Ghostmaxxing A public lab for testing face-recognition camouflage
Vision & About

Make the machine-readable face contestable.

Ghostmaxxing is a browser-based workshop assistant and public research platform for testing face-recognition camouflage.

It grows out of privacy activism, adversarial makeup workshops, and the need to investigate which biometric systems are actually used in public space.

Workshop assistant.

Designed to support group workshops, where participants play with makeup and learn how different faces read to a recognition model: point a browser camera at your face, record a baseline, then change your look — paint directly on the tracked face or follow a guided pattern — and watch how the local recognition pipeline reacts in real time.

The goal is to lower the barrier to entry. You don't need a makeup specialist to take part — only water-based colors, safe enough for kids. The system runs locally: it uses the webcam or a phone camera, keeps everything on-device, and sends nothing anywhere else, except what you choose to share with us.

The project is built to run in a phone browser, because makeup is usually applied in front of a mirror, not at a desktop workstation.

Two kinds of success exist: the face stops being detected as a face at all, or the face is still detected but its extracted points differ enough from the clean-face baseline that matching fails.

What can be sent to us?

Three things mostly:

  1. Before/after images of a successful attempt, sent via the share icon in the lab.
  2. A one-second video of a successful attempt.
  3. A camouflage pattern you baked from a look that worked, so others can study and retest it. This is the technical layer — mostly for people who want to look into how it works; see the Ghostyle documentation.

Keep what works.

When a look defeats the local match, you can keep that exact state: paint it on the tracked face in the lab and bake it into a reusable pattern others can study and retest. Automatically extracting a pattern from a pair of before/after photos is a much harder research problem, and one we deliberately don't depend on.

These approaches are experimental. We can't guarantee they will work — and a human reviewing camera footage can often still recognize someone even when they're wearing makeup. A browser result is a local, conditional finding, not a general protection claim.

Where it comes from.

Ghostmaxxing is the international evolution of an experiment run by NINA.watch. As part of the Universal Digital Union, Ghòstati (become a ghost) is a workshop we keep repeating to explore adversarial makeup as a way to resist facial recognition. The project began in May 2026 during the NINA festival, in Milan and Rome. We learned from Michelle Tylicki, an artist who has run this kind of workshop before us — we added the application development, and now this wider vision.

Tylicki's DAZZLE, developed with Lauri Love, is an art-and-tech installation and interactive tool for teaching Computer Vision Dazzle, also known as anti-surveillance makeup. Ghostmaxxing inherits that workshop energy, but turns it into a browser-based system people can run on their own devices.

Vision.

  • Make the workshop easier to run.
  • Make adversarial makeup a popular practice, not a niche one.
  • Collect evidence of what actually works.
  • Support new forms — clothing, 3D-printed objects, and beyond.
  • Support new research.
  • Use network effects to test everywhere, share results, and keep improving.

The research question is minimal camouflage.

The core question is simple: how little makeup is needed to disrupt a face-recognition pipeline?

Less makeup matters because it lowers the barrier to practice. It makes the technique easier to learn, easier to repeat, and easier to move from exceptional workshop performance toward everyday culture. The hope is not to sell invisibility; it is to make adversarial makeup legible enough to become pop practice.

Success should be shareable.

Ghostmaxxing includes sharing-oriented functions because a successful look is also a teachable pattern. People who want to share a one-second video, a before/after comparison, or a Ghostyle result can help others understand what worked and what still needs to be tested.

Why leaking matters.

The lab can test browser pipelines, but real-world facial recognition is a supply chain: camera hardware, edge devices, model vendors, watchlists, matching systems, dashboards, alerts, metadata, operators, procurement contracts, and retention rules.

Leak to us exists to understand that hidden chain. Which technologies are deployed? Who sells them? Who maintains them? What metadata is produced between capture and decision? Where does it go? Who can access it? Tell us what you know, only if it is safe for you to do so — and please don't include unnecessary personal data.

Some allies may be forced to work on or near these systems. If they can safely share information, they may help us understand whether Ghostyles and adversarial makeup are actually affecting real deployments, or whether the resistance needs to change.

In Europe, real-time remote biometric identification in publicly accessible spaces for law enforcement is treated as a prohibited AI practice, subject to narrow exceptions and safeguards. That legal frame still leaves a practical question: what is actually being deployed, and under whose control?

A ban that keeps getting reopened.

The Reclaim Your Face campaign has spent years pushing for a ban on biometric mass surveillance, and it helped get real-time remote biometric identification treated as prohibited in EU law. But the fight didn't end with the text of the regulation: national security agendas keep reopening the exceptions, arguing for carve-outs around major events, "special" cases, and pilot deployments. Reporting from the campaign has documented national authorities attempting to work around the AI Act's limits rather than comply with them. A ban that keeps getting quietly worked around by fear-mongering, securitarian framing needs the same kind of public pressure and evidence-gathering that got it written in the first place — which is part of why the reporting node exists here too.

Internal tools & diagnostics.

To support deeper analysis, model testing, and pattern sharing, Ghostmaxxing includes experimental diagnostic tools. These utilities run entirely locally in the browser to examine recorded behavior and transfer designs.

Video Loader

The Video Loader allows users to import local MP4 video files to run against our on-device 2D and 3D face-detection engines. This allows for precise frame-by-frame analysis, face extraction, database recording, and signature comparison without requiring a live camera feed. It is designed to evaluate recorded workshop outcomes or diagnostic video tracks under stable, repeatable conditions.

Ghostyle Transfer

The Ghostyle Transfer tool extracts painted makeup patterns from a workshop before/after image pair and attaches them to a new target face. When the local face engine detects matching landmarks, the tool aligns the pattern using a 3D face mesh. Otherwise, it scales the pattern using manual bounding boxes, letting researchers visual-test camouflage layouts on different facial structures before physical application.

Latent Space Visualizer

The Latent Space Visualizer is a real-time visual debugger for analyzing face descriptor drift. By recording a baseline face signature via webcam, it tracks facial embedding alterations and showcases biometric distance thresholds alongside a 128-dimensional descriptor equalizer. It is used to study exactly how specific facial movements, lighting shifts, and makeup strokes skew facial signatures.

Read, test, report.

Ghostmaxxing is strongest when the lab, the archive, and the reporting channel work together. Test techniques locally, read the lineage of anti-biometric appearance design, and help document the real infrastructure when it appears in the world.