\"https:\/\/www.instagram.com\/piavpn\/\",\"https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/81e858f02c25a06ea360c64afb2cce2c\",\"name\":\"David Rutland\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/11\/me_headshot_low_cloaked-96x96.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/11\/me_headshot_low_cloaked-96x96.png\",\"caption\":\"David Rutland\"},\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/author\/davidrutland\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How to Hide from Facial Recognition Software with Fawkes","description":"Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform. Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/","og_locale":"en_US","og_type":"article","og_title":"How to Hide from Facial Recognition Software with Fawkes","og_description":"Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform. Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.","og_url":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/","og_site_name":"PIA","article_publisher":"https:\/\/www.facebook.com\/privateinternetaccess\/","article_published_time":"2022-01-03T20:00:00+00:00","article_modified_time":"2024-01-25T09:34:51+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg","type":"image\/jpeg"}],"author":"David Rutland","twitter_card":"summary_large_image","twitter_creator":"@buyvpnservice","twitter_site":"@buyvpnservice","twitter_misc":{"Written by":"David Rutland","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#article","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/"},"author":{"name":"David Rutland","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/81e858f02c25a06ea360c64afb2cce2c"},"headline":"How to Hide from Facial Recognition Software with Fawkes","datePublished":"2022-01-03T20:00:00+00:00","dateModified":"2024-01-25T09:34:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/"},"wordCount":2352,"commentCount":2,"publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg","articleSection":["Cybersecurity","Guides","Social Media","Surveillance"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/","name":"How to Hide from Facial Recognition Software with Fawkes","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg","datePublished":"2022-01-03T20:00:00+00:00","dateModified":"2024-01-25T09:34:51+00:00","description":"Face recognition tools can recognize you because they have a vast trove of data to analyze and discover the unique combination of features which make up your face. The fewer images available, the worse the tools will perform. Another way to fool the systems is to feed them images which poison the model they use, making it less likely that they will be able to recognize you from a fresh snapshot or video feed.","breadcrumb":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#primaryimage","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2022\/01\/monitoring-1305045_1280.jpeg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/www.privateinternetaccess.com\/blog\/hide-from-facial-recognition-software-with-fawkes\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.privateinternetaccess.com\/blog\/"},{"@type":"ListItem","position":2,"name":"How to Hide from Facial Recognition Software with Fawkes"}]},{"@type":"WebSite","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website","url":"https:\/\/www.privateinternetaccess.com\/blog\/","name":"PIA","description":"Online privacy news from around the world.","publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization","name":"Private Internet Access","url":"https:\/\/www.privateinternetaccess.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","width":1200,"height":1200,"caption":"Private Internet Access"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/privateinternetaccess\/","https:\/\/x.com\/buyvpnservice","https:\/\/www.instagram.com\/piavpn\/","https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w"]},{"@type":"Person","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/81e858f02c25a06ea360c64afb2cce2c","name":"David Rutland","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/11\/me_headshot_low_cloaked-96x96.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2021\/11\/me_headshot_low_cloaked-96x96.png","caption":"David Rutland"},"url":"https:\/\/www.privateinternetaccess.com\/blog\/author\/davidrutland\/"}]}},"_links":{"self":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/19504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/users\/64"}],"replies":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/comments?post=19504"}],"version-history":[{"count":30,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/19504\/revisions"}],"predecessor-version":[{"id":19640,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/19504\/revisions\/19640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media\/19642"}],"wp:attachment":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media?parent=19504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/categories?post=19504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/tags?post=19504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}