acceptodds
Under review as a conference paper at ICLR 2027

FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation

Abstract

Privacy-preserving face recognition (PPFR) and face anonymization are designed for different goals, but both must retain some identity-related information to remain useful. We show that this remaining information can be learned by an adaptive attacker. We propose FaceLinkGen, a simple distillation-based attack that trains a face recognition model to map protected inputs back to standard face embeddings. FaceLinkGen applies to keyless PPFR systems and perception-preserving face de-identification (De-ID) systems. For PPFR, the recovered embeddings can be used to regenerate faces that match the original person. Across MinusFace, PartialFace, and DecoyFace, the regenerated faces achieve acceptance rates of 81.0–99.0% on Face++ and 74.9–99.2% on Amazon. For De-ID, FaceLinkGen links protected faces to unprotected images of the same person, reaching Recall@1 values of 48.4–89.6% across the evaluated methods. The attack also remains effective when trained with limited paired data. Our results show that protection against a fixed recognizer or reconstruction model is not enough when identity information remains in the protected representation.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.