Face swaps on Reddit: I built the harmless version years ago
Someone on Reddit is putting celebrities' faces into porn with a home GPU and open-source tools. How it works, and why consent has to be designed in now.
Motherboard reported this week on a Reddit user called “deepfakes” who has been posting porn videos with celebrities’ faces swapped in. They’re not perfect, but some are convincing at a glance, and they were made by one person with consumer hardware and open-source machine learning libraries.
The technique, as far as people have worked it out from the posts, is a pair of autoencoders with a shared encoder. You collect a few hundred or thousand images of person A and person B. You train one encoder that compresses any face into a small code, and two decoders, one that reconstructs A’s face from the code and one that reconstructs B’s. Because the encoder is shared, it learns to represent things common to both faces, like pose, expression and lighting, and the decoders learn the identity. To swap, you encode a frame of A and decode it with B’s decoder. You get B’s face with A’s expression, pose and lighting, which you then blend back into the frame.
This is a close relative of what I worked on for years. In 2013 we took a selfie, built a 3D model, and made it move with someone else’s expressions. The goal was fun: put yourself in a game, make your face sing. The core problem is the same: separate identity from expression, then recombine them. We did it with geometry and hand-built models. This does it with a network that learns the separation from data. It needs no 3D modeling skills, and it’s already better at the things we struggled with, like skin texture and lighting.
The technology was always going to get here. Face tracking, GANs and autoencoders have all been improving in public for years. What’s new is that the pieces got easy enough for anyone to use, and the first large use of it is non-consensual porn. That’s depressing and not surprising.
What should people building face technology do? I think a few things have to become default rather than optional. Consent for your own face: tools that make it easy to use your face, and hard to use someone else’s without permission. Provenance: some way to mark generated media so platforms can detect and label it. And platform policy: Reddit and others will have to decide quickly whether they host this.
None of that is a complete answer, and I’m not sure there is one. The capability won’t go away, and in a couple of years it will run on a phone. The time to design how faces get used is before that happens, not after the first scandal big enough to force it.