
Alibi
AI Face Anonymization
Overview
The Problem
Publishing video of recognizable people without their consent is a real privacy problem under GDPR: faces often need to be obscured before publication. The problem is that doing it manually is unsustainably slow. A 10-minute video with 20 people on screen requires hours of frame-by-frame work. For journalistic content, surveillance footage, or field research, this becomes a real bottleneck.
The risk is not just time: it's easy to miss a face in a crowded scene or a blurred frame. A single omission in a legal or journalistic context can have serious consequences.
The Solution
Alibi is an appliance that runs locally. A FastAPI backend handles login, users, the task queue and an audit log that can't be deleted. The video is uploaded in chunks, a worker analyzes it and then produces the blurred version.
For detection I use two ONNX models, RetinaFace and YOLOX, with a tracker that follows each face across the whole video and blur applied frame by frame. On Apple Silicon the detector runs on CoreML, much faster than on CPU in my benchmarks.
Privacy is part of the design: files expire (30 days by default) and GDPR deletion immediately removes the original and the output and wipes the job's personal data. Only a skeleton is kept for the audit.
The Result
In the benchmark on an Apple M3 Pro, one hour of 25 fps video takes about 2.4 hours to analyze, about 5.7 if the video is 60 fps. It is not a real-time system: it makes sense for queued processing. For now I've tried it on test videos and it has no client in production yet.
Key Features
- Face detection with RetinaFace and YOLOX, tracking across the whole video
- Chunked upload and task queue: probe, analysis, render, finalization
- File expiry and GDPR deletion, with a tamper-proof audit log
- FastAPI backend with login, users and Docker installer