arXiv ScienceSearch

arXiv · 2602.02914

FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation

Abstract

Privacy-preserving face recognition (PPFR) hides facial appearance while retaining machine recognition, whereas perception-preserving face de-identification (De-ID) retains human recognizability while blocking face recognition models. We show that both designs preserve identity signals that an adaptive attacker can extract. We introduce FaceLinkGen, a unified distillation attack that learns from paired protected and original images. Across MinusFace, PartialFace, and DecoyFace, FaceLinkGen regenerates faces accepted by Face++ at rates of 81.0--99.0\% and by Amazon at rates of 74.9--99.2\%. Against four De-ID methods, it raises mixed-gallery Recall@1 to 55.2--89.6\% and remains effective with limited paired data. These results establish adaptive evaluation as essential for measuring facial privacy and show that resistance to fixed recognition or reconstruction models does not prevent identity leakage.

Explore related subjects

Keep this discovery

BibTeXRIS

Wenqi Guo, Mohamed Shehata, Shan Du. 2026-09-03. FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation. https://arxiv.org/abs/2602.02914

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

Stochastic Optimization of Tree Tensor Networks

Tensor networks, originally developed for quantum many-body physics, are promising models for machine learning. We derive stochastic Riemannian optimizers for tree tensor networks (TTNs) on both their parameter and quotient manifolds, including adaptive and learning-rate-free schemes suitable for minibatch training. Using a hybrid CNN-TTN architecture, we evaluate the methods on Fashion-MNIST, CIFAR10, and Imagenette. The proposed optimizers achieve predictive performance comparable to unconstrained optimization while enabling numerically stable downstream compression.

math.OC

Can We Change the Stroke Size for Easier Diffusion?

Diffusion models can be challenged in the low signal-to-noise regime, where they have to make pixel-level predictions despite the presence of high noise. The geometric intuition is akin to using the finest stroke for oil painting throughout, which may be ineffective. We therefore study \emph{stroke-size control} as a controlled intervention that changes the roughness of the supervised target, predictions and perturbations across timesteps, in an attempt to ease the low signal-to-noise challenge via the prediction target simplification.

cs.CV

Texture Image Classification Using DWT AlexNet Feature Fusion and Deep Neural Networks

Texture image classification plays a significant role in computer vision applications, including industrial inspection, medical image analysis, remote sensing, and object recognition. Handcrafted features can capture local texture characteristics but may have limited capability to represent complex visual patterns. In contrast, deep learning models automatically learn discriminative representations but may not fully exploit the multiscale spatial-frequency information inherent in texture images. This paper proposes a hybrid feature fusion framework, termed DWT_AlexNet_DNN, which combines Discrete Wavelet Transform (DWT) features with deep features extracted using AlexNet for texture image classification.

cs.CV