Redaction, Video Redaction, Redactor

Blur vs Pixelate vs Solid Fill, and Why Redacted Video Must Fail Safe

Choosing between blur and pixelation looks like a question of house style until someone asks whether the face under the mask could be recovered, and for video the answer depends on more than the filter. In the blur vs pixelate comparison, both styles leave a weakened trace of the face in the pixels, and machine learning can sometimes use it. A solid fill leaves nothing of the face behind and can carry the exemption code printed on the mask.

The other decision that settles whether a redacted video leaks is what the software does when something breaks partway through a job. Our guide to video redaction best practices sets both beside the timing and tracking failures that affect every recording. Both can be tested before a tool is trusted with a live release, and the checks near the end of this article show how.

What blur, pixelation and a solid fill leave behind

A mask burned into a re-encoded video replaces the original pixels, which sets it apart from an overlay placed on a document, where the original can survive intact underneath. Under blur or pixelation, what remains in the video is a weakened version of the face.

How much of the face survives depends on the filter and how strongly it is applied, which is where the research comes in. The Scientific Working Group on Digital Evidence (SWGDE) summarizes that research in its Video and Audio Redaction Guidelines. It reports that "a mosaic filter when set to an extreme pixelation will create a visual effect that prevents humans and machine learning/facial recognition technology from revealing the identity of redacted information." A heavy gaussian blur, by contrast, "will make the image unrecognizable by humans," yet "a machine learning approach may be able to identify the object or subject from the remaining image boundary information."

Academic work has demonstrated the weakness directly, using the kinds of blur and pixelation that real services apply. McPherson, Shokri and Shmatikov found in 2016 that modern image recognition methods "can recover hidden information from images protected by various forms of obfuscation." The forms they tested included pixelation and the blurring used by a major video platform.

SWGDE's practical advice follows from that research, starting with a mosaic filter, where users should "ensure the cell size or pixel matrix size renders all redacted content unidentifiable." For a solid shape, "the opacity of the shape must not allow the redacted content to remain visible." The guidelines also strongly recommend choosing "a filter that once rendered and exported from the software is irreversible," which only a fully opaque fill guarantees by construction.

The table below sets out what each style leaves in a released frame and what to test before adopting it as a house style.

Style What stays in the released pixels What to test before adopting it
Blur A smoothed version of the region, with its outline and shading intact Whether a face is still recognizable at the distances and sizes your footage contains
Pixelation Averaged blocks, whose size relative to the region decides how much detail survives Whether the smallest regions you mask actually change, and whether larger ones are coarse enough
Solid fill Nothing of the original region That the fill is fully opaque and any exemption code on it is legible

A house style has to suit the audience as well as the threat, since blur and pixelation keep a scene readable for a viewer who needs to follow what happened. A solid fill makes the withholding unmistakable instead, and it gives an exemption code somewhere to sit. In the UK the Information Commissioner's Office leaves the choice open, listing blurring, masking and a solid fill among the techniques for answering requests for CCTV. A unit can reasonably use pixelation coarse enough for its smallest regions in crowd scenes and a solid fill for anyone who must never be recovered, such as a witness or an undercover officer.

Why a video track is weaker than a still

A single blurred photo gives anyone trying to recover a face one view of it, while a blurred video gives them many slightly different views. Each frame catches the face at a slightly different position, angle and light, and each blurred copy loses slightly different detail. The National Institute of Standards and Technology (NIST) reaches the same point in its report on de-identification of personal information. It warns: "Care must also be taken if pixelation or blurring are used for obscuring video, as technology exists for de-pixelating and de-blurring video by combining multiple images."

SWGDE makes a related point about strength across a clip, advising that "the intensity of the filter should be adjusted throughout the redacted video segments to ensure the protected information is properly obscured." For releases that must hold up against a determined requester, that argues for a solid fill, or for pixelation coarse enough for the smallest masked region, ahead of blur.

Small regions need stronger masks

A distant face, a license plate or a single printed character may be only a few pixels across, which is where a mask sized for a close-up face stops working. Pixelation applied with a fixed block size can return a region that small with no pixel changed while the job still counts it as masked. A region small in one direction only, such as a thin line of text, can keep about half its detail.

VIDIZMO Redactor derives pixelation strength from each region's own size, so every region collapses to at least one block while large regions keep their full strength. Mask edges are rounded outward, so rounding can only grow a mask, a rule our article on frame-by-frame redaction sets out. A code drawn on a mask is sized to the mask as well, so a small region carries less text than a large one.

Completeness matters as much as strength, and a person standing on the seam of a 360-degree frame needs a mask at both edges of the flat image. Our article on 360-degree video and images explains why the seam splits people in two.

Failing safe inside a job: one bad frame

A single frame can fail to take its masks in the middle of a long job, from something as small as a malformed coordinate. On a four-hour recording, passing that frame through would put it in the output exactly as recorded, every face and plate on it visible, in a job marked successful.

Redactor writes that frame fully black and carries on with the job, which is failing safe without stopping. Dropping the frame instead would shift every later timestamp by one frame and pull the picture out of step with its sound. Stopping the job would throw away hours of work over a single frame, and the release would wait for a rerun.

A black frame has a cost of its own, because it withholds a whole frame where only a face or a plate was exempt. Under the segregability rule discussed in our guide, that is a real withholding, however brief. A pipeline that writes black frames should therefore keep them rare, and a reviewer should be able to find each one and ask why it is there.

Failing safe for the whole job

A job can also fail as a whole while leaving behind a file that plays. A masking stage can stop partway through while the encoder closes the output cleanly, so the file exists, plays and is not empty. In one such case a 456-frame source came out as 200 frames, and the job reported success.

A file that exists proves nothing about whether its redaction finished, which is why every stage has to report completion before anything is published. In Redactor, a stage that quits early, an encoder that errors out or a run past its configured time limit ends the job, deletes the partial file and publishes nothing. That is the fail-safe default our guide traces back to security engineering in the 1970s.

Encoder failures are a special case, because some of them can be fixed by trying again. A hardware encoder can fail under load, or the disk can fill in the middle of writing. Either way a failed encode can leave a partial file behind, which a workflow will accept if all it checks is that the output exists.

Redactor retries an encoder failure once on a different encoder, and it never retries around a masking failure, because encoding again cannot put a mask on a frame where drawing it failed. If both encoding attempts fail, the job fails and the partial file is deleted.

Even a job with nothing to blur in the picture has to prove that it finished before anything is published. A video whose picture needs no masks but whose audio does can be finished by copying the picture and attaching the redacted audio. A copy that stops partway could then be published as the finished asset if nothing checked it. Every path through a job in Redactor, that one included, has to show it completed.

The cost of failing safe, and the checks to run

Failing safe accepts a small, visible loss, such as a black frame or a job that has to be rerun, to avoid a large one that nobody sees until a requester does. SWGDE's guidelines put the emphasis on "testing and evaluating software prior to use to ensure the effects are irreversible once rendered," which is the last check in the table below. A job that stopped early is caught by comparing the redacted file's length and frame count with the original, the first check in our guide's release checklist.

Check How to run it What it catches
The smallest masked regions Compare them pixel for pixel with the original Masks that changed nothing, or too little
Exemption codes on small masks Look at the smallest masks that carry a code Codes cut short or too small to read
Black frames Scan the output for fully black frames and account for each one Frames that failed to mask, and whether there are too many
Reversibility Try to recover a known face from a test clip redacted in the chosen style, before adopting it A style too weak for your footage

Two questions belong in every evaluation of a redaction tool, ours included: what happens to a frame that fails to mask, and what happens to a job that stops halfway. A precise answer to both shows that the vendor has planned for failure, and a vague one leaves the buyer to find out on a live release. Recording each black frame and each rerun in the redaction log keeps the answers on file for the next reviewer.

Mask styles, exemption codes and fail-closed output in Redactor

Redactor applies blur, pixelation or a solid fill per job and burns it into a new copy, with the original kept by default, so a failed job loses nothing. The exemption code can be drawn onto the mask from default lists for the US and UK Freedom of Information Acts and the US Privacy Act, or from an organization's own list. Choosing the right exemption for each mask remains a reviewer's judgment.

For the full picture of detection, review and output together, see how Redactor masks and releases redacted video.

TopicsRedactionVideo RedactionRedactor

You may also like

Video Redaction Best Practices: Motion, Frame Rates, Tracking and Failing Safe

I led our video redaction project for a county public safety agency where two people handled every disclosure, and ...

Redacting Dash Cam, Body Cam and Drone Footage From a Moving Camera

A fleet claims manager preparing crash footage for an insurer and defense counsel is doing a different job from a ...

Why Frame-Rate Headers Lie: Redacting Variable Frame Rate Video

A video file keeps time frame by frame, and the frames-per-second figure a player displays is a summary of that timing, ...

See all blogs

See it on your own content

Tell us what you are trying to solve and we will show you how it works on your infrastructure.