Can AI unblur a face? A realistic result can still be wrong

You've probably seen the before-and-after images. On the left, a face reduced to a few blurry blocks. On the right, a perfectly plausible person. Eyes, skin, little hairs, the whole thing.
Blur can leave identifying information behind. But a sharp AI result doesn't prove that somebody recovered the original face. It may have made up a person who fits the blurry picture.
Before deciding what a demonstration means for your child's photo, ask what happened between those two pictures. Did the software recover surviving detail, recognise the person, or invent a face? The first two can present a privacy problem even when nobody produces an impressive portrait. The third can look convincing while showing the wrong person entirely.
The video about undoing pixelation is a useful warning
In “It's easier than ever to de-censor videos”, published April 15, 2025, Jeff Geerling describes a challenge involving a pixelated computer window. His own lightly edited transcript explains how participants recovered hidden text using information from multiple moving frames.
The movement is the part to pay attention to. A video gives someone more than one look at the hidden material. Something that appears unreadable in a paused frame may leave enough information across the clip to work with.
That example demonstrates a weakness in the pixelation used there. It doesn't demonstrate that any stranger can recover an unknown child's original face from any heavily obscured video. Text, faces, the filter and the information left in the file all matter.
Still, I think the lesson for publishing is uncomfortable enough on its own: looking at one frame and deciding “I can't read that” isn't a sufficient check.
A generated face can be completely imaginary
Take PULSE, a research project from 2020. It generates detailed faces that look like the blurry starting picture when shrunk down. Several different faces can fit that same starting point. The paper explains how it makes those images, and the researchers' own project page explicitly warns that the resulting faces are imaginary, not identification or reconstruction of the original person.
In other words, the software can supply details it was never given. Photographic-looking details. That makes a striking demonstration, but the appearance of certainty comes from the image, not from evidence that it's correct.
When you see one of these comparisons, ask which of these jobs the tool actually performed:
| What happened | What you can conclude |
|---|---|
| Some hidden detail was recovered | The blur or blocks left clues that helped work out what was underneath. |
| A plausible face was generated | A face fits the input. It may not be the person in the original. |
| An identity was recognised | A system could match the person, even without drawing a clear face. |
A before-and-after picture on its own doesn't tell you which row you're looking at.
Recognition doesn't need to give you a portrait
This is the less spectacular problem, and it's easy to overlook while everyone is admiring the generated eyelashes.
In Defeating Image Obfuscation with Deep Learning, Richard McPherson, Reza Shokri and Vitaly Shmatikov demonstrated recognition of faces protected by some forms of blur and pixelation. The experiments used particular collections of pictures, examples the software learned from and ways of hiding the faces. They didn't establish that every hidden face is identifiable. They did show why “a human can't see it clearly” is a weak test of privacy. Original research paper
And then there's the much simpler version. You cover a child's face, leave their name in the caption and post it from the family account. Or there's a school badge, a familiar room, a voice calling their name. Someone who knows the family may have all the information they need already.
We shouldn't become so occupied with what a model might recover that we miss what we've plainly included.
Make the file reveal less
For an ordinary post, obscuring a face can reduce what you expose. If revealing the person could have serious consequences, I'd take a more conservative route: keep the image unpublished, crop the person out, or use a fully opaque cover over the whole identifying area for the entire clip. Sometimes the right edit is not publishing that picture.
A fully opaque cover is a solid shape you can't see through. When you save a new copy with that shape built into the image, it replaces the part of the picture beneath it. A blur still shows a softened version of the face. That difference matters, but coverage still has to be complete. The patch needs to follow the person through movement, and the rest of the image and audio can still identify them. Our blur, pixelate or cover comparison explains the tradeoffs.
Once you've edited, review the file you're actually going to upload:
- Watch the exported clip all the way through, including entrances, turns and fast movement.
- Look closely at the start and end of covered sections for a brief uncovered face.
- Check mirrors, screens and people in the background.
- Listen for names and locations, then read the caption as a separate part of the post.
- Confirm you've selected the finished export, rather than the original sitting beside it.
The video face-blurring guide goes into tracking and export checks. This review is less exciting than an AI demo. It's also something you can actually do before the file leaves your phone.
Stacking effects isn't a security proof
Adding several effects may change how much detail survives. Counting the effects doesn't tell you how much. Neither a complicated-looking edit nor our own face-covering tool gives us grounds to promise that an image is anonymous.
The research links above let you inspect what has been demonstrated. You don't need to send your child's original face to an unfamiliar “unblur” website to see whether privacy is worth bothering with.
Choose an image that gives away as little as the post requires. Then check what survived your edit. Whether an AI can draw a believable face is a different question from whether you've shared enough information for someone to know whose face it is.
Sources reviewed 5 September 2026. Source links appear alongside the relevant advice.