June 8-10, 2027

São Paulo Expo - SP 1 PM to 8 PM

Fiera Milano Brazil
ABESE 30 Years

June 8-10, 2027 | São Paulo Expo - SP
1 PM to 8 PM

Anti-facial recognition technologies are fueling debates about security and privacy.

The debate surrounding data protection and privacy gained a new element in August. Researchers at the University of Chicago in the United States announced the development of software to deceive facial recognition in photos – an identification feature already used, for example, on social media.

The tool was named Fawkes, in reference to the Englishman Guy Fawkes (1570-1606), a revolutionary who inspired the creation of the mask shown in the comic book/film series. V for Vendetta and adopted by protesters worldwide. Versions of the software for Windows and Mac are available on project website, they surpassed 175,000 downloads in just a few days.

Basically, Fawkes works by applying subtle changes to photos, at the pixel level, "confusing" artificial intelligence and algorithms. The changes usually combine some facial features of the program's user with those of celebrity faces kept in an image bank, and identified by the algorithm as sufficient to fool facial recognition systems.

A test conducted by Security magazine verified that the technology is effective. Besides the fact that the manipulated portrait created by Fawkes showed almost imperceptible modifications compared to the original, Facebook was unable to correctly identify and "tag" the person using its algorithm. According to the researchers, Fawkes also managed to fool the facial recognition systems of Microsoft, Amazon, and the Chinese technology company Megvii.

The main motivation behind the creation of Fawkes was to guarantee people's privacy. The project's website points to the disclosure of the activities of the American startup Clearview AI as the trigger. According to news reports, the company collected more than 3 billion photos scattered across the internet to form a data repository that, when cross-referenced with Facebook accounts, would reveal people's identities and aid police investigations.

“Our goal is to make Clearview disappear,” Ben Zhao, a professor of computer science at the University of Chicago, told a reporter about Fawkes in an American newspaper. The New York Times.

It's worth highlighting that Fawkes is not the first and probably won't be the last effort in terms of counter-technologies to facial recognition. “There is a broad context of contesting these systems, and obfuscation techniques are a strong focus of privacy activism. The idea is that containment through laws is not enough; technological interventions are also necessary,” explains Rafael Zanatta, director of Data Privacy Brasil, an organization that brings together a data protection NGO and an educational division on the subject. “Software is the most advanced resource. But discussions about makeup techniques and disguises with accessories capable of hindering vector analysis processes of the human face are growing online and at events.”.

Today, facial recognition has two main uses. The first is in authentication systems, for identity verification, confirmation of document legitimacy and, consequently, fraud prevention. This is an aspect supported by article 11 of the General Data Protection Law (LGPD) and, therefore, should continue to progress, according to Zanatta. The other field of application, that of public security, is surrounded by much controversy.

There are many people who oppose surveillance through facial recognition systems., already used in dozens of Brazilian cities and is being studied by several others. The main argument of opponents is that the technology is invasive and oppressive, in addition to having questionable efficiency, and could trigger injustices. International studies have verified, for example, False positives in approximately 95% of facial analyses of Black people..

“In a country with structural inequality like Brazil, it’s obvious that we need to be very careful in applying these devices,” Zanatta points out, citing the problems that recently occurred in Rio: police raids aided by catalogs of photos of wanted and fugitive individuals. caused wrongful arrests.

According to the Data Privacy Brazil specialist, it will be necessary to establish legal codes for the use of this resource, with one possibility being regulated use: always based on plausible justifications and judicial permissions, with limited duration/scope and including the preparation of subsequent impact reports on civil rights. The LGPD (Brazilian General Data Protection Law) does not clearly outline rules for facial recognition, but this is not a loophole. “It's not a flaw, because the LGPD shouldn't address a specific sectoral problem. This is a demand for other projects, such as the draft laws on public security and personal data protection currently being prepared or processed in Congress or at the state level,” explains Zanatta.

In certain countries, such as the United States, there are state and municipal regulations regarding the use of facial recognition. In the United Kingdom, there is no consensus, but the Ed Bridges case of 2019 – in which... The court ruled in favor of an activist. which challenged the use of technology in public squares – promises to curb the advancement of deployments in monitoring devices. Faced with the challenges and controversies, giants like Amazon, IBM, and Microsoft announced retreats from projects related to the topic.

China, however, is going against the grain. In that country, where there is a strong culture of surveillance and less public objection, facial recognition is in full swing. As various TV and internet reports have shown, the use of such solutions intensified during the pandemic, to repress those who violated quarantine or to check the body temperature of passersby.

But, in addition to its adoption in security and public order systems, another aspect worries privacy advocates: commercial use. At the end of August, following a complaint from Idec (Brazilian Institute for Consumer Protection), Senacon (National Consumer Secretariat) fined Hering. The reason: the fashion company used facial recognition in a store in São Paulo to capture consumers' reactions without their knowledge. It was the first conviction in Brazil for violation of rights in the use of facial recognition.

“The message is clear: companies need to inform consumers about this type of initiative, so as not to violate the principle of transparency. Care must be taken with information security and good faith,” emphasizes Zanatta. He believes that the trend is for a scenario of actions and reactions similar to what happens with digital viruses and antivirus software to consolidate in the future.

Regarding proposals like Fawkes, everything suggests they will become popular through smartphone apps or easy-to-apply filters on networks like Instagram. "Imagine these obfuscation techniques being taught by influencers on YouTube, for example. The viral spread will be rapid, and life won't be easy for companies and startups involved with facial recognition," the expert predicts.

 

SOURCE:
SECURITY

Share this content

Comments

Open chat
1
Exposec
Hello 👋
Can we help you?