Validating Privacy-Preserving Face Recognition Under a Minimum Assumption
Hui Zhang, Xingbo Dong, Yen-Lung Lai, Ying Zhou, Xiaoyan Zhang, Xingguo Lv, Zhe Jin, Xuejun Li
Abstract
The widespread use of cloud-based face recognition technology raises privacy concerns, as unauthorized access to face images can expose personal information or be exploited for fraudulent purposes. In response, privacypreserving face recognition (PPFR) schemes have emerged to hide visual information and thwart unauthorized access. However, the validation methods employed by these schemes often rely on unrealistic assumptions, leaving doubts about their true effectiveness in safeguarding facial privacy. In this paper, we introduce a new approach to privacy validation called Minimum Assumption Privacy Protection Validation (Map 2 V). This is the first exploration of formulating a privacy validation method utilizing deep image priors and zeroth-order gradient estimation, with the potential to serve as a general framework for PPFR evaluation. Building upon Map 2 V, we comprehensively validate the privacy-preserving capability of PPFRs through a combination of human and machine vision. The experiment results and analysis demonstrate the effectiveness and generalizability of the proposed Map 2 V, showcasing its superiority over native privacy validation methods from PPFR works of literature. Additionally, this work exposes privacy vulnerabilities in evaluated state-of-the-art PPFR schemes, laying the foundation for the subsequent effective proposal of countermeasures. The source code is available at https://github.com/Beauty9882/MAP2V . Table 1. Comparision of privacy validation methods on SOTA PPFRs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 412794d2-bdb2-4c15-962e-e0a30f5724eaCited by top-tier papers2
- FracFace: Breaking the Visual Clues - Fractal-Based Privacy-Preserving Face RecognitionWanying Dai, Beibei Li, Naipeng Dong, Guangdong Bai et al.NeurIPS 2025 · 7 citations
- LDP-Slicing: Local Differential Privacy for Images via Randomized Bit-Plane SlicingYuanming Cao, Chengqi Li, Wenbo HeCVPR 2026 · 2 citations
Builds on9
- AdaFace: Quality Adaptive Margin for Face RecognitionMinchul Kim, Anil K. Jain, Xiaoming LiuCVPR 2022 · 509 citations
- Ensemble of Averages: Improving Model Selection and Boosting Performance in Domain GeneralizationDevansh Arpit, Huan Wang, Yingbo Zhou, Caiming XiongNeurIPS 2022 · 232 citations
- Privacy-Preserving Face Recognition in the Frequency DomainYinggui Wang, Jian Liu, Man Luo, Le Yang et al.AAAI 2022 · 62 citations
- FedSDG-FS: Efficient and Secure Feature Selection for Vertical Federated LearningAnran Li, Hongyi Peng, Lan Zhang, Jiahui Huang et al.INFOCOM 2023 · 50 citations
- PRO-Face: A Generic Framework for Privacy-preserving Recognizable Obfuscation of Face ImagesLin Yuan, Linguo Liu, Xiao Pu, Zhao Li et al.ACM MM 2022 · 38 citations
Related papers
- Machine Pareidolia: Protecting Facial Image with Emotional EditingBinh M. Le, Simon S. WooAAAI 2026
- FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face RecognitionShuaifan Jin, He Wang, Zhibo Wang, Feng Xiao et al.USENIX Security 2024 · 9 citations
- Privacy-preserving Adversarial Facial FeaturesZhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang et al.CVPR 2023
- Transferable Adversarial Facial Images for Privacy ProtectionMinghui Li, Jiangxiong Wang, Hao Zhang, Ziqi Zhou et al.ACM MM 2024 · 11 citations
- Personalized and Invertible Face De-identification by Disentangled Identity Information ManipulationJingyi Cao, Bo Liu, Yunqian Wen, Rong Xie et al.ICCV 2021 · 80 citations
