Pith. sign in

REVIEW 2 major objections 2 minor 125 references

AuraMask: An Extensible Pipeline for Developing Aesthetic Anti-Facial Recognition Image Filters

T0 review · 2 major / 2 minor · reviewed 2026-05-14 · grok-4.3

Pith's one-line read AuraMask pipeline produces aesthetic filters that block facial recognition while matching Instagram styles.

desk verdict AuraMask gives a pipeline for Instagram-style anti-FR filters with a decent user study on acceptance, but effectiveness is only shown on open-source models. read the letter →

arxiv 2605.12937 v1 pith:Z3VOTPH2 submitted 2026-05-13 cs.CV cs.AIcs.HC

classification cs.CVcs.AIcs.HC
keywords anti-facialrecognitionaestheticfiltersadversarialeffectivenessuseracceptanceimageprivacyprotectionInstagramstyles
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper presents AuraMask as a pipeline for generating anti-facial recognition filters that alter images subtly to computers yet remain visually appealing to people. It creates 40 filters by emulating popular one-click Instagram edits. These filters match or exceed the success of earlier methods at fooling open-source facial recognition models. A user study with 630 participants shows markedly higher acceptance for the new filters than for previous approaches. The authors release the full pipeline to support further development of such protections.

What carries the argument

AuraMask, an extensible pipeline that generates anti-facial recognition filters by emulating popular Instagram image processing styles.

What would settle it

A direct test in which AuraMask filters fail to lower recognition accuracy on a major commercial facial recognition API would disprove the effectiveness claim.

Watch

Extended reading notes

Core claim

AuraMask is an extensible pipeline for creating anti-facial recognition image filters that emulate popular Instagram one-click styles. The authors use it to generate 40 aesthetic filters. These filters achieve adversarial effectiveness against open-source facial recognition models that meets or exceeds prior methods. In a controlled online study with 630 participants the same filters obtain significantly higher user acceptance than earlier anti-facial recognition techniques.

Load-bearing premise

That results shown on open-source facial recognition models and in a controlled online user study will hold for proprietary real-world systems and everyday photo use.

Editorial extensions

If this is right

  • Forty aesthetic filters are produced that equal or surpass prior methods against open-source facial recognition models.
  • The filters receive significantly higher user acceptance than prior methods in a study of 630 participants.
  • Releasing the pipeline enables faster community research on effective and acceptable protections.
  • Filters integrate as simple one-click edits similar to existing social media tools.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Widespread use could reduce the reliability of facial recognition in public photo sharing platforms.
  • Integration into standard photo apps might make privacy-preserving edits a default option for users.
  • Further tests on proprietary systems and diverse real-world images would clarify practical limits.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 2 minor

Summary. The manuscript introduces AuraMask, an extensible pipeline for generating aesthetic anti-facial recognition (AFR) image filters that emulate popular one-click Instagram filters. The authors produce 40 such filters and report that they meet or exceed the adversarial effectiveness of prior methods when tested against open-source facial recognition models. A controlled online user study with N=630 participants is presented to show significantly higher user acceptance compared to previous AFR approaches. The pipeline is released publicly to support further community research.

Significance. If the empirical results on open-source models and the user acceptance findings hold under broader conditions, this work could meaningfully advance practical AFR tools by reducing the aesthetic barrier that currently limits adoption. The public release of the extensible pipeline is a clear strength, as it directly supports reproducibility and allows other researchers to extend or adapt the approach.

major comments (2)
  1. [Abstract and §4] Abstract and §4 (Evaluation): The central claim of practical AFR protection is load-bearing on generalization beyond the tested open-source models, yet all reported adversarial results are confined to open-source facial recognition models with no transferability experiments, black-box evaluations, or tests against proprietary systems that may use different backbones, ensembles, or adversarial training.
  2. [§5] §5 (User Study): The claim of significantly higher user acceptance rests on the N=630 study, but the manuscript provides insufficient detail on the precise statistical tests, effect sizes, confidence intervals, or controls for image content and presentation order, which are necessary to assess whether the acceptance advantage is robust.
minor comments (2)
  1. [§3] §3 (Pipeline): The description of how the 40 filters were selected from the extensible pipeline would benefit from an explicit enumeration or selection criterion to aid reproducibility.
  2. [Figure 2] Figure 2: Side-by-side visual comparisons of original images, prior AFR methods, and AuraMask outputs would improve clarity when illustrating aesthetic differences.

Simulated Author's Rebuttal

2 responses · 1 unresolved

We thank the referee for the constructive feedback. We address each major comment below and describe the planned revisions to strengthen the manuscript while maintaining its core contributions on the extensible pipeline and empirical results for open-source models.

read point-by-point responses
  1. Referee: [Abstract and §4] Abstract and §4 (Evaluation): The central claim of practical AFR protection is load-bearing on generalization beyond the tested open-source models, yet all reported adversarial results are confined to open-source facial recognition models with no transferability experiments, black-box evaluations, or tests against proprietary systems that may use different backbones, ensembles, or adversarial training.

    Authors: We acknowledge that our adversarial evaluations are restricted to open-source models, which aligns with standard practice in the field for ensuring reproducibility. To address this, we will add transferability experiments across multiple open-source facial recognition architectures in the revised §4 and include an expanded limitations discussion on the difficulties of black-box and proprietary evaluations. The public release of the AuraMask pipeline is explicitly intended to enable the community to perform such extensions. We cannot, however, directly test proprietary systems as they are not accessible. revision: partial

  2. Referee: [§5] §5 (User Study): The claim of significantly higher user acceptance rests on the N=630 study, but the manuscript provides insufficient detail on the precise statistical tests, effect sizes, confidence intervals, or controls for image content and presentation order, which are necessary to assess whether the acceptance advantage is robust.

    Authors: We agree that additional statistical details are required for full transparency. In the revised manuscript, we will specify the exact tests (e.g., paired t-tests or mixed-effects models), report effect sizes and confidence intervals, and detail the controls including use of identical base images across filter conditions and randomized presentation order. These additions will appear in §5 with supporting tables in the supplementary material. revision: yes

standing simulated objections not resolved
  • Direct evaluation against proprietary facial recognition systems, as these are not publicly available to researchers.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: purely empirical pipeline with external validation

full rationale

The paper describes an extensible pipeline (AuraMask) for generating aesthetic anti-facial-recognition filters by emulating Instagram styles, then evaluates them via direct experiments on open-source facial recognition models and a separate controlled user study (N=630). No equations, derivations, fitted parameters renamed as predictions, or self-citation chains appear in the provided abstract or reader summary; the central claims rest on measured adversarial success rates and acceptance scores rather than any self-referential construction. The work is therefore self-contained against its own benchmarks and receives the default non-circularity finding.

Assumptions & free parameters 0 free parameters · 0 assumptions · 0 invented entities

Based solely on the abstract, no explicit free parameters, axioms, or invented entities are detailed. The pipeline likely involves standard optimization techniques from adversarial ML without new postulated entities.

how reviews work

0 comments
Cite this review

Pith. "Pith review of AuraMask: An Extensible Pipeline for Developing Aesthetic Anti-Facial Recognition Image Filters." pith.science (2026). https://pith.science/paper/Z3VOTPH2

@misc{pith2026260512937,
  author       = {Pith},
  title        = {Pith review of: AuraMask: An Extensible Pipeline for Developing Aesthetic Anti-Facial Recognition Image Filters},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/Z3VOTPH2}},
  note         = {Machine review of arXiv:2605.12937}
}
abstract

Anti-facial recognition (AFR) image filters alter images in ways that are subtle to people but blinding to computer vision. Yet, despite widespread interest in these technologies to subvert surveillance, users rarely use them in practice -- because the ``subtle'' alterations are visible enough to conflict with users' self-presentation goals. To address this challenge, we propose AuraMask: a novel approach to creating AFR filters that are both adversarially effective and aesthetically acceptable. Using AuraMask, we produce 40 ``aesthetic'' filters that emulate popular ``one-click'' Instagram image filters. We show that AuraMask filters meet or exceed the adversarial effectiveness of prior methods against open-source facial recognition models. Moreover, in a controlled online user study ($N=630$) we confirm these filters achieve significantly higher user acceptance than prior methods. Lastly, we provide our AFR pipeline to the community for accelerated research in adversarially effective and aesthetically acceptable protections.

Figures

Figures reproduced from arXiv: 2605.12937 by the authors.

Figure 1
Figure 1. Aesthetic AFR defenses with Single (top) and Ensemble (bottom) Targets produced with the AuraMask pipeline. [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. Face verification task with obfuscation opportunity in green and obfuscation target highlighted in orange. [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. Plot of face embedding losses with respect to cosine distance, highlighting where faces are considered validated for [PITH_FULL_IMAGE:figures/full_fig_p006_3.png] view at source ↗
Figures from the paper (8 more)
Figure 4
Figure 4. Figure 4: LFW pairwise face verification recall using ArcFace, VGGFace2, Facenet embeddings across defenses. [PITH_FULL_IMAGE:figures/full_fig_p012_4.png]
Figure 5
Figure 5. Figure 5: Perceptual similarity assessment across defenses. [PITH_FULL_IMAGE:figures/full_fig_p013_5.png]
Figure 6
Figure 6. Figure 6: Screenshot of survey instrument used for collection of SAIA-8 responses. [PITH_FULL_IMAGE:figures/full_fig_p015_6.png]
Figure 7
Figure 7. Figure 7: Five images selected for second iteration of SAIA-8 data collection. [PITH_FULL_IMAGE:figures/full_fig_p016_7.png]
Figure 8
Figure 8. Figure 8: Distribution of SAIA-8 scores in each iteration with conditions grouped on statistical similarity ( [PITH_FULL_IMAGE:figures/full_fig_p017_8.png]
Figure 9
Figure 9. Figure 9: Defenses tested in the acceptability task, charted along user acceptability (x-axis) and similarity relative to the original image [PITH_FULL_IMAGE:figures/full_fig_p018_9.png]
Figure 10
Figure 10. Figure 10: Plackett-Luce worth parameters for the grid preference selection task, grouped using pairwise statistical comparisons. Higher [PITH_FULL_IMAGE:figures/full_fig_p019_10.png]
Figure 11
Figure 11. Figure 11: ATN trained only using TopIQ as perceptual loss. [PITH_FULL_IMAGE:figures/full_fig_p027_11.png]

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

125 extracted references · 125 canonical work pages

  1. [1]

    William Agnew, Kevin R McKee, I Gabriel, J Kay, W Isaac, AS Bergman, S El-Sayed, and S Mohamed. 2023. Technologies of Resistance to AI.Equity and Access in Algorithms, Mechanisms, and Optimization(2023), 1–13. 9Available here: https://gitlab.com/raccs-lab/auramask-library 22 Lagogiannis et al

  2. [2]

    Good, Simon King, Mor Naaman, and Rahul Nair

    Shane Ahern, Dean Eckles, Nathaniel S. Good, Simon King, Mor Naaman, and Rahul Nair. 2007. Over-Exposed? Privacy Patterns and Considerations in Online and Mobile Photo Sharing. InProceedings of the SIGCHI Conference on Human Factors in Computing Systems (CHI ’07). Association for Computing Machinery, New York, NY, USA, 357–366. doi:10/dhkjj4

  3. [3]

    Naveed Akhtar and Ajmal Mian. 2018. Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey.IEEE Access6 (Feb. 2018), 14410–14430. arXiv:1801.00553 doi:10/gfxzrs

  4. [4]

    Recurrent Residual Convolutional Neural Network based on U-Net (R2U-Net) for Medical Image Segmentation

    Md Zahangir Alom, Mahmudul Hasan, Chris Yakopcic, Tarek M. Taha, and Vijayan K. Asari. 2018. Recurrent Residual Convolutional Neural Network Based on U-Net (R2U-Net) for Medical Image Segmentation. arXiv:1802.06955 [cs] doi:10.48550/arXiv.1802.06955

  5. [5]

    Bertenthal, and Apu Kapadia

    Mary Jean Amon, Rakibul Hasan, Kurt Hugenberg, Bennett I. Bertenthal, and Apu Kapadia. 2020. Influencing Photo Sharing Decisions on Social Media: A Case of Paradoxical Findings. In2020 IEEE Symposium on Security and Privacy (SP) (IEEE Symposium on Security and Privacy 2020). IEEE, San Francisco, CA, USA, 1350–1366. doi:10/gmbpwp

  6. [6]

    N. D. Amsden, L. Chen, and X. Yuan. 2014. Transmitting Hidden Information Using Steganography via Facebook. InFifth International Conference on Computing, Communications and Networking Technologies (ICCCNT). 1–7. doi:10/gsnqr9

  7. [7]

    Saeideh Bakhshi, David Shamma, Lyndon Kennedy, and Eric Gilbert. 2015. Why We Filter Our Photos and How It Impacts Engagement.Proceedings of the International AAAI Conference on Web and Social Media9, 1 (2015), 12–21. doi:10/gsnqvd

  8. [8]

    Shumeet Baluja and Ian Fischer. 2017. Adversarial Transformation Networks: Learning to Generate Adversarial Examples. arXiv:1703.09387 [cs] doi:10.48550/arXiv.1703.09387

Show all 125 references
  1. [9]

    You Take Fifty Photos, Delete Forty Nine and Use One

    Beth T. Bell. 2019. “You Take Fifty Photos, Delete Forty Nine and Use One”: A Qualitative Study of Adolescent Image-Sharing Practices on Social Media.International Journal of Child-Computer Interaction20 (June 2019), 64–71. doi:10/gjvm4p

  2. [10]

    Sam Biddle. 2020. Police Surveilled George Floyd Protests With Help From Twitter-Affiliated Startup Dataminr. https://theintercept.com/2020/07/09/twitter-dataminr-police-spy-surveillance-black-lives-matter-protests/

  3. [11]

    Russell Brandom. 2016. Facebook, Twitter, and Instagram Surveillance Tool Was Used to Arrest Baltimore Protestors. https://www.theverge.com/2016/10/11/13243890/facebook-twitter-instagram-police-surveillance-geofeedia-api

  4. [12]

    That Moment of Curiosity

    Kat Brewster, Aloe DeGuia, and Samuel Mayworm. 2025. "That Moment of Curiosity": Augmented Reality Face Filters for Transgender Identity Exploration, Gender Affirmation, and Radical Possibility. (2025)

  5. [13]

    André Brock. 2012. From the Blackhand Side: Twitter as a Cultural Conversation.Journal of Broadcasting & Electronic Media56, 4 (Oct. 2012), 529–549. doi:10/gddxwm

  6. [14]

    2015.Dark Matters: On the Surveillance of Blackness

    Simone Browne. 2015.Dark Matters: On the Surveillance of Blackness. Duke University Press

  7. [15]

    2015.Obfuscation: A User’s Guide for Privacy and Protest

    Finn Brunton and Helen Fay Nissenbaum. 2015.Obfuscation: A User’s Guide for Privacy and Protest. MIT Press, Cambridge, Massachusetts

  8. [16]

    Nhat-Tan Bui, Ngoc-Thao Nguyen, and Xuan-Nam Cao. 2022. Structure-Aware Photorealistic Style Transfer Using Ghost Bottlenecks. InPattern Recognition and Artificial Intelligence, Mounîm El Yacoubi, Eric Granger, Pong Chi Yuen, Umapada Pal, and Nicole Vincent (Eds.). Springer In...

  9. [17]

    Vladimir Bychkovsky, Sylvain Paris, Eric Chan, and Frédo Durand. 2011. Learning Photographic Global Tonal Adjustment with a Database of Input / Output Image Pairs. InThe Twenty-Fourth IEEE Conference on Computer Vision and Pattern Recognition

  10. [18]

    Hey, I’m Having These Experiences

    Paul Byron, Brady Robards, Benjamin Hanckel, Son Vivienne, and Brendan Churchill. 2019. "Hey, I’m Having These Experiences": Tumblr Use and Young People’s Queer (Dis)Connections.International Journal of Communication13 (2019), 2239–2259

  11. [19]

    Qiong Cao, Li Shen, Weidi Xie, Omkar M Parkhi, and Andrew Zisserman. 2018. Vggface2: A Dataset for Recognising Faces across Pose and Age. In 2018 13th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2018). IEEE, 67–74

  12. [20]

    Nathalie Casemajor, Stéphane Couture, Mauricio Delfin, Matthew Goerzen, and Alessandro Delfanti. 2015. Non-Participation in Digital Media: Toward a Framework of Mediated Political Action.Media, Culture & Society37, 6 (Sept. 2015), 850–866. doi:10/gndhkm

  13. [21]

    Varun Chandrasekaran, Chuhan Gao, Brian Tang, Kassem Fawaz, Somesh Jha, and Suman Banerjee. 2021. Face-Off: Adversarial Face Obfuscation. Proceedings on Privacy Enhancing Technologies2021, 2 (April 2021), 369–390. doi:10/gsnqn2

  14. [22]

    Chaofeng Chen, Jiadi Mo, Jingwen Hou, Haoning Wu, Liang Liao, Wenxiu Sun, Qiong Yan, and Weisi Lin. 2023. TOPIQ: A Top-down Approach from Semantics to Distortions for Image Quality Assessment. arXiv:2308.03060 doi:10.48550/arXiv.2308.03060

  15. [23]

    Valeriia Cherepanova, Micah Goldblum, Harrison Foley, Shiyuan Duan, John Dickerson, Gavin Taylor, and Tom Goldstein. 2021. LowKey: Leveraging Adversarial Attacks to Protect Social Media Users from Facial Recognition.arXiv:2101.07922 [cs](Jan. 2021). arXiv:2101.07922 [cs]

  16. [24]

    Mitchell Church, Ravi Thambusamy, and Hamid Nemati. 2020. User Misrepresentation in Online Social Networks: How Competition and Altruism Impact Online Disclosure Behaviours.Behaviour & Information Technology39, 12 (Dec. 2020), 1320–1340. doi:10/gpbrfj

  17. [25]

    Sauvik Das. 2020. Subversive AI: Resisting Automated Algorithmic Surveillance with Human-Centered Adversarial Machine Learning. InResistance AI Workshop at NeurIPS. 4

  18. [26]

    Julia Davies. 2007. Display, Identity and the Everyday: Self-presentation through Online Image Sharing.Discourse: studies in the cultural politics of education28, 4 (2007), 549–564. doi:10/c99wtk

  19. [27]

    Brown, and Peyman Milanfar

    Mauricio Delbracio, Damien Kelly, Michael S. Brown, and Peyman Milanfar. 2021. Mobile Computational Photography: A Tour.Annual Review of Vision Science7, 1 (2021), 571–604. doi:10/gmx68q

  20. [28]

    Jiankang Deng, Jia Guo, Niannan Xue, and Stefanos Zafeiriou. 2019. Arcface: Additive Angular Margin Loss for Deep Face Recognition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 4690–4699. AuraMask 23

  21. [29]

    Diakogiannis, François Waldner, Peter Caccetta, and Chen Wu

    Foivos I. Diakogiannis, François Waldner, Peter Caccetta, and Chen Wu. 2020. ResUNet-a: A Deep Learning Framework for Semantic Segmentation of Remotely Sensed Data.ISPRS Journal of Photogrammetry and Remote Sensing162 (April 2020), 94–114. doi:10.1016/j.isprsjprs.2020.01.013

  22. [30]

    2019.New York City Police Department Surveillance Technology

    Angel Diaz. 2019.New York City Police Department Surveillance Technology. Technical Report. Brennan Center for Justice

  23. [31]

    Grinter, Jessica Delgado de la Flor, and Melissa Joseph

    Paul Dourish, Rebecca E. Grinter, Jessica Delgado de la Flor, and Melissa Joseph. 2004. Security in the Wild: User Strategies for Managing Security as an Everyday, Practical Problem.Personal and Ubiquitous Computing8, 6 (Nov. 2004), 391–401. doi:10/dw9f76

  24. [32]

    Ádám Erdélyi, Thomas Winkler, and Bernhard Rinner. 2013. Serious Fun: Cartooning for Privacy Protection.. InProceedings of the MediaEval 2013 Multimedia Benchmark Workshop, Barcelona, Spain, October 18-19, 2013. (MediaEval 2013)

  25. [33]

    Yihua Fan, Yongzhen Wang, Dong Liang, Yiping Chen, Haoran Xie, Fu Lee Wang, Jonathan Li, and Mingqiang Wei. 2024. Low-FaceNet: Face Recognition-Driven Low-Light Image Enhancement.IEEE Transactions on Instrumentation and Measurement73 (2024), 1–13. doi:10.1109/TIM.2024. 3372230

  26. [34]

    Vendemia

    Jesse Fox and Megan A. Vendemia. 2016. Selective Self-Presentation and Social Comparison Through Photographs on Social Networking Sites. Cyberpsychology, Behavior, and Social Networking19, 10 (Oct. 2016), 593–600. doi:10/ghcbdf

  27. [35]

    Ashley Gorski. 2022. The Biden Administration’s SIGINT Executive Order, Part II: Redress for Unlawful Surveillance.Just Security(2022)

  28. [36]

    Mitchell Gray. 2003. Urban Surveillance and Panopticism: Will We Recognize the Facial Recognition Society?Surveillance & Society1, 3 (2003), 314–330. doi:10/gs42bb

  29. [37]

    Cory Hallam and Gianluca Zanella. 2017. Online Self-Disclosure: The Privacy Paradox Explained as a Temporally Discounted Balance between Concerns and Rewards.Computers in Human Behavior68 (March 2017), 217–227. doi:10/f9nv3s

  30. [38]

    Daniel A Hanley and Sally Hubbard. 2020. Eyes Everywhere: Amazon’s Surveillance Infrastructure and Revitalizing Worker Power.Open Markets Institute(2020)

  31. [39]

    Bertenthal, Kurt Hugenberg, and Apu Kapadia

    Rakibul Hasan, Bennett I. Bertenthal, Kurt Hugenberg, and Apu Kapadia. 2021. Your Photo Is so Funny That I Don’t Mind Violating Your Privacy by Sharing It: Effects of Individual Humor Styles on Online Photo-sharing Behaviors. InProceedings of the 2021 CHI Conference on Human F...

  32. [40]

    Crandall, Roberto Hoyle, and Apu Kapadia

    Rakibul Hasan, Eman Hassan, Yifang Li, Kelly Caine, David J. Crandall, Roberto Hoyle, and Apu Kapadia. 2018. Viewer Experience of Obscuring Scene Elements in Photos to Enhance Privacy. InProceedings of the 2018 CHI Conference on Human Factors in Computing Systems (CHI ’18). As...

  33. [41]

    Hassan, Rakibul Hasan, Patrick Shaffer, David Crandall, and Apu Kapadia

    Eman T. Hassan, Rakibul Hasan, Patrick Shaffer, David Crandall, and Apu Kapadia. 2017. Cartooning for Enhanced Privacy in Lifelogging and Streaming Videos. In2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW) (CVPR 2017). IEEE, Honolulu, HI, USA,...

  34. [42]

    J. He, B. Liu, D. Kong, X. Bao, N. Wang, H. Jin, and G. Kesidis. 2016. PUPPIES: Transformation-Supported Personalized Privacy Preserving Partial Image Sharing. In2016 46th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). 359–370. doi:10/gsnqqm

  35. [43]

    Kashmir Hill. 2020. This Tool Could Protect Your Photos From Facial Recognition.The New York Times(Aug. 2020)

  36. [44]

    Ho and Jinjia Zhou

    Man M. Ho and Jinjia Zhou. 2021. Deep Preset: Blending and Retouching Photos with Color Style Transfer. arXiv:2007.10701 [cs, eess] doi:10.48550/arXiv.2007.10701

  37. [45]

    Jahng, Namyeon Lee, and Kevin R

    Seoyeon Hong, Mi R. Jahng, Namyeon Lee, and Kevin R. Wise. 2020. Do You Filter Who You Are?: Excessive Self-Presentation, Social Cues, and User Evaluations of Instagram Selfies.Computers in Human Behavior104 (March 2020), 106159. doi:10/gnfnbd

  38. [46]

    Yuheng Hu, Lydia Manikonda, and Subbarao Kambhampati. 2014. What We Instagram: A First Analysis of Instagram Photo Content and User Types.Proceedings of the International AAAI Conference on Web and Social Media8, 1 (May 2014), 595–598. doi:10/gr739d

  39. [47]

    Gary B Huang, Marwan Mattar, Tamara Berg, and Eric Learned-Miller. 2008. Labeled Faces in the Wild: A Database Forstudying Face Recognition in Unconstrained Environments. InWorkshop on Faces in’Real-Life’Images: Detection, Alignment, and Recognition

  40. [48]

    Håkon Hukkelås, Rudolf Mester, and Frank Lindseth. 2019. DeepPrivacy: A Generative Adversarial Network for Face Anonymization. InAdvances in Visual Computing (Lecture Notes in Computer Science, Vol. 11844), George Bebis, Richard Boyle, Bahram Parvin, Darko Koracin, Daniela Ush...

  41. [49]

    Shehzeen Hussain, Todd Huster, Chris Mesterharm, Paarth Neekhara, and Farinaz Koushanfar. 2023. ReFace: Adversarial Transformation Networks for Real-time Attacks on Face Recognition Systems. In2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networ...

  42. [50]

    Sergio Ibáñez-Sánchez, Carlos Orús, and Carlos Flavián. 2022. Augmented Reality Filters on Social Media. Analyzing the Drivers of Playability Based on Uses and Gratifications Theory.Psychology & Marketing39, 3 (March 2022), 559–578. doi:10/gpbsqv

  43. [51]

    Panagiotis Ilia, Iasonas Polakis, Elias Athanasopoulos, Federico Maggi, and Sotiris Ioannidis. 2015. Face/Off: Preventing Privacy Leakage from Photos in Social Networks. InProceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS ’15). Associat...

  44. [52]

    Ana Javornik, Ben Marder, Jennifer Brannon Barhorst, Graeme McLean, Yvonne Rogers, Paul Marshall, and Luk Warlop. 2022. ‘What Lies behind the Filter?’ Uncovering the Motivations for Using Augmented Reality (AR) Face Filters on Social Media and Their Effect on Well-Being.Comput...

  45. [53]

    Nicola Jones. 2024. The AI Revolution Is Running out of Data. What Can Researchers Do?Nature636, 8042 (Dec. 2024), 290–292. doi:10.1038/d41586- 024-03990-2 24 Lagogiannis et al

  46. [54]

    Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012. ImageNet Classification with Deep Convolutional Neural Networks. InAdvances in Neural Information Processing Systems, Vol. 25. Curran Associates, Inc

  47. [55]

    Isadora Krsek, Anubha Kabra, Yao Dou, Tarek Naous, Laura A Dabbish, Alan Ritter, Wei Xu, and Sauvik Das. 2025. Measuring, Modeling, and Helping People Account for Privacy Risks in Online Self-Disclosures with AI.Proceedings of the ACM on Human-Computer Interaction9, 2 (2025), 1–31

  48. [56]

    2008.Surveillance Unlimited : How We’ve Become the Most Watched People on Earth

    Keith Laidler. 2008.Surveillance Unlimited : How We’ve Become the Most Watched People on Earth. Cambridge [England] : Icon Books Ltd. : Distributed in the UK by TBS Ltd

  49. [57]

    Huang, Aruni RoyChowdhury, Haoxiang Li, and Gang Hua

    Erik Learned-Miller, Gary B. Huang, Aruni RoyChowdhury, Haoxiang Li, and Gang Hua. 2016. Labeled Faces in the Wild: A Survey. InAdvances in Face Detection and Facial Image Analysis, Michal Kawulok, M. Emre Celebi, and Bogdan Smolka (Eds.). Springer International Publishing, Ch...

  50. [58]

    Bin Li, Junhui He, Jiwu Huang, and Yun Qing Shi. 2011. A Survey on Image Steganography and Steganalysis.J. Inf. Hiding Multim. Signal Process. 2, 2 (April 2011), 142–172

  51. [59]

    Knijnenburg, and Kelly Caine

    Yifang Li, Nishant Vishwamitra, Hongxin Hu, Bart P. Knijnenburg, and Kelly Caine. 2017. Effectiveness and Users’ Experience of Face Blurring as a Privacy Protection for Sharing Photos via Online Social Networks.Proceedings of the Human Factors and Ergonomics Society Annual Mee...

  52. [60]

    Arriaga, and Sauvik Das

    Jacob Logas, Poojita Garg, Rosa I. Arriaga, and Sauvik Das. 2024. The Subversive AI Acceptance Scale (SAIA-8): A Scale to Measure User Acceptance of AI-generated, Privacy-Enhancing Image Modifications.Proc. ACM Hum.-Comput. Interact.8, CSCW1, Article 185 (April 2024). doi:10.1...

  53. [61]

    Jacob Logas, Ari Schlesinger, Zhouyu Li, and Sauvik Das. 2022. Image DePO: Towards Gradual Decentralization of Online Social Networks Using Decentralized Privacy Overlays.Proceedings of the ACM on Human-Computer Interaction6, CSCW1 (March 2022), 1–28. doi:10/gsnqpm

  54. [62]

    Ilya Loshchilov and Frank Hutter. 2019. Decoupled Weight Decay Regularization. arXiv:1711.05101 [cs] doi:10.48550/arXiv.1711.05101

  55. [63]

    Katerina Lup, Leora Trub, and Lisa Rosenthal. 2015. Instagram #Instasad?: Exploring Associations Among Instagram Use, Depressive Symptoms, Negative Social Comparison, and Strangers Followed.Cyberpsychology, Behavior, and Social Networking18, 5 (May 2015), 247–252. doi:10.1089/...

  56. [64]

    Ryan Mac, Caroline Haskins, and Logan McDonald. 2020. Clearview’s Facial Recognition App Has Been Used By The Justice Department, ICE, Macy’s, Walmart, And The NBA. https://www.buzzfeednews.com/article/ryanmac/clearview-ai-fbi-ice-global-law-enforcement

  57. [65]

    Penousal Machado and Amilcar Cardoso. 1998. Computing Aesthetics. InAdvances in Artificial Intelligence (Lecture Notes in Computer Science), Flávio Moreira de Oliveira (Ed.). Springer, Berlin, Heidelberg, 219–228. doi:10/dnwxc3

  58. [66]

    Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2019. Towards Deep Learning Models Resistant to Adversarial Attacks.arXiv:1706.06083 [cs, stat](Sept. 2019). arXiv:1706.06083 [cs, stat]

  59. [67]

    I. Manokha. 2018. Surveillance, Panopticism, and Self-Discipline in the Digital Age.Surveillance and Society16, 2 (2018). doi:10/gg4sxm

  60. [68]

    Sanya Mansoor. 2025. Pro-Palestinian Activists under Increased Surveillance on Massachusetts Campuses. https://www.wgbh.org/news/local/2025- 03-24/pro-palestinian-activists-under-increased-surveillance-on-massachusetts-campuses

  61. [69]

    Filippo Menczer and Thomas Hills. 2020. The Attention Economy.Scientific American323, 6 (2020), 54–61

  62. [70]

    Fausto Milletari, Nassir Navab, and Seyed-Ahmad Ahmadi. 2016. V-Net: Fully Convolutional Neural Networks for Volumetric Medical Image Segmentation. arXiv:1606.04797 [cs.CV]

  63. [71]

    Amar Kumar Mohapatra, Kamal Kumar, and Shubha Swarup. 2025. A Comparative Review and Performance Benchmarking of Face Recognition. Proceedings of Data Analytics and Management: ICDAM 2025, Volume 55 (2025), 320

  64. [72]

    Kyzyl Monteiro, Yuchen Wu, and Sauvik Das. 2025. Imago Obscura: An Image Privacy AI Co-Pilot to Enable Identification and Mitigation of Risks. InProceedings of the 38th Annual ACM Symposium on User Interface Software and Technology. 1–26

  65. [73]

    Shyam Sundar

    Anne Oeldorf-Hirsch and S. Shyam Sundar. 2016. Social and Technological Motivations for Online Photo Sharing.Journal of Broadcasting & Electronic Media60, 4 (Oct. 2016), 624–642. doi:10/gsnfbs

  66. [74]

    Hammerla, Bernhard Kainz, Ben Glocker, and Daniel Rueckert

    Ozan Oktay, Jo Schlemper, Loic Le Folgoc, Matthew Lee, Mattias Heinrich, Kazunari Misawa, Kensaku Mori, Steven McDonagh, Nils Y. Hammerla, Bernhard Kainz, Ben Glocker, and Daniel Rueckert. 2018. Attention U-Net: Learning Where to Look for the Pancreas. arXiv:1804.03999 [cs] do...

  67. [75]

    Parkhi, Andrea Vedaldi, and Andrew Zisserman

    Omkar M. Parkhi, Andrea Vedaldi, and Andrew Zisserman. 2015. Deep Face Recognition. InProcedings of the British Machine Vision Conference

  68. [76]

    doi:10/gf7pj3

    British Machine Vision Association, Swansea, 41.1–41.12. doi:10/gf7pj3

  69. [77]

    Sarah Parvini, Garance Burke, and Jesse Bedayn. 2024. Surveillance Tech Advances by Biden Could Aid in Trump’s Promised Crackdown on Immigration. https://apnews.com/article/artificial-intelligence-ai-deportation-biden-trump-immigration-0a0c2387762a7342af5668660f0391b5

  70. [78]

    Yilang Peng. 2017. Time Travel with One Click: Effects of Digital Filters on Perceptions of Photographs. InProceedings of the 2017 CHI Conference on Human Factors in Computing Systems (CHI ’17). Association for Computing Machinery, New York, NY, USA, 6000–6011. doi:10/gsnqr2

  71. [79]

    Penousal Machado, Juan Romero, and Bill Z. Manaris. 2008. Experiments in Computational Aesthetics.. InThe Art of Artificial Evolution 2008 (Natural Computing Series). Springer, Berlin, Heidelberg, 381–415. doi:10/bkrcv3

  72. [80]

    Daniela Petrelli and Steve Whittaker. 2010. Family Memories in the Home: Contrasting Physical and Digital Mementos.Personal and Ubiquitous Computing14, 2 (Feb. 2010), 153–169. doi:10.1007/s00779-009-0279-7 AuraMask 25

  73. [81]

    Proudfoot, David Wilson, Joseph S

    Jeffrey G. Proudfoot, David Wilson, Joseph S. Valacich, and Michael D. Byrd. 2018. Saving Face on Facebook: Privacy Concerns, Social Benefits, and Impression Management.Behaviour & Information Technology37, 1 (Jan. 2018), 16–37. doi:10/gg6cxt

  74. [82]

    Anthony Quintano. 2019. Mark Zuckerberg F8 2019 Keynote

  75. [83]

    Moo-Ryong Ra, Ramesh Govindan, and Antonio Ortega. 2013. P3: Toward Privacy-Preserving Photo Sharing.. InProceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2013, Lombard, IL, USA, April 2-5, 2013 (NSDI 2013). 515–528

  76. [84]

    Evani Radiya-Dixit and Florian Tramèr. 2021. Data Poisoning Won’t Save You From Facial Recognition.arXiv:2106.14851 [cs](June 2021). arXiv:2106.14851 [cs]

  77. [85]

    Robin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser, and Björn Ommer. 2022. High-Resolution Image Synthesis with Latent Diffusion Models. arXiv:2112.10752 [cs] doi:10.48550/arXiv.2112.10752

  78. [86]

    Olaf Ronneberger, Philipp Fischer, and Thomas Brox. 2015. U-Net: Convolutional Networks for Biomedical Image Segmentation. InMedical Image Computing and Computer-Assisted Intervention – MICCAI 2015, Nassir Navab, Joachim Hornegger, William M. Wells, and Alejandro F. Frangi (Ed...

  79. [87]

    Meredith Salisbury and Jefferson D. Pooley. 2017. The #nofilter Self: The Contest for Authenticity among Social Networking Sites, 2002–2016. Social Sciences6, 1 (March 2017), 10. doi:10.3390/socsci6010010

  80. [88]

    Ilyssa Salomon and Christia Spears Brown. 2021. That Selfie Becomes You: Examining Taking and Posting Selfies as Forms of Self-Objectification. Media Psychology24, 6 (Nov. 2021), 847–865. doi:10/gndjh2

  81. [89]

    Brubaker

    Morgan Klaus Scheuerman, Kandrea Wade, Caitlin Lustig, and Jed R. Brubaker. 2020. How We’ve Taught Algorithms to See Identity: Constructing Race and Gender in Image Databases for Facial Analysis.Proceedings of the ACM on Human-Computer Interaction4, CSCW1 (May 2020), 058:1–058...

  82. [90]

    Florian Schroff, Dmitry Kalenichenko, and James Philbin. 2015. FaceNet: A Unified Embedding for Face Recognition and Clustering. InProceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 815–823

  83. [91]

    Evan Selinger and Woodrow Hartzog. 2020. The Inconsentability of Facial Surveillance Consentability Symposium.Loyola Law Review66, 1 (2020), 33–54

  84. [92]

    Ayon Sen, Xiaojin Zhu, Erin Marshall, and Robert Nowak. 2020. Popular Imperceptibility Measures in Visual Adversarial Attacks Are Far from Human Perception. InDecision and Game Theory for Security (Lecture Notes in Computer Science), Quanyan Zhu, John S. Baras, Radha Poovendra...

  85. [93]

    Sefik Serengil and Alper Ozpinar. 2024. A Benchmark of Facial Recognition Pipelines and Co-Usability Performances of Modules.Journal of Information Technologies17, 2 (2024), 95–107. doi:10.17671/gazibtd.1399077

  86. [94]

    Sefik Ilkin Serengil and Alper Ozpinar. 2020. LightFace: A Hybrid Deep Face Recognition Framework. In2020 Innovations in Intelligent Systems and Applications Conference (ASYU). IEEE, Istanbul, Turkey, 1–5. doi:10.1109/ASYU50717.2020.9259802

  87. [95]

    Yingkai Sha. 2021. Keras-Unet-Collection. GitHub. doi:10.5281/zenodo.5449801

  88. [96]

    Shawn Shan, Emily Wenger, Jiayun Zhang, Huiying Li, Haitao Zheng, and Ben Y Zhao. 2020. Fawkes: Protecting Privacy against Unauthorized Deep Learning Models.. In29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020 (USENIX Security Symposium 2020). 1589–1604

  89. [97]

    Katie Shepherd. 2020. An Artist Stopped Posting Protest Photos Online to Shield Activists from Police. Then, He Was Arrested.Washington Post (Aug. 2020)

  90. [98]

    Freeman, and Fredo Durand

    YiChang Shih, Sylvain Paris, Connelly Barnes, William T. Freeman, and Fredo Durand. 2014. Style Transfer for Headshot Portraits.MIT web domain(July 2014)

  91. [99]

    Shumeet Baluja. 2017. Hiding Images in Plain Sight: Deep Steganography.. InNIPS 2017. Curran Associates, Inc., 2069–2079

  92. [100]

    Brian Solis. 2008. SXSW Mark Zuckerberg Keynote -

  93. [101]

    Lars St, Svante Wold, et al. 1989. Analysis of Variance (ANOVA).Chemometrics and intelligent laboratory systems6, 4 (1989), 259–272

  94. [102]

    Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing Properties of Neural Networks.. InICLR 2014. arXiv:1312.6199 [cs]

  95. [103]

    Monika Taddicken. 2014. The ‘Privacy Paradox’ in the Social Web: The Impact of Privacy Concerns, Individual Characteristics, and the Perceived Social Relevance on Different Forms of Self-Disclosure*.Journal of Computer-Mediated Communication19, 2 (Jan. 2014), 248–273. doi:10/f5pv2z

  96. [104]

    Hossein Talebi and Peyman Milanfar. 2018. NIMA: Neural Image Assessment.IEEE Transactions on Image Processing27, 8 (Aug. 2018), 3998–4011. doi:10/gdpcsd

  97. [105]

    Alise Tifentale and Lev Manovich. 2015. Selfiecity: Exploring Photography and Self-Fashioning in Social Media. InPostdigital Aesthetics: Art, Computation and Design, David M. Berry and Michael Dieter (Eds.). Palgrave Macmillan UK, London, 109–122. doi:10.1057/9781137437204_9

  98. [106]

    Ethan Tseng, Yuxuan Zhang, Lars Jebe, Xuaner Zhang, Zhihao Xia, Yifei Fan, Felix Heide, and Jiawen Chen. 2022. Neural Photo-Finishing.ACM Transactions on Graphics41, 6 (Dec. 2022), 1–15. doi:10/gtn99d

  99. [107]

    John W Tukey. 1949. Comparing Individual Means in the Analysis of Variance.Biometrics. Journal of the International Biometric Society(1949), 99–114

  100. [108]

    2025.PlackettLuce: Plackett-luce Models for Rankings

    Heather Turner, Ioannis Kosmidis, and David Firth. 2025.PlackettLuce: Plackett-luce Models for Rankings. doi:10.32614/CRAN.package.PlackettLuce

  101. [109]

    Turner, Jacob van Etten, David Firth, and Ioannis Kosmidis

    Heather L. Turner, Jacob van Etten, David Firth, and Ioannis Kosmidis. 2020. Modelling Rankings in R: The PlackettLuce Package.Computational Statistics35 (2020), 1027–1057. doi:10.1007/s00180-020-00959-3 26 Lagogiannis et al

  102. [110]

    Rehmat Ullah, Hassan Hayat, Afsah Abid Siddiqui, Uzma Abid Siddiqui, Jebran Khan, Farman Ullah, Shoaib Hassan, Laiq Hasan, Waleed Albattah, Muhammad Islam, and Ghulam Mohammad Karami. 2022. A Real-Time Framework for Human Face Detection and Recognition in CCTV Images. Mathemat...

  103. [111]

    Vendemia and David C

    Megan A. Vendemia and David C. DeAndrea. 2021. The Effects of Engaging in Digital Photo Modifications and Receiving Favorable Comments on Women’s Selfies Shared on Social Media.Body Image37 (June 2021), 74–83. doi:10/gsnqrr

  104. [112]

    Venkataramanan, Chengyang Wu, Alan C

    Abhinau K. Venkataramanan, Chengyang Wu, Alan C. Bovik, Ioannis Katsavounidis, and Zafar Shahid. 2021. A Hitchhiker’s Guide to Structural Similarity.IEEE Access9 (2021), 28872–28896. arXiv:2101.06354 [cs, eess] doi:10/gtq92w

  105. [113]

    Hoai Nam Vu, Mai Huong Nguyen, and Cuong Pham. 2022. Masked Face Recognition with Convolutional Neural Networks and Local Binary Patterns.Applied Intelligence52, 5 (2022), 5497–5512

  106. [114]

    Manish Reddy Vuyyuru, Andrzej Banburski, Nishka Pant, and Tomaso Poggio. 2020. Biologically Inspired Mechanisms for Adversarial Robustness.. InAdvances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, D...

  107. [115]

    Emily Wenger, Shawn Shan, Haitao Zheng, and Ben Y. Zhao. 2023. Sok: Anti-facial Recognition Technology. In2023 IEEE Symposium on Security and Privacy (SP). IEEE, 864–881. doi:10/gsnqrg

  108. [116]

    Teke Wiggin. 2025. Weaponizing the Workplace: How Algorithmic Management Shaped Amazon’s Antiunion Campaign in Bessemer, Alabama. Socius11 (Aug. 2025), 23780231251318389. doi:10.1177/23780231251318389

  109. [117]

    Li, Tianxiang Wei, Xiaohui Liang, and Qingxu Wang

    Bailin Yang, Changrui Zhu, Frederick W.B. Li, Tianxiang Wei, Xiaohui Liang, and Qingxu Wang. 2023. IAACS: Image Aesthetic Assessment through Color Composition and Space Formation.Virtual Reality & Intelligent Hardware5, 1 (2023), 42–56. doi:10/gst4h2

  110. [118]

    Jonghwa Yim, Jisung Yoo, Won-joon Do, Beomsu Kim, and Jihwan Choe. 2020. Filter Style Transfer Between Photos. InComputer Vision – ECCV 2020, Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.). Vol. 12351. Springer International Publishing, Cham, 103–119....

  111. [119]

    Bo Yu and Ian Lane. 2014. Multi-Task Deep Learning for Image Understanding. In2014 6th International Conference of Soft Computing and Pattern Recognition (SoCPaR). 37–42. doi:10/gtgm6v

  112. [120]

    Dan Zeng, Raymond Veldhuis, and Luuk Spreeuwers. 2021. A Survey of Face Recognition Techniques under Occlusion.IET Biometrics10, 6 (2021), 581–606. doi:10.1049/bme2.12029

  113. [121]

    Kaipeng Zhang, Zhanpeng Zhang, Zhifeng Li, and Yu Qiao. 2016. Joint Face Detection and Alignment Using Multitask Cascaded Convolutional Networks.IEEE Signal Processing Letters23, 10 (Oct. 2016), 1499–1503. doi:10/gfhwcq

  114. [122]

    Efros, Eli Shechtman, and Oliver Wang

    Richard Zhang, Phillip Isola, Alexei A. Efros, Eli Shechtman, and Oliver Wang. 2018. The Unreasonable Effectiveness of Deep Features as a Perceptual Metric. In2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2018). IEEE, Salt Lake City, UT, 586–595. do...

  115. [123]

    Dorothy Zhao, Mikako Inaba, and Andrés Monroy-Hernández. 2022. Understanding Teenage Perceptions and Configurations of Privacy on Instagram.Proceedings of the ACM on Human-Computer Interaction6, CSCW2, Article 550 (Nov. 2022), 28 pages. doi:10/gsnqsg

  116. [124]

    Yan Zhao, Xiuying Wang, Tongtong Che, Guoqing Bao, and Shuyu Li. 2023. Multi-Task Deep Learning for Medical Image Computing and Analysis: A Review.Computers in Biology and Medicine153 (Feb. 2023), 106496. doi:10/gr2dvr

  117. [125]

    Diana Zulli. 2018. Capitalizing on the Look: Insights into the Glance, Attention Economy, and Instagram.Critical Studies in Media Communication 35, 2 (March 2018), 137–150. doi:10.1080/15295036.2017.1394582 1 I don’t feel comfortable with the changes made to the photograph. 2 ...

Pith tools

Reviewed May 14, 2026 · model on record in the stance chip above.