acceptodds
Under review as a conference paper at ICLR 2027

IDENTITY RECOVERY FROM REPEATED CAMPRO OUTPUTS UNDER SYNTHETIC ACQUISITION NOISE

Abstract

Privacy-oriented imaging aims to suppress facial recognition, but repeated releases may support identity recovery. We examine identity recovery from repeated outputs of the CamPro image signal processor (ISP), using independent synthetic pre-ISP noise and fixed, aligned face images. Comparisons include separately selected single-output attacks, reconstruction averaging, joint inversion and matched pixel-mean inversion, alongside color-channel and fixed-weight detection analyses. Eight observations improve FaceScrub closed-gallery Rank-1 by 14.6–20.3 percentage points over the selected single-output attack; NTU gains are less consistent. The FaceScrub gain persists after 8-bit lossless export, while strict open-set acceptance remains limited under the tested calibration. A 500-identity synthetic study reports mean gains of 5.9–9.2 points across recognizers over three independently trained and selected fits; averaging recovers much of this gain. Joint inversion outperforms matched pixel-mean inversion on FaceScrub. Eight of twelve constructed color pairs with identical noiseless outputs have distinguishable noisy output distributions. Added noise lowers native person AP from 0.518 to 0.505; task and identity inputs use different spatial preprocessing. These results motivate repeated-release privacy evaluation and show that deterministic ambiguity need not survive random acquisition.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.