arXiv:2602.02914cs.CV2026-02

提出新攻击方法,揭示隐私保护人脸识别中身份泄露的深层风险

FaceLinkGen: Rethinking Identity Leakage in Privacy-Preserving Face Recognition with Identity Extraction

  • 通过直接从保护模板提取身份信息,实现无需还原像素的匹配与生成
  • 在3个主流系统上匹配准确率超98.5%,生成成功率超96%
  • 适用于评估隐私保护系统的实际安全性,尤其对安全研究人员有价值

基于变换的隐私保护人脸识别(PPFR)旨在验证身份的同时隐藏面部数据,防止攻击者和恶意服务提供商窃取。现有评估多以像素级重建的抗性为标准,使用PSNR和SSIM衡量。我们发现这一重建中心视角存在缺陷。本文提出FaceLinkGen攻击方法,可直接从受保护的模板中进行身份链接/匹配和人脸生成,无需恢复原始像素。在三个近期PPFR系统上,该攻击达到超过98.5%的匹配准确率和96%以上的生成成功率,即使在近乎零知识条件下,匹配仍超92%,生成超94%。结果揭示了像素失真度量与真实隐私之间的结构性差距。视觉模糊并未真正隐藏身份信息,反而使外部入侵者和不可信服务提供者仍能广泛获取身份线索。

原文摘要 · Abstract (English)

Transformation-based privacy-preserving face recognition (PPFR) aims to verify identities while hiding facial data from attackers and malicious service providers. Existing evaluations mostly treat privacy as resistance to pixel-level reconstruction, measured by PSNR and SSIM. We show that this reconstruction-centric view fails. We present FaceLinkGen, an identity extraction attack that performs linkage/matching and face regeneration directly from protected templates without recovering original pixels. On three recent PPFR systems, FaceLinkGen reaches over 98.5\% matching accuracy and above 96\% regeneration success, and still exceeds 92\% matching and 94\% regeneration in a near zero knowledge setting. These results expose a structural gap between pixel distortion metrics, which are widely used in PPFR evaluation, and real privacy. We show that visual obfuscation leaves identity information broadly exposed to both external intruders and untrusted service providers.

隐私保护身份泄露人脸识别攻击方法

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。