
TLDR
Seoul National University hid invisible pixel signals in 5,800 graduation portraits to stop deepfake generators processing the images. The move follows a 2024 Telegram scandal in which graduates' photos were weaponised to produce sexual deepfakes. The technology blocks roughly 70 per cent of commercial face-swap tools.
Invisible armour baked into every JPEG
Seoul National University's 2026 graduation album looks identical to every one before it. The portraits are crisp, the gowns are pressed, the smiles are regulation-proud. What you cannot see is that approximately 5,800 of those photos carry invisible adversarial pixel signals designed to scramble deepfake generators before they can produce a usable output.[1] The SNU Student Council signed an MOU with alumni startup StealCut, which supplied the technology at no cost.
The backstory is ugly. In mid-2024 a Telegram chatroom, quickly labelled the SNU Nth Room case, became a marketplace for non-consensual sexual deepfakes built from yearbook photos of SNU graduates.[4] The images were already public. A face-swap tool and a Telegram account were all the harm required. That case, more than any legislation, is why SNU moved.
How adversarial perturbations work
Adversarial perturbations are minute, mathematically calculated changes to individual pixel values, changes so small the human eye reads the image as normal. To a deepfake generator's neural network, those changes land like static on a radio signal: the model misreads the face geometry it needs and the synthesised output degrades or fails entirely.[2] The technique is neither encryption nor a watermark.
In real-world testing across 30 commercial deepfake platforms, StealCut recorded a 70 per cent defence rate against face-swap services, and the company has filed four global patent applications covering the perturbation method.[3] That ceiling matters: 70 per cent means three in ten attempts still get through. The technology raises friction; it does not install a lock. StealCut's documentation frames the goal as stopping deepfakes at the source, before damage occurs rather than after.[2]
StealCut ran a pilot at SNU in February 2025, integrating the perturbation step directly into the photo-processing workflow so that protection is applied at the point of image distribution rather than as an afterthought.[2] The 2026 album rollout, confirmed in September 2026, scales that pilot to the full graduating cohort.
Korea tightened the law, then the university acted
Under Article 14-2 of the Act on Special Cases concerning the Punishment of Sexual Crimes, amended on 16 October 2024, editing or distributing non-consensual sexual deepfakes carries up to seven years' imprisonment or a fine of up to fifty million won; possession or viewing alone draws up to three years' imprisonment or a fine of thirty million won.[5] The possession offence is the sharper edge, shifting legal exposure well down the distribution chain and targeting the audience as much as the producers.
Even with those penalties in place, the SNU case illustrated the gap between law and remedy. By the time investigators identify a chatroom, content has already circulated. The SNU-StealCut approach bets on making source images resistant before they are ever uploaded to a generator.
What Australian universities are looking at
Australian universities distribute high-resolution graduation portraits through essentially the same workflows SNU used before 2025: professional photography, online delivery, no pixel-level protection. There is no equivalent standard, no regulation mandating one, and no announced industry move toward adversarial perturbation at scale. StealCut's own documentation describes the SNU deployment as one of the first large-scale institutional applications of the technique at the point of image distribution.[2]
The practical barriers are manageable: universities would need to integrate perturbation into photography vendor contracts, verify that the process does not degrade print quality, and decide whether to disclose the protection to graduates or keep it silent. The SNU-StealCut MOU, signed September 2026, is the clearest proof-of-concept currently on the table.[1]
KEY TAKEAWAYS
SOURCES & CITATIONS
- StealCut LinkedIn post, SNU 2026 graduation album MOU
- StealCut official website, Protect product description
- Kbench, StealCut 70 per cent defence rate and patent filings
- UNODC, Deepfake non-consensual intimate material report, 2025
- Act on Special Cases concerning the Punishment of Sexual Crimes, Article 14-2 (amended October 2024)
FREQUENTLY ASKED QUESTIONS
What are adversarial perturbations and why do they stop deepfakes?
How effective is the StealCut protection?
What sparked Seoul National University's decision to act?
What are the penalties under Korea's amended deepfake law?

Alex Mercer writes about technology, energy and infrastructure. He likes the physical end of the story: the plants, the grids and the machines that everything else depends on.




