arXiv:2607. 17504v1 Announce Type: cross Abstract: Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers.
By Zhihan Ren, Lijun He, Xinyao Wang, Xinzhu Fu, Fan Li
arXiv:2602.02914v4 Announce Type: replace
Abstract: Privacy-preserving face recognition (PPFR) and face anonymization have different goals, but both must retain some identity-related information for...
By Wenqi Guo, Qingyun Qian, Mohamed Shehata, Shan Du
arXiv:2510. 25687v4 Announce Type: replace-cross Abstract: Model inversion attacks pose an open challenge to privacy-sensitive applications that use machine learning (ML) models.
By Mallika Prabhakar, Louise Xu, Prateek Saxena
arXiv:2607. 29144v1 Announce Type: cross Abstract: Synthetic face datasets are increasingly used to reduce privacy exposure and data access constraints in biometric recognition.
By Pawe{\l} Borsukiewicz, Daniele Lunghi, Wendk\^uuni C. Ou\'edraogo, Jacques Klein, Tegawend\'e F. Bissyand\'e
arXiv:2409. 01062v4 Announce Type: replace Abstract: Model Inversion (MI) attacks pose a significant privacy threat by reconstructing private training data from machine learning models.
By Viet-Hung Tran, Ngoc-Bao Nguyen, Son T. Mai, Hans Vandierendonck, Ira Assent, Alex Kot, Ngai-Man Cheung
arXiv:2608.21455v1 Announce Type: new
Abstract: Face presentation attack detection (PAD) is traditionally formulated as a face-specific problem, although many of the visual artifacts introduced by pr...
By Guray Ozgur, Fadi Boutros, Naser Damer
The paper compares four audit methods for assessing identity‑level differential privacy in pre‑trained, black‑box face generators. Each method—GaussMech, KDE‑LR, MMD‑TV, and ROC‑HT—has distinct assumptions, hyperparameters, and finite‑sample limitations, and they produce markedly different epsilon estimates when applied to FaceFusion and InstantID. The study finds that all methods reveal significant identity distinguishability, but none can be reliably ranked in this high‑distinguishability regime, suggesting that future work should evaluate them on partially private mechanisms.
By Arman Zareian Jahromi, Vishnu Bondalakunta, Mohammad Akbar Bin Shah, Naimul Haque, Shuangqing Wei, George T. Amariucai
FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self-supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss to make the encoder more sensitive to perturbations, thereby avoiding the rigid feature patterns seen in earlier attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving normal model performance.
arXiv:2608. 08521v1 Announce Type: cross Abstract: Face recognition systems face two distinct, commonly-separated failure modes: spoofing, where an impostor presents a photograph or video of an authorized user, and disguise, where a legitimate user is rejected because their appearance differs from their enrolled template due to accessories, facial hair, illumination, or pose.
By Sangiya Pararajasingham
FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self‑supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss that trains the encoder to heighten sensitivity of triggered features along perturbation directions, thereby avoiding the rigid feature patterns seen in prior attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving benign utility, exposing a significant threat to real‑world facial analysis applications.
By Zhiyang Chen, Changchun Yin, Huiqin Yang, Liming Fang
arXiv:2607. 25926v1 Announce Type: cross Abstract: Face de-identification (De-ID) aims to remove or conceal personally identifiable facial features in images or videos to prevent identity recognition while preserving utility for downstream tasks.
By Hui Wei, Hao Yu, Guoying Zhao
arXiv:2609.27011v1 Announce Type: new
Abstract: Target-oriented face de-identification models aim to anonymize the identity of a target individual across different images or video frames, such that t...
By Felix Rosberg, Vitomir \v{S}truc, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez