Pixelation is also attackable. Generate input (e.g. GAN) and apply pixelation until it converges. Probably won't be super accurate but enough to probably ID someone.
Black/delete (and flatten/rebroadcast) is the only way.
I'd worry about hallucinations when applying a GAN to a pixellated image. You'll get out a face, but who's to say that it's the correct face? Lots of people look similar.
Black/delete (and flatten/rebroadcast) is the only way.