Researchers use duelling AI’s to defeat facial recognition technology
As both our online, as well as our offline privacy, continue to be eroded, scientists are using AI to fight back.
Key takeaways
- Aarabi and Bose then tested the system on the existing so called 300-W face dataset, which consists of photos of over 600 faces covering different ethnicities, lighting conditions and environments.
- Without the algorithm being applied to those images, a facial recognition system was able to accurately identify almost 100 percent of the people.
- Once it was applied, however, that rate dropped to 0.5 percent.
Cite or link to this article
Griffin, M. (2018) 'Researchers use duelling AI’s to defeat facial recognition technology', 311 Institute, 5 June. Available at: https://www.311institute.com/researchers-use-duelling-ais-to-defeat-facial-recognition-technology/ (Accessed: 1 October 2026).
Most of us probably don't like the idea of some stranger finding out who we are, and then where we live, or what we’ve been up to recently, and so on, just by uploading a photo of us to any social media platform like Facebook, but thanks to the facial recognition systems used by social media sites this form of stalking, surveillance, or whatever moniker you decide to give it, even if you're wearing a mask, is becoming increasingly possible, so much so that scientists, as well as others, recently decided to do something about it by turning a couple of Artificial Intelligence (AI) systems against one another. And who knows, it might even be a technology that helps us uncover fake news video footage, or let criminals slip through border security unnoticed, a phenomenon called photo-morphing, that I wrote about a while go, that's already being used in real life. It's also not the first time that two AI's have duelled, Google pitted two against each other recently to see who'd win, then found out the more powerful AI became aggressive and won, but that's another story...
At the University of Toronto in Canada, Prof. Parham Aarabi and grad student Avishek Bose started by designing two AI based neural networks. One of these used the same techniques as existing facial recognition systems, to identify people in photos. The other network sought to thwart the first one, by slightly altering the aspects of those photos that were being used to identify the people.

Even simple adjustments fool facial recognition systems
"The disruptive AI can 'attack' what the neural net for the face detection is looking for," says Bose, "if the detection AI is looking for the corner of the eyes, for example, it adjusts the corner of the eyes so they're less noticeable. It creates very subtle disturbances in the photo, but to the detector they're significant enough to fool the system."
The two networks went back and forth for a while, each one learning what the other was doing and trying to compensate for it. What ultimately resulted was an algorithm that could be applied to photos of faces, making them nearly facial recognition-proof yet still recognisable to people who knew them.
Aarabi and Bose then tested the system on the existing so called 300-W face dataset, which consists of photos of over 600 faces covering different ethnicities, lighting conditions and environments. Without the algorithm being applied to those images, a facial recognition system was able to accurately identify almost 100 percent of the people. Once it was applied, however, that rate dropped to 0.5 percent.
It’s now hoped that the algorithm could be integrated into a publicly-available app or website that people who are concerned about their privacy could use to treat or edit their photos appropriately before posting them.
Source: University of Toronto
FAQ
Why does this matter?
As both our online, as well as our offline privacy, continue to be eroded, scientists are using AI to fight back.

About the author
Matthew Griffin Founder, 311 Institute
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."
Read full bio
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.
An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.
As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.
Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.
What future do you need to see?
Choose one to get started on security and privacy and the future of your organisation.
Sources and further reading
- University of Toronto news.engineering.utoronto.ca
Source: first published by the 311 Institute on 5 June 2018. Cite as: Griffin, M. (2018). Researchers use duelling AI’s to defeat facial recognition technology. 311 Institute. https://www.311institute.com/researchers-use-duelling-ais-to-defeat-facial-recognition-technology/
You are welcome to quote this article with credit and a link to the original.