arXiv:2607. 28936v1 Announce Type: cross Abstract: Facial biometric identification relies on the distinctiveness of user attributes within a high-dimensional embedding space.
By Omid Ahmadieh, Nima Karimian
arXiv:2602.02914v4 Announce Type: replace
Abstract: Privacy-preserving face recognition (PPFR) and face anonymization have different goals, but both must retain some identity-related information for...
By Wenqi Guo, Qingyun Qian, Mohamed Shehata, Shan Du
arXiv:2606. 11615v1 Announce Type: cross Abstract: The widespread adoption of face recognition (FR) technologies raises serious privacy concerns, as facial data can be exploited without consent.
By Omid Ahmadieh, Nima Karimian
arXiv:2609.27011v1 Announce Type: new
Abstract: Target-oriented face de-identification models aim to anonymize the identity of a target individual across different images or video frames, such that t...
By Felix Rosberg, Vitomir \v{S}truc, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez
arXiv:2607. 12354v1 Announce Type: new Abstract: In this paper, we challenge the prevailing view that information dependency (including rote memorization) drives training data exposure to image reconstruction attacks.
By Rasmus Torp, Shailen K. Smith, Adam Breuer
The impressive visual quality and ubiquity of AI-generated images call for reliable and robust detection methods. Reconstruction-based detectors have emerged as a promising direction for transparent and training-free identification of synthetic images.
arXiv:2608. 03395v1 Announce Type: cross Abstract: Deepfake technologies pose increasing threats to facial privacy and identity security, motivating proactive defenses that protect facial images before misuse.
By Sungwon Cho, Kwanghyun Ko, Myungjoo Kang
arXiv:2607. 29144v1 Announce Type: cross Abstract: Synthetic face datasets are increasingly used to reduce privacy exposure and data access constraints in biometric recognition.
By Pawe{\l} Borsukiewicz, Daniele Lunghi, Wendk\^uuni C. Ou\'edraogo, Jacques Klein, Tegawend\'e F. Bissyand\'e
The paper introduces a "carrier"—a secondary visual element—to help preserve the main subject of an image during strong, unrestricted adversarial attacks. By allocating a larger portion of globally normalized attack updates to the carrier, the method reduces distortion of the subject while maintaining attack strength. Additionally, the carrier enhances cross-model transferability and allows targeted attacks to mislead classifiers while keeping the subject recognizable to humans.
By Linfeng Jiang, Steven McDonagh, Yuhang Chen, Xingyu Zhao, Siddartha Khastgir, Andi Zhang
Model-specific adversarial attacks have been extensively studied. We study a different failure mode: naturally occurring statistical signals in vision data that can behave like backdoor-like triggers without being maliciously inserted.
arXiv:2607. 05516v2 Announce Type: replace-cross Abstract: Model-specific adversarial attacks have been extensively studied.
By Paul K. Mandal, Pavan Reddy, Tristan Malatynski
arXiv:2506.12454v2 Announce Type: replace-cross
Abstract: What fundamentally distinguishes an adversarial attack from a misclassification due to limited model expressivity or finite data? In this wor...
By Matteo Vilucchio, Lenka Zdeborov\'a, Bruno Loureiro