A linear stochastic model is proposed that treats face-swappers as transformations on the space of identity embeddings, providing an interpretable account of the leakage mechanism, thus making formal privacy guarantees explainable -- and perfectible -- rather than purely observational.
Abstract
Face-swapping has emerged as a promising approach to facial privacy protection, replacing a target individual's appearance with that of a donor while preserving non-facial context. The resulting images visually resemble the donor, and face recognition systems tend to suppress the target's match scores -- ostensibly satisfying privacy requirements. Empirical evaluation across a range of face-swapping models, however, reveals that significant target identity leakage still occurs. This raises a deeper question: why does leakage occur, and can it be predicted? We propose a linear stochastic model that treats face-swappers as transformations on the space of identity embeddings, providing an interpretable account of the leakage mechanism. The model is fit to empirical observations and used to derive testable predictions. The aim is to ground privacy assessments in principled, interpretable analysis, thus making formal privacy guarantees explainable -- and perfectible -- rather than purely observational.
Private Face Distillation is proposed, an identity-decoupling and geometry-preserving framework that uses Orthogonal Geometry Preservation to construct decoupled proxy identities from private identity representations while maintaining hyperspherical geometry, and Relational Topology Alignment to preserve identity relations for recognition learning.
Shuhuan Chen, Xiangyu Zhu, Weisong Zhao et al.· 0 citations
A comparative study of four audits applicable to pre-trained, black-box face generators, which consistently reveal substantial identity distinguishability while reporting markedly different epsilon estimates that reflect each method's distinct assumptions and finite-sample treatment.
Arman Zareian Jahromi, Vishnu Bondalakunta, M. Shah et al.· 0 citations
This work proposes SRAP, which combines per-channel truncated SVD refinement with an identity-importance mask at every optimization step, and demonstrates that SRAP substantially improves protected-image fidelity across all reported metrics while maintaining competitive identity-disruption performance.
The experimental results show that this method balances visual consistency and structural rationality while enhancing identity concealment, providing a feasible path and technical support for the secure generation and compliant application of private images.
Zhiyong Sun, Li-Hsuan Li· Information Technology and C...· 0 citations
The widespread deployment of face recognition and visual analytics has made balancing privacy protection and image usability a critical challenge. Existing anonymization methods often rely on blurring or occlusion, which suppress identity but distort key non-identity attributes. To address this issue, this study proposes a reversible face anonymization framework based on multi-conditional collaborative control (RFAMCC), integrating multi-level feature-driven anonymization, identity-space deflection, context fusion, and a steganography–recovery mechanism. Experimental evaluations demonstrated that RFAMCC preserved semantic consistency under original, compressed, and cropped conditions. It achieved correlation scores of 0.312, 0.308, and 0.301, as well as face retrieval accuracies of 83.7%, 82.4%, and 80.9%, respectively. In privacy-sensitive evaluations, gender and age inference attacks attained low success rates of 21.4% and 23.1%, indicating strong resistance to attribute leakage. Overall, RFAMCC effectively balances anonymization strength and reversibility, providing a practical solution for privacy-preserving and legally compliant facial data sharing.
Yuzhen Zhang, Houfei Song· Information Technology and C...· 0 citations
This paper studies embedding-space privacy as a representation-level learning problem. Rather than altering raw records directly, the proposed framework applies embeddingspace transformation to full-record representations through Gaussian perturbation and adversarial representation sanitization. The method is evaluated through ablation across utility metrics, linkage attacks, attribute-inference attacks, and membership-inference tests. The primary empirical evaluation uses a synthetic fusion recommendation benchmark built from MovieLens [1], [2] 32M behavior and Adult-derived demographics [3], while a secondary synthetic medical benchmark is used to examine cross-domain transferability under more constrained conditions. The strongest results appear in the recommendation experiments. Under grouped demographic privacy evaluation, the combined condition preserves recommendation utility with $N D C G {@} K=0.6312$ while reducing exact and entity linkage from 0.7090/0.7204 to 0.0001/0.0000. Sensitive-target attacker performance remains near the majority baseline, supporting the claim of empirical privacy improvement without visible ranking degradation in that benchmark. The healthcare experiments also demonstrate meaningful embedding transformation and linkage reduction, though the current benchmark remains datalimited and therefore less conclusive for utility-focused evaluation. Overall, the findings support the conclusion that embeddingspace transformation can preserve downstream utility while substantially reducing linkage risk and sensitive-information recoverability under explicit attacker evaluation. The findings support embedding-space transformation as a practical privacypreserving strategy for embedding-driven AI systems under explicit attacker evaluation.
D. Panagoulias, Evangelia-Aikaterini Tsichrintzi, E. Sakkopoulos· International Conference on...· 0 citations