FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation
Abstract
Privacy-preserving face recognition (PPFR) and face anonymization are designed for different goals, but both must retain some identity-related information to remain useful. We show that this remaining information can be learned by an adaptive attacker. We propose FaceLinkGen, a simple distillation-based attack that trains a face recognition model to map protected inputs back to standard face embeddings. FaceLinkGen applies to keyless PPFR systems and perception-preserving face de-identification (De-ID) systems. For PPFR, the recovered embeddings can be used to regenerate faces that match the original person. Across MinusFace, PartialFace, and DecoyFace, the regenerated faces achieve acceptance rates of 81.0–99.0% on Face++ and 74.9–99.2% on Amazon. For De-ID, FaceLinkGen links protected faces to unprotected images of the same person, reaching Recall@1 values of 48.4–89.6% across the evaluated methods. The attack also remains effective when trained with limited paired data. Our results show that protection against a fixed recognizer or reconstruction model is not enough when identity information remains in the protected representation.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.