Protego: User-Centric Pose-Invariant Privacy Protection Against Face Recognition-Induced Digital Footprint Exposure
Ziling Wang, Shuya Yang, Jialin Lu, Ka-Ho Chow
Abstract
Face recognition (FR) technologies are increasingly used to power large-scale image retrieval systems, raising serious privacy concerns. Services like Clearview AI and PimEyes allow anyone to upload a facial photo and retrieve a large amount of online content associated with that person. This not only enables identity inference but also exposes their digital footprint, such as social media activity, private photos, and news reports, often without their consent. In response to this emerging threat, we propose Protego, a user-centric privacy protection method that safeguards facial images from such retrieval-based privacy intrusions. Protego encapsulates a user's 3D facial signatures into a pose-invariant 2D representation, which is dynamically deformed into a naturallooking 3D mask tailored to the pose and expression of any facial image of the user, and applied prior to online sharing. Motivated by a critical limitation of existing methods, Protego amplifies the sensitivity of FR models so that protected images cannot be matched even among themselves. Experiments show that Protego significantly reduces retrieval accuracy across a wide range of black-box FR models and performs at least 2× better than existing methods. It also offers unprecedented visual coherence, particularly in video settings where consistency and natural appearance are essential. Overall, Protego contributes to the fight against the misuse of FR for mass surveillance and unsolicited identity tracing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 050f0702-e90f-4e6d-9f21-828abdb2d28dCited by top-tier papers1
Ask how each one uses itBuilds on7
- AdaFace: Quality Adaptive Margin for Face RecognitionMinchul Kim, Anil K. Jain, Xiaoming LiuCVPR 2022 · 509 citations
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su et al.ICCV 2021 · 109 citations
- LowKey: Leveraging Adversarial Attacks to Protect Social Media Users from Facial RecognitionValeriia Cherepanova, Micah Goldblum, Harrison Foley, Shiyuan Duan et al.ICLR 2021 · 52 citations
- SoK: Anti-Facial Recognition TechnologyEmily Wenger, Shawn Shan, Haitao Zheng, Ben Y. ZhaoS&P 2023
Related papers
- Fawkes: Protecting Privacy against Unauthorized Deep Learning ModelsShawn Shan, Emily Wenger, Jiayun Zhang, Huiying Li et al.USENIX Security 2020
- PRO-Face: A Generic Framework for Privacy-preserving Recognizable Obfuscation of Face ImagesLin Yuan, Linguo Liu, Xiao Pu, Zhao Li et al.ACM MM 2022 · 38 citations
- Privacy-preserving Adversarial Facial FeaturesZhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang et al.CVPR 2023
- Robust Secure Swap: Responsible Face Swap With Persons of Interest Redaction and Provenance TraceabilityYunshu Dai, Jianwei Fei, Fangjun Huang, Chip Hong ChangICML 2025
- Machine Pareidolia: Protecting Facial Image with Emotional EditingBinh M. Le, Simon S. WooAAAI 2026
