Technical privacy · R&D leadership · product
I build deep-tech systems for complex privacy problems.
I work where there is no ready-made recipe: the problem has to be opened up in technical depth, a new solution researched, and then built into a product that works and makes business sense.
- 20+ yearson the technical side of privacy, since 2005
- 500+citations to my publications
- R&D → productfrom the research question to the paying customer
Research, industrial R&D and product leadership: Vitarex · SEON · Inria · BME
My role
I approach technical privacy problems as whole systems: from the research question, through architecture and implementation, to how the product works in reality.
As an expert, I go to the technical core of the problem — data flows, identifiability, attack surfaces, algorithmic limits, and how these relate to the system as a whole. As an R&D lead, I do not stop at analysis: I turn open research questions into validated technical directions, architectures that can be built by a team, and working systems.
I am strongest when the problem is complex, standard solutions are not enough, and technical, privacy and business decisions must be understood together.
What I know
-
De-anonymisation, identification, biometrics
My PhD topic was the de-anonymisation of social networks and defences against it, and this has remained the backbone of my field. I have worked on k-anonymity anonymisation for tabular and relational data, on a risk assessment methodology for transactional data for the Hungarian National Bank, and published on how face recognition fingerprints can be traced back to the person they were taken from. The recurring question is always the same: is the anonymisation strong enough, and if it is broken, how many data subjects are affected.
-
Online tracking and device fingerprinting
In 2011, my colleagues and I were the first in the world to propose the concept of device identification through the browser, but independent of the browser itself; the public test we built on this had over 500,000 runs and about 50 media appearances. At Inria, we measured how browser extensions and web logins make users unique — we presented the results in the European Parliament. At SEON, I led the device fingerprint research and development team for five years, focusing on fraud prevention.
-
AI, computer vision and analytics, data science
I have worked with machine learning since 2015. I researched how ML methods can be used for de-anonymisation risk assessment, and examined the privacy implications of generative models — such as deepfakes. At VeriDome, we are building a complex video analysis system that can also perform pseudonymised face recognition. In the IML4E project, the focus was on MLOps, and here we developed a posture analysis machine for health visitors.
My cocktail
I do not optimise a single subproblem — these four things together give my work its value.
-
01
Technical depth
Analysis of algorithms, data flows, identifiability and attack surfaces down to the real technical core of the problem.
-
02
System-level overview
Placing the subproblem in the context of the full architecture, operational environment and privacy risk model.
-
03
R&D leadership
From open research questions to a validated direction, coordinated teamwork and a buildable system.
-
04
Product and business connection
Connecting technical possibilities with usability, deployability, market needs and risks.
Highlighted works
What they have in common: each required a new solution at the intersection of identifiability, privacy and working technology.
-
2023–
VeriDome — GDPR-compatible video analysis
Pseudonymised face recognition procedure and the video analysis system built on it, operating in real environments with paying clients. At Vitarex, this is my project: research, product development, sales. Projects
-
2017–2022
Device fingerprinting at SEON
For five years I led the device fingerprint research and development team: here, for example, we built solutions to detect the 'incognito' technologies used by fraudsters, which are still used by companies in Hungary and abroad. Professional work
-
2017
Browser Extension and Login-Leak Experiment
A large-scale experiment at Inria on how browser extensions and web logins make users unique. We presented preliminary results in the European Parliament. Projects
Selected publications
Research underpins the system-building. All my publications with their PDFs are in one place.
-
2021
A Comparative Study on the Privacy Risks of Face Recognition Libraries
I. Fábián, G. Gy. Gulyás · Acta Cybernetica 25(2), 233–255.
-
2020
De-anonymizing Facial Recognition Embeddings
I. Fábián, G. Gy. Gulyás · Infocommunications Journal 12(2), 50–56.
-
2018
To Extend or not to Extend: On the Uniqueness of Browser Extensions and Web Logins
G. Gy. Gulyás, D. F. Somé, N. Bielova, C. Castelluccia · WPES'18
-
2016
Near-Optimal Fingerprinting with Constraints
G. Gy. Gulyás, G. Ács, C. Castelluccia · Proceedings on Privacy Enhancing Technologies, 2016/4
Contact
A technically hard problem is a good starting point. For professional enquiries about privacy technologies, identification, deep-tech R&D, or designing a new system: