EN AR
EN

Abu Dhabi researchers build face-photo shield that survives compression

Sukaina Khalid

Also in: UAE

Key Points

  1. MBZUAI and Khalifa University unveiled FaceGuardian, a defense against AI diffusion edits of face photos.
  2. Earlier pixel-noise protections are stripped out when apps automatically resize or compress uploaded images.
  3. The method keeps working after compression, closing the gap that made prior defenses useless online.

The latest:

A new protection method developed in Abu Dhabi keeps face photos resistant to AI editing even after they are compressed and resized, the step that defeated earlier defenses. Researchers at MBZUAI and Khalifa University said their system, FaceGuardian, won a Best Paper Award at the LifeGenIP workshop held at ECCV. It remains a research method, not a consumer product.

Details:

  • The problem: Existing protections work by adding faint pixel-level noise meant to confuse AI editing tools. According to MBZUAI, that noise is stripped away when an image is resized or compressed, which happens automatically on most apps and social platforms, leaving the uploaded photo fully exposed to diffusion-model editing.
  • The approach: Instead of noise, FaceGuardian alters the image inside a learned space of facial features known as a StyleGAN latent space. The researchers said this produces realistic changes that still look like the same person to a human viewer while disrupting diffusion models trying to edit the face.
  • Headline number: On one benchmark dataset, face-recognition similarity between the AI-edited output and the original photo fell from 0.833 without protection to 0.272 with FaceGuardian, according to the university. Lower scores mean less of the original identity survived into the edited image, indicating stronger protection.
  • Versus rivals: The next-best existing method scored 0.315 on the same uncompressed test, a narrower margin than the compression results suggest. The researchers presented the two figures together as evidence that FaceGuardian leads even before durability is factored in.
  • The durability test: After compression, the decisive scenario for real-world uploads, FaceGuardian still registered 0.361 while the next-best method, FaceLock, rose to 0.709, according to MBZUAI. The widening gap is the core claim: rival protection largely collapses once an image passes through ordinary platform processing.
  • Test conditions: Evaluation covered two open-source diffusion models in what the researchers described as a gray box setting, meaning the attacking model’s architecture was known but its prompts were not. Fully closed commercial editing systems were not part of this round of testing.
  • Next steps: The team said it plans to extend testing to closed and commercial models, and to video. No timeline was given for that work, and no release date or distribution plan was announced for turning the method into a tool available to the public.
  • The institutions: The work came from MBZUAI, the Mohamed bin Zayed University of Artificial Intelligence, together with Khalifa University, both based in Abu Dhabi. The award was announced at a workshop attached to ECCV, one of the main international computer vision conferences.

Background:

Diffusion models can edit an existing face photo from a text instruction, producing convincing images of real people in scenes that never occurred. Defenses have focused on making the source photo unusable to such systems rather than detecting the output afterward.

Between the lines:

The compression result is the substantive advance. With uncompressed images, FaceGuardian’s 0.272 against a rival’s 0.315 is a modest edge; after compression the separation widens to 0.361 against 0.709. Because resizing and compression happen automatically on upload, a protection that only holds on untouched files offers little practical cover, which is the limitation the researchers set out to address.

What’s next

Watch for results against closed commercial editing models and video, the two extensions the team named, and for any indication that the method moves from research paper toward a usable tool.

What to read next