acceptodds
Under review as a conference paper at ICLR 2027

Rethinking Identity Targets for Face De-Identification: Attribute Compatibility Matters

Abstract

Face de-identification aims to suppress identity information while preserving the utility of facial images for downstream tasks. Effective de-identification must therefore balance privacy with the preservation of non-identity information, visual fidelity, and realism. To this end, modern de-identification methods increasingly rely on generative models to transform the source image towards a desired target appearance. Here, the target appearance is typically defined by a face-recognition (FR) embedding that is sufficiently different from the source embedding in order to reduce the likelihood of re-identification. However, selecting targets mainly based on their separation from the source ignores the fact that FR embeddings also encode non-identity information, such as age, gender, ethnicity, and pose. As a result, unsuitable targets can induce unwanted attribute changes and reduce the utility and fidelity of de-identified images. In this paper, we introduce HIDE (Hyperspherical Identity Target Editing), a novel flow-matching framework for face de-identification that explicitly accounts for this problem by first constructing a target that is sufficiently separated from the source identity and then refining it to improve compatibility with source attributes. The resulting target is then used to condition HIDE's flow-matching generator that transforms the source image toward an anonymous identity while retaining its attributes. To strengthen identity conditioning, we introduce an online inverse training branch that reconstructs the source image from the generated de-identified sample, using the source as the target for both the flow-matching and the identity objective. We evaluate HIDE in comprehensive experiments against nine recent state-of-the-art face de-identification methods on three diverse face datasets, i.e., LFW, CelebA-HQ, and WFLW. Our results demonstrate that HIDE outperforms existing methods in terms of the privacy–utility trade-off, ensuring strong identity removal while preserving facial attributes and visual fidelity across challenging variations in pose, expression, age, and occlusion. Source code will be made available.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.