Faces, People and Pose

Anonymising faces in a dataset

Blurring and pixelating faces feels like anonymisation and is defeatable by anyone holding a list of candidates, so real de-identification either destroys the region or replaces the face with a different one.

On this page 8
  1. The short answer
  2. Why this matters more than it sounds
  3. How the attack works
  4. What actually works
  5. The awkward truth about the rest of the body
  6. Where you have already seen this
  7. Remember this
  8. What to learn next

One lesson, three depths. Pick the one that fits you today — you can switch any time.

Beginner — No maths. Plain English.

The short answer

Blurring a face hides it from you. It does not always hide it from a computer holding a list of suspects.

Think of a frosted glass door. Standing in the corridor, you see a smudge and cannot say who it is. Now imagine you already know it is one of five colleagues, and you know each of their outlines by heart.

You do not need to see through the glass. You compare the smudge against five remembered shapes and pick the closest. The frosting removed detail; it did not remove the match.

That is how blurring and pixelating fail.

Why this matters more than it sounds

Teams anonymise faces for good reasons. Publishing a street dataset. Sharing CCTV footage with a contractor. Releasing training images. Complying with a data protection rule.

If the redaction is reversible, none of that worked. Under European law, data that can be linked back to a person is still personal data. Every obligation continues to apply. A team that blurred faces and believed itself finished has a compliance problem it does not know about.

How the attack works

The attacker needs one thing: a manageable list of who it might be. Employees of a company. Residents of a building. Students in a year group.

   released image (face blurred)
        │
        ▼
   for every candidate photo the attacker has:
        apply the SAME blur
        │
        ▼
   compare the two blurred versions
        │
        ▼
   the closest match names the person

The trick is applying the identical damage to both sides. The comparison is then between two equally degraded pictures, and enough signal survives to rank the candidates correctly.

This works because blurring is a fixed, repeatable operation. Anyone can apply it. Anyone can undo the effect of it by putting both sides through the same filter.

What actually works

Remove the pixels. Replace the face region with a solid block. Nothing survives because nothing is left. It ruins the picture for most uses, and it is the only method with no clever attack against it.

Replace the face with a different one. Generate a new, synthetic face that never belonged to anybody, and place it where the real one was. The scene stays usable. Head pose, expression and lighting can be preserved. Somebody training a person-detector still gets a working dataset.

Group people together first. Take a group of faces and produce one blended face to stand for all of them. Any single released face now belongs to a group rather than a person. This is a genuine guarantee rather than a hope, and it costs realism.

The awkward truth about the rest of the body

Even with the face perfectly removed, a person can often still be recognised.

Gait — how somebody walks — is distinctive. So is body shape, hairstyle, clothing, a bag, a wheelchair, a tattoo. Add the context: this photo was taken outside a particular building at a particular hour.

Research on person re-identification has repeatedly found that removing the face reduces matching accuracy without eliminating it. Face redaction is one control among several, not a complete answer.

Where you have already seen this

  • Blurred faces and number plates on Google Street View.
  • Pixelated bystanders in a news broadcast.
  • Blurred witnesses in a documentary interview.
  • Synthetic faces in a published driving dataset.

Remember this

  • Blurring and pixelating are reversible when the attacker has a short list of candidates.
  • Removing the pixels works. Replacing the face with a synthetic one works and keeps the image usable.
  • The face is not the only identifier. Body, clothing, gait and context remain.

What to learn next

Developer — Code and libraries.

Setup

bash
pip install numpy opencv-python

Run against numpy 1.26 and opencv-python 4.10. The demonstration below carries out the attack described above, on data small enough to run instantly.

The parrot attack, in thirty lines

Each "face" here is a 32x32 pattern, and identity is the pattern. The matcher is a correlation, which is far weaker than a real face model — and it is still enough.

deid_attack.py
import numpy as np
import cv2
rng = np.random.default_rng(1)

# Twelve people in a tiny dataset. Each "face" is a 32x32 pattern; identity is the pattern.
def make_face(seed):
    r = np.random.default_rng(seed)
    base = r.normal(0.5, 0.18, (8, 8))
    return np.clip(cv2.resize(base, (32, 32), interpolation=cv2.INTER_CUBIC), 0, 1)

faces = np.stack([make_face(100 + i) for i in range(12)])
target = faces[7]                                  # the person we are trying to protect

def pixelate(img, block):
    h, w = img.shape
    small = cv2.resize(img, (w // block, h // block), interpolation=cv2.INTER_AREA)
    return cv2.resize(small, (w, h), interpolation=cv2.INTER_NEAREST)

def blur(img, k):
    return cv2.GaussianBlur(img, (k, k), 0)

def black_box(img):
    return np.zeros_like(img)

def matcher(a, b):                                 # a crude but honest identity score
    if a.std() < 1e-9 or b.std() < 1e-9:
        return 0.0                                 # a blank image carries no identity at all
    return float(np.corrcoef(a.ravel(), b.ravel())[0, 1])

print("attack: apply the SAME redaction to all 12 known candidates, then match.")
print(f"{'redaction':>22} {'rank of true person':>20} {'score margin':>13}")
for name, fn in [("pixelate, 8px blocks", lambda x: pixelate(x, 8)),
                 ("pixelate, 16px blocks", lambda x: pixelate(x, 16)),
                 ("gaussian blur k=15",    lambda x: blur(x, 15)),
                 ("gaussian blur k=31",    lambda x: blur(x, 31)),
                 ("solid black box",       black_box)]:
    released = fn(target)
    sims = np.array([matcher(released, fn(f)) for f in faces])
    if np.allclose(sims, sims[0]):
        print(f"{name:>22} {'all 12 tied':>20} {0.0:>13.4f}")
        continue
    order = np.argsort(-sims)
    rank = int(np.where(order == 7)[0][0]) + 1
    margin = sims[7] - np.max(np.delete(sims, 7))
    print(f"{name:>22} {rank:>20} {margin:>13.4f}")
Output
attack: apply the SAME redaction to all 12 known candidates, then match.
             redaction  rank of true person  score margin
  pixelate, 8px blocks                    1        0.6709
 pixelate, 16px blocks                    1        0.0054
    gaussian blur k=15                    1        0.7448
    gaussian blur k=31                    1        0.4162
       solid black box          all 12 tied        0.0000

Reading it

Every blur and pixelation setting is defeated, at rank 1. Not "sometimes". Every one. The correct person is the top candidate in all four cases, using a correlation matcher a student could write in a minute.

Look at the margins, because they carry the real story. Eight-pixel blocks leave a margin of 0.6709 — the right answer wins by a mile. Sixteen-pixel blocks, which reduce a 32x32 face to a 2x2 grid, leave a margin of 0.0054. Still correct, and barely. That thin margin is what "stronger redaction" actually buys: not safety, a smaller edge, which a better matcher or a longer candidate list can restore or destroy.

The black box is the only clean result. All twelve scores are identical because there is nothing to compare. No margin, no ranking, no attack. It is the only entry in the table with a guarantee behind it.

This attack is called parrot recognition, and the point of it is that the attacker never has to reverse the blur. They apply the same blur to their own candidates and compare like with like. Published work on face de-identification has used this evaluation protocol for years, and it is the correct way to test any redaction you are considering.

Choosing a method for a real job

MethodSurvives the attackImage still usefulGuarantee
Gaussian blurNoYesNone
PixelationNoYesNone
Black box / maskingYesRegion destroyedComplete, for the region
Generative face replacementUsuallyYesEmpirical, not formal
k-same familyYesDegraded realismFormal k-anonymity

Generative replacement — synthesising a new face conditioned on the surrounding context — is the practical default for dataset release. It preserves pose, lighting and the fact that a person is present, which is what a downstream detector needs. The guarantee is empirical: measured re-identification rates against known models, not a proof.

Common mistakes

Redacting only the faces the detector found. A missed face is an un-redacted face. Run at a low detection threshold, accept the false positives, and blur more than you think you need. Then audit a sample by hand.

Forgetting other identifiers in the same frame. Number plates, name badges, house numbers, screens showing an email client, unique clothing. A face-only redaction pass frequently leaves a direct identifier in shot.

Redacting the released copy and keeping the original. The original is still personal data with all the duties attached. Decide the retention position on the original before you generate the redacted set.

Believing redaction removes legal obligations. Under GDPR Recital 26, the test is whether re-identification is reasonably likely using means reasonably available. A reversible blur does not meet that test, and the data remains personal data. True anonymisation takes it out of scope; pseudonymisation does not.

Blurring only in the compressed output. If a video is redacted after encoding, motion vectors and reference frames from the original can leak the un-blurred region. Redact the frames, then encode.

Assuming the face is the identifier. Person re-identification research repeatedly shows that body, clothing and gait carry substantial identity signal. Removing the face lowers matching accuracy; it does not zero it.

Try it yourself

Cut the candidate list from twelve to three and rerun. Then raise it to two hundred by extending the seed range. Watch what happens to the margin under sixteen-pixel blocks. This tells you the one thing that actually determines whether a redaction holds: not how strong it is, but how many people the attacker has to choose between.

What to learn next

Researcher — Mathematics and papers.

Threat model first

De-identification is meaningless without stating the adversary. Three levels are standard:

  1. Naive human observer. Blurring defeats this. It is also the weakest adversary anyone should design against.
  2. Automated matcher with a candidate gallery. The parrot attack above: apply the identical transform to gallery images and match in the degraded domain. Formalised in Newton, Sweeney and Malin (IEEE TKDE 2005), which showed pixelation and blurring fail against a recognition system trained or evaluated on similarly degraded imagery.
  3. Adversary with a generative prior. Modern inversion, super-resolution and diffusion-based restoration reconstruct plausible faces from heavily degraded input. Note the important caveat: a reconstruction can be plausible without being correct, so this raises attack success against a gallery while not constituting proof of identity on its own.

Report which adversary your method resists. A method evaluated only against level 1 has not been evaluated.

The k-same family

Newton et al. (2005) introduced k-Same: partition faces into clusters of at least $k$ members, and replace every face in a cluster with the cluster average (in pixel or eigenface space). Any released face then corresponds to at least $k$ originals, so the best possible recognition rate against a gallery is bounded by $1/k$.

This is a formal guarantee, and it is what distinguishes the family from blurring. The costs are ghosting artefacts from averaging, and a requirement that the whole set be de-identified together rather than image by image.

Subsequent work replaces averaging with generation while keeping the $k$-anonymity structure: k-Same-Net (Meden et al., 2018) uses a generative network to synthesise the surrogate, and k-Same-Siamese-GAN (Pan et al., 2019) adds adversarial training. Realism improves; the guarantee is inherited from the partition, not from the generator.

Generative de-identification

DeepPrivacy (Hukkelås et al., ISVC 2019, arxiv.org/abs/1909.04538) removes the face region entirely and inpaints a new face conditioned on the surrounding image and a sparse pose keypoint set. The original face pixels are never an input to the generator, which is the design decision that matters: an identity-preserving reconstruction loss would reintroduce the leak the method exists to prevent.

More recent work explores reversible anonymisation — anonymising with a key that permits authorised recovery, for scenarios such as investigative review of surveillance footage. Examples include UU-Net (Proença, 2020), G2Face (2024) and diffusion-based schemes (2025–2026). The security of these rests on key management, and they convert a privacy problem into a key-custody problem rather than removing it.

Evaluate any generative method on three axes:

  • Privacy: rank-1 and rank-$k$ re-identification rate against several recognition models, including one the method was not tuned against.
  • Utility: downstream task performance on the anonymised data — detection AP, pose error, whatever your consumers need.
  • Naturalness: FID or human study, which matters only if the images will be looked at.

GDPR Recital 26 sets the standard: data is anonymous when the data subject is not, or is no longer, identifiable, accounting for "all the means reasonably likely to be used" by the controller or another person. Anonymous data falls outside the Regulation entirely; pseudonymous data does not.

A reversible transform therefore does not achieve anonymisation in the legal sense, whatever it is called internally. The Article 29 Working Party opinion on anonymisation techniques (WP216, 2014) assesses techniques against three risks — singling out, linkability and inference — and it remains the clearest published framework for arguing that a given method is sufficient.

The parallel point in the AI Act: Article 5(1)(e) prohibits creating or expanding facial recognition databases by untargeted scraping. A dataset of un-redacted faces scraped from the web is not made lawful by redacting it afterwards, because the prohibited act is the collection.

Beyond the face

Person re-identification research is the honest counterweight to face redaction. Work examining the contribution of facial information to re-identification finds that models retain substantial accuracy when faces are removed or obscured, drawing on clothing, body shape and gait. Gait recognition is a mature field in its own right.

For a genuinely sensitive release, the redaction plan must cover:

  • Faces and heads, including partially visible ones.
  • Text: badges, plates, screens, signage, documents.
  • Distinctive body attributes and clothing where the population is small.
  • Location and timestamp metadata, which frequently single out an individual on their own.
  • Gait, if the release is video and the candidate set is small.

Papers

  • Newton, Sweeney and Malin, Preserving Privacy by De-identifying Face Images, IEEE TKDE 2005
  • Article 29 Data Protection Working Party, Opinion 05/2014 on Anonymisation Techniques (WP216)
  • Meden et al., k-Same-Net: k-Anonymity with Generative Deep Neural Networks for Face Deidentification, Entropy 2018
  • Hukkelås et al., DeepPrivacy: A Generative Adversarial Network for Face Anonymization, ISVC 2019 — arxiv.org/abs/1909.04538
  • Proença, The UU-Net: Reversible Face De-Identification for Visual Surveillance Video Footage, 2020 — arxiv.org/abs/2007.04316
  • Wen et al., Face De-identification: State-of-the-art Methods and Comparative Studies, 2024 — arxiv.org/abs/2411.09863

What to learn next