Subscribe
Technology

Seoul university hides anti-deepfake pixels in 5,800 graduation photos

The invisible technology blocks roughly 70 per cent of commercial face-swap tools, arriving two years after a Telegram chatroom weaponised alumni portraits to produce non-consensual sexual material.

6 min read
A Seoul National University graduate throws her mortarboard into the air, backlit by the sun
Seoul National University graduates. The university embedded anti-deepfake signals in 5,800 yearbook portraits. Digitally illustrated image.
Alex Mercer
By Alex Mercer · 2026-09-24

TLDR

Seoul National University hid invisible pixel signals in 5,800 graduation portraits to stop deepfake generators processing the images. The move follows a 2024 Telegram scandal in which graduates' photos were weaponised to produce sexual deepfakes. The technology blocks roughly 70 per cent of commercial face-swap tools.

Invisible armour baked into every JPEG

Seoul National University's 2026 graduation album looks identical to every one before it. The portraits are crisp, the gowns are pressed, the smiles are regulation-proud. What you cannot see is that approximately 5,800 of those photos carry invisible adversarial pixel signals designed to scramble deepfake generators before they can produce a usable output.[1] The SNU Student Council signed an MOU with alumni startup StealCut, which supplied the technology at no cost.

The backstory is ugly. In mid-2024 a Telegram chatroom, quickly labelled the SNU Nth Room case, became a marketplace for non-consensual sexual deepfakes built from yearbook photos of SNU graduates.[4] The images were already public. A face-swap tool and a Telegram account were all the harm required. That case, more than any legislation, is why SNU moved.

How adversarial perturbations work

Adversarial perturbations are minute, mathematically calculated changes to individual pixel values, changes so small the human eye reads the image as normal. To a deepfake generator's neural network, those changes land like static on a radio signal: the model misreads the face geometry it needs and the synthesised output degrades or fails entirely.[2] The technique is neither encryption nor a watermark.

In real-world testing across 30 commercial deepfake platforms, StealCut recorded a 70 per cent defence rate against face-swap services, and the company has filed four global patent applications covering the perturbation method.[3] That ceiling matters: 70 per cent means three in ten attempts still get through. The technology raises friction; it does not install a lock. StealCut's documentation frames the goal as stopping deepfakes at the source, before damage occurs rather than after.[2]

StealCut ran a pilot at SNU in February 2025, integrating the perturbation step directly into the photo-processing workflow so that protection is applied at the point of image distribution rather than as an afterthought.[2] The 2026 album rollout, confirmed in September 2026, scales that pilot to the full graduating cohort.

Korea tightened the law, then the university acted

Under Article 14-2 of the Act on Special Cases concerning the Punishment of Sexual Crimes, amended on 16 October 2024, editing or distributing non-consensual sexual deepfakes carries up to seven years' imprisonment or a fine of up to fifty million won; possession or viewing alone draws up to three years' imprisonment or a fine of thirty million won.[5] The possession offence is the sharper edge, shifting legal exposure well down the distribution chain and targeting the audience as much as the producers.

Even with those penalties in place, the SNU case illustrated the gap between law and remedy. By the time investigators identify a chatroom, content has already circulated. The SNU-StealCut approach bets on making source images resistant before they are ever uploaded to a generator.

What Australian universities are looking at

Australian universities distribute high-resolution graduation portraits through essentially the same workflows SNU used before 2025: professional photography, online delivery, no pixel-level protection. There is no equivalent standard, no regulation mandating one, and no announced industry move toward adversarial perturbation at scale. StealCut's own documentation describes the SNU deployment as one of the first large-scale institutional applications of the technique at the point of image distribution.[2]

The practical barriers are manageable: universities would need to integrate perturbation into photography vendor contracts, verify that the process does not degrade print quality, and decide whether to disclose the protection to graduates or keep it silent. The SNU-StealCut MOU, signed September 2026, is the clearest proof-of-concept currently on the table.[1]

KEY TAKEAWAYS

01Seoul National University protected 5,800 graduation portraits with invisible adversarial pixels under a free deal with startup StealCut.
02Real-world tests against 30 commercial platforms found the technology blocked roughly 70 per cent of face-swap deepfake attempts.
03The 2024 SNU Nth Room case saw graduates' yearbook photos used to produce and trade sexual deepfakes on Telegram.
04Korea's amended law now punishes deepfake creation with up to seven years' imprisonment and mere possession with up to three years.
05Australian universities distribute comparable high-resolution portraits but have no equivalent pixel-protection standard in place.

FREQUENTLY ASKED QUESTIONS

What are adversarial perturbations and why do they stop deepfakes?
Adversarial perturbations are tiny, human-imperceptible changes to pixel values in an image. They are calculated to confuse the pattern-recognition layers inside deepfake neural networks, causing the generator to misread facial geometry and produce degraded or failed output. To the naked eye the photo looks normal.
How effective is the StealCut protection?
In testing against 30 commercial deepfake platforms, StealCut recorded a 70 per cent defence rate against face-swap tools. That means roughly three in ten attempts still succeed, so the technology raises the barrier without eliminating the risk entirely.
What sparked Seoul National University's decision to act?
A 2024 Telegram chatroom case, known as the SNU Nth Room case, saw graduates' yearbook photos used to create and trade non-consensual sexual deepfakes. The scandal prompted both legislative reform in Korea and the university's eventual adoption of pixel-level photo protection.
What are the penalties under Korea's amended deepfake law?
Under the Act on Special Cases concerning the Punishment of Sexual Crimes, amended in October 2024, creating or distributing non-consensual sexual deepfakes carries up to seven years' imprisonment or a fine of up to fifty million won. Possession or viewing alone is punishable by up to three years' imprisonment.
Alex Mercer

Alex Mercer

Alex Mercer writes about technology, energy and infrastructure. He likes the physical end of the story: the plants, the grids and the machines that everything else depends on.

Related topics
What's your reaction?

Make us a preferred source on Google

Tap once and our reporting shows at the top of your Google search results and AI answers. You can change this at any time.

Add as a preferred source on Google
Subscribe — it's free