← Blog
· 8 min read

Why Face Recognition Sees Through Most Disguises Now

If you count on a cap, sunglasses or a mask to keep your face out of the system, this is what the test results say about that plan. Most of it stopped working between 2020 and 2022. Here is what changed, what still holds up, and what to do instead.

Remove my face from search engines →

The short version

  • A mask alone no longer beats good software. The best algorithms NIST tested in late 2020 got masked faces wrong 2.4% to 5% of the time, about where unmasked recognition stood in 2017 (NIST, December 2020).
  • Everyday disguises are a solved research problem. On the Disguised Faces in the Wild benchmark, the top systems verified identities correctly more than 87% of the time at a 1% false-accept rate, with hats, glasses, beards and scarves in the mix (Singh et al., 2018).
  • Only engineered disguises still work, and they take a computer, a makeup artist and a specific target system.
A baseball cap, dark sunglasses and a folded black face mask laid out on a wooden table under a desk lamp, photographed from above.
The classic kit. Against 2026 software it changes the odds, not the outcome.

Masks: from 50% failure to 5% in six months

The clearest before-and-after we have comes from the US National Institute of Standards and Technology, which runs the standard test that face recognition vendors submit to.

  • July 2020, pre-pandemic algorithms. The best failed to match a masked face about 5% of the time, up from 0.3% unmasked. Many otherwise competent algorithms failed 20% to 50% of the time (NISTIR 8311).
  • November 2020, algorithms trained with masks in mind. Sixty-five new submissions. The best now erred 2.4% to 5% of the time on masked faces, and some vendors cut their error rate by a factor of ten (NISTIR 8331).
  • Live cameras, real masks. In the DHS 2020 Biometric Technology Rally, 60 systems and 582 volunteers, the median system identified 77% of masked people and the best identified 96% (DHS S&T).

Details still matter. NIST found round masks caused fewer errors than wide ones, and black or red masks caused more errors than pale ones. A mask pulled high over the nose hurt accuracy most. None of that returns you to the 50% failure rates of early 2020.

Hats, sunglasses, beards and scarves

Researchers built a benchmark for exactly this in 2018: Disguised Faces in the Wild, 11,000-plus photos of 1,000 people wearing hats, glasses, beards, wigs and scarves, plus photos of lookalikes trying to pass as them. The point was to test recognition under the disguises people actually wear.

  • The baseline was weak. A standard 2015-era model struggled badly on the disguised pairs.
  • Purpose-built models closed the gap fast. The competition entries reached over 87% verification accuracy at a 1% false-accept rate, a 53.8% improvement on that baseline (Singh et al.).
  • The eye region does the work. Masked-face research since then has focused on the strip between the brows and the cheekbones. Fine-tuning ordinary face models on masked images beat models built only on that eye region (Boutros et al., 2021), which is why a mask plus sunglasses is harder to defeat than either alone, and why a cap does very little.
A person seen from behind in a hooded jacket and baseball cap waiting at a city crossing at dusk, with blurred traffic lights ahead.
From behind, nothing to match. The moment they turn, the eye region is enough.

The one trick that still works, and why you will not use it

In 2021 a team at Ben-Gurion University showed that makeup can beat recognition, with a catch. They used software to work out which patches of each face the model relied on most, then had a makeup artist shade those patches with ordinary, natural-looking products.

  • It worked on live cameras. Walking a corridor with two CCTV cameras, 20 volunteers were recognised 47.6% of the time with no makeup, 33.7% with random makeup, and 1.2% with the computed pattern (BGU Cyber Security Research Center).
  • It is tuned to the target. The pattern was computed against specific models. A different engine sees different features.
  • It has to be reapplied, by hand, every time. And the researchers themselves note it makes you stand out to human eyes.

That is the state of the art for hiding from a camera in person: a bespoke pattern, per system, per day. It says nothing about the photos of you already online, which is where most people are actually exposed.

Why the software got better

  • It trained on occluded faces. The 2020 mask studies show the mechanism plainly: once vendors added masked images to training, error rates dropped within months. The same has happened for glasses, hats and beards.
  • It stopped needing the whole face. Modern models produce a match from partial views. The eyes, brows and nose bridge carry most of the signal.
  • It compares against many photos, not one. A search engine such as PimEyes holds several images of the same person from different years. A partial match against any of them is enough to surface the rest.

Common doubts

“I always wear sunglasses in photos anyway.”

Sunglasses remove some signal and raise error rates, and NIST still tests for it. Against a gallery of your unobstructed photos, a partial match is often enough. Run the free self-check with one sunglasses photo and see what comes back.

“Cameras in shops and stadiums are the real danger.”

They are worth knowing about, and most offer an opt-out at the gate. What they capture is usually deleted within days. A face-search index keeps your photos until someone removes them, and anyone with a card can query it.

“Can you guarantee my photos disappear?”

No. We file the removal requests with each engine, track every reply in your dashboard, and re-file monthly. Each engine decides how it responds, and we say so plainly.

“What does it cost?”

US$9.99 a month, or US$7.99 a month billed annually. Cancel from your dashboard whenever you like. Web payments made through Stripe carry a 30-day money-back guarantee.

Take the photos out of the index instead.

Upload two photos. We file removal requests with the major face-search engines and re-file them every month.

Remove my face from search engines →