Toward Interpretable Privacy Guarantees in Face-Swapping Anonymization
A linear stochastic model is proposed that treats face-swappers as transformations on the space of identity embeddings, providing an interpretable account of the leakage mechanism, thus making formal privacy guarantees explainable -- and perfectible -- rather than purely observational.