VOOZH about

URL: https://thenewstack.io/deepprivacy-ai-uses-deepfake-tech-to-anonymize-faces-and-protect-privacy/

⇱ DeepPrivacy AI Uses Deepfake Tech to Anonymize Faces and Protect Privacy - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2019-10-11 11:05:47
DeepPrivacy AI Uses Deepfake Tech to Anonymize Faces and Protect Privacy
news,
Operations

DeepPrivacy AI Uses Deepfake Tech to Anonymize Faces and Protect Privacy

Researchers at the Norwegian University of Science and Technology have developed such a technology, which uses machine learning algorithms to seamlessly and automatically replace one's face in real-time with a variety of anonymous faces, sourced from a database of 1.47 million images.
Oct 11th, 2019 11:05am by Kimberley Mok
👁 Featued image for: DeepPrivacy AI Uses Deepfake Tech to Anonymize Faces and Protect Privacy

Recent advances in artificial intelligence are helping us to accelerate new discoveries in medicine and science, in addition to expanding the range creative possibilities in art, music and literature. But like any other tool, AI can be used for more nefarious ends — such as generating faked images or videos (known as “deepfakes”), as well as facilitating mass surveillance — a practice that is on the rise in authoritarian countries like China, and even in liberal democracies. In the case of deepfakes, AI algorithms can be used to produce eerily convincing videos of politicians, while AI-assisted facial recognition systems can be used to identify people who might dare to speak out against repressive regimes.

But it may be possible to fight fire with fire, so to speak, by using the same technology to thwart facial recognition algorithms and generating a deepfaked appearance in order to protect one’s privacy. Researchers at the Norwegian University of Science and Technology have developed such a technology, which uses machine learning algorithms to seamlessly and automatically replace one’s face in real-time with a variety of anonymous faces, sourced from a database of 1.47 million images. Recently presented at the International Symposium on Visual Computing, the team’s paper suggests that such “de-identification” technology could help safeguard the identities of people who want to remain anonymous in photographs or in livestreamed online videos.

Dubbed DeepPrivacy, the system utilizes what is known as a generative adversarial network (GAN) to swap out the original face in a photo or video with a different one that is synthesized from a database of over a million Creative Commons-licensed facial images taken from Flickr. While the concept is nothing new, what’s intriguing in this work is that the facial substitution happens almost seamlessly, with the GAN dynamically retaining original “conditions” such as the subject’s facial expressions, the existing background, and the initial pose of the subject’s body. In addition, as an extra layer of added protection, the DeepPrivacy system is designed to not use any privacy-sensitive information in the original face; instead, it uses “keypoints” indicating the positioning of the nose, mouth, eyes and so on in order to simulate a new face.

👁 Image

First column: original photo. Second column: bounding box showing the model where anonymization is needed. Third column: final result.

As we’ve seen previously in experiments that attempt to fool both humans and machines, generative adversarial networks function by pitting two neural networks against each other: a “generative” network that pumps out faked images, and a “discriminator” network that evaluates the simulated images as either real or counterfeit. The goal is for the generative network to increase the error rate of the discriminator network by “fooling” it over and over again, so that the system can gradually train itself to generate more and more persuasive — but ultimately bogus — images.

To achieve this, the DeepPrivacy system works by first superimposing a bounding box over the original face. Relevant facial “keypoints” like the location of the eyes, nose and shoulders are noted. The DeepPrivacy model then draws upon Flickr Diverse Faces (FDF), an open source dataset of over one million faces that was culled from an existing database of over 100 million Creative Commons images from Flickr, which were selected for their diversity of appearance, facial expressions, unconventional poses and backgrounds. Each of these faces in the FDF dataset are preloaded with an anonymizing bounding box and annotated “keypoints”— allowing the system to quickly generate a new, unique face that effectively conceals the subject’s actual identity.

👁 Image

More examples of photos where the DeepPrivacy algorithm has been used.

As we can see, the method works quite well for swapping faces in static images, while in videos where the facial information is constantly changing from frame-to-frame (such as this one uploaded by the team), the faces are still a bit blurry and contain some residual visual artifacts. While there remains some room for improvement, the system nevertheless offers up some useful advantages over other similar techniques: its design permits full anonymization of a person’s face, and still performs relatively well even when confronted with a variety of challenges like odd poses, partially covered faces and varying backgrounds. Of course, such “de-identification” tools will someday have to expand to cover other possible biometric identifiers like items of clothing, hair or cranial shape in order to keep up with ever-evolving technology.

Check out the DeepPrivacy code on Github.

TRENDING STORIES
Kimberley Mok is a tech and design reporter who covers artificial intelligence, robotics, quantum computing, tech culture and science stories for The New Stack. Trained as an architect, she is also an illustrator and multidisciplinary designer who has been passionate...
Read more from Kimberley Mok
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.