Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

FaceLinkGen: Rethinking Identity Leakage in Privacy-Preserving Face Recognition with Identity Extraction

About

Transformation-based privacy-preserving face recognition (PPFR) aims to verify identities while hiding facial data from attackers and malicious service providers. Existing evaluations mostly treat privacy as resistance to pixel-level reconstruction, measured by PSNR and SSIM. We show that this reconstruction-centric view fails. We present FaceLinkGen, an identity extraction attack that performs linkage/matching and face regeneration directly from protected templates without recovering original pixels. On three recent PPFR systems, FaceLinkGen reaches over 98.5\% matching accuracy and above 96\% regeneration success, and still exceeds 92\% matching and 94\% regeneration in a near zero knowledge setting. These results expose a structural gap between pixel distortion metrics, which are widely used in PPFR evaluation, and real privacy. We show that visual obfuscation leaves identity information broadly exposed to both external intruders and untrusted service providers.

Wenqi Guo, Shan Du• 2026

Related benchmarks

TaskDatasetResultRank
Linkage AttackCASIA-WebFace Hold-Out
Top-1 Recall88.23
16
Face VerificationAmazon Rekognition API
Pass Rate99
3
Identity Recovery SuccessTPDNE
Success@5100
3
Identity Recovery SuccessCASIA-WebFace Hold-Out
Success@599.2
3
Identity Recovery SuccessLFW
Success@598.8
3
Identity Protection EvaluationSet (test)--
3
Showing 6 of 6 rows

Other info

Follow for update