vix.ing · top · new · best · stats · spec

Assessing Privacy Risks from Feature Vector Reconstruction Attacks

2022/02/11 by Emily Wenger, Wenger, Emily, Francesca Falzon +7 · 1 citation
Computer Science · #Adversarial Robustness in Machine Learning #Biometric Identification and Security #Computer Vision and Pattern Recognition (cs.CV) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Face recognition and analysis

paper · pdf · doi:10.48550/arxiv.2202.05760

openalex publication_date 2022/02/11 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

In deep neural networks for facial recognition, feature vectors are numerical representations that capture the unique features of a given face. While it is known that a version of the original face can be recovered via "feature reconstruction," we lack an understanding of the end-to-end privacy risks produced by these attacks. In this work, we address this shortcoming by developing metrics that meaningfully capture the threat of reconstructed face images. Using end-to-end experiments and user studies, we show that reconstructed face images enable re-identification by both commercial facial recognition systems and humans, at a rate that is at worst, a factor of four times higher than randomized baselines. Our results confirm that feature vectors should be recognized as Personal Identifiable Information (PII) in order to protect user privacy.

Cited by

Related