Pith. sign in

REVIEW 3 major objections 4 minor 113 references

IDFace: Face Template Protection for Efficient and Secure Identification

T0 review · 3 major / 4 minor · reviewed 2026-08-06 · deepseek-v4-flash

Pith's one-line read IDFace claims encrypted face identification over 1M templates in 126ms, only 2x slower than plaintext search, using a sign-locked ternary transform and slot-packing to make inner products addition-only.

desk verdict A practical HE-based face identification system with real measured speedups, but the advertised isometry theorem does not prove a usable finite-dimension guarantee, so the theoretical framing overreaches while the empirical core largely stands. read the letter →

arxiv 2507.12050 v1 pith:K32X2WRN submitted 2025-07-16 cs.CR cs.CV

classification cs.CRcs.CV MSC 68P2594A60
keywords facetemplateprotectionhomomorphicencryptionbiometricidentificationternaryquantizationalmostisometrycosinesimilaritySIMDpacking
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

IDFace claims to make homomorphically encrypted face identification practical at million-person scale. The paper's central assertions are that mapping each unit-length template into a sparse ternary vector — retaining only the top ~341 of 512 coordinates by magnitude, as ±1, and zeroing the rest — preserves cosine similarity well enough to hold accuracy loss to about 1% on standard benchmarks, and that packing several such transformed templates into one ciphertext slot, so their inner products decode cleanly, brings identification over 1M encrypted templates down to 126 ms, roughly 2x the cost of the unprotected matrix-vector search. The claim matters because prior HE-based template protection ran hundreds of times slower than plaintext, which made real-time secure identification at airports or building entrances impractical.

What carries the argument

The load-bearing device is the almost-isometric ternary transform Tα: given a unit vector, it selects the α coordinates with the largest absolute values and replaces them by +1 or −1 according to sign, zeroing everything else; after normalization the output lies in Z^d_α, the set of ternary vectors with exactly α nonzeros. Templates with α nonzero ±1 entries have inner products that are just counts of matching signs minus mismatching signs, so the encrypted matching test becomes additions and look-ups, with no homomorphic multiplications at all. The paper formalizes the needed property as an (ε, δ, θ)-isometry and proves the d=512, α=341 parameter statement in the supplement, using a classical order-statistics asymptotic to control which coordinates survive the threshold. The second device, Encode/Decode, writes m transformed templates as digits of a base-p number inside each AHE slot so that m inner products arrive in a single decrypted word and are recovered by modular decoding.

What would settle it

Evaluate the expectation in Assumption 1 directly at d=512 over a dense grid of θ, using exact quadrature or a very large Monte Carlo sample; if the bias exceeds 0.01 for any θ, Lemma 2 in the proof loses its guarantee and the (0.111, o(1), θ)-isometry statement is unsupported. A complementary empirical check is to sample real face embeddings from a public template set, compute max |⟨Tα(x),Tα(y)⟩ − ⟨x,y⟩| for pairs at the operating threshold, and see whether the 99th percentile stays well below 0.111.

Watch

Extended reading notes

Core claim

The central discovery is that an encrypted inner product can be reduced to additions when templates are first passed through Tα, the map that keeps the α largest-magnitude coordinates as their signs and zeros the rest. The paper proves (Proposition 1 in the main text, with the full statement and proof in the supplement) that for d=512 and α=341 this map is an (0.111, o(1), θ)-isometry for every angle θ, meaning that for uniformly random unit vectors at angle θ the inner product of the transformed vectors differs from cosθ by less than 0.111 except with probability tending to zero as the dimension grows. An Encode/Decode layer then packs m transformed templates into a single message slot using base-p representation, so one homomorphic addition yields m inner products at once. The reported result is 126 ms identification over 1M enrolled templates with CKKS (7.08 s with Paillier at the same speed setting), with storage of 1.5–6.6 GB depending on parameters and accuracy loss held below 1% on LFW, CFP-FP, AgeDB and IJB-C.

Load-bearing premise

The formal distance-preservation guarantee rests on an unproved statistical assumption, stated as Assumption 1 in the supplement: for independent d-dimensional Gaussian vectors X and Y and W = (X + tanθ·Y)/√(1+tan²θ), the expected cosine between X and W equals cosθ up to a term that vanishes as d grows, which the authors verify only by numerical sampling.

Editorial extensions

If this is right

  • If the claims are correct, template-protected identification at 1M scale becomes real time, with a 126–753 ms range covering the β = 63, 127, 341 trade-off between speed and accuracy.
  • Because the matching test is addition-only, any additive homomorphic encryption works; the CKKS instantiation is not special, only faster due to slot packing.
  • Accuracy degradation stays under about 1% across LFW, CFP-FP, AgeDB and IJB-C for several recent face recognition backbones, so the protection can be plugged in without retraining the recognizer.
  • The claimed 2x overhead is measured against a plaintext matrix–vector product; storage for 1M identities remains modest, from 1.5 GB (Paillier) to 6.6 GB (CKKS).
  • The appendix's speaker and fingerprint results indicate the same transform-and-pack recipe extends to any biometric scored by cosine similarity.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The isometry theorem is proven for uniformly random unit vectors, but real face embeddings are strongly non-uniform, so the formal 0.111 bound probably overstates the distortion seen in practice; one could measure the empirical isometry error directly on real template pairs at the operating threshold rather than on random vectors.
  • Since the speed-up eliminates homomorphic multiplications, the same ternary transform could accelerate other encrypted inner-product workloads, such as private nearest-neighbor search or encrypted recommender scoring, whenever a couple of percent accuracy loss is acceptable.
  • The 126 ms figure covers only the encrypted search computation; an end-to-end deployment also pays for key-server decryption and two-server communication, so the complete identification latency will be higher in practice.
  • Choosing α to maximize the number of codewords is a worst-case heuristic; searching over α values fitted to actual template statistics might reduce the inner-product error further than the reported α=341.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper proposes IDFace, a homomorphic-encryption-based face template protection scheme for large-scale identification. It introduces two techniques: (1) an almost-isometric transformation Tα that maps a 512-dimensional unit face template to a ternary vector with α nonzero ±1 entries, allowing inner products to be computed by additions only; (2) a space-efficient encoding that packs multiple transformed templates into a single plaintext slot, reducing the number of ciphertexts. The authors instantiate IDFace with Paillier and CKKS, report identification times of 126–753 ms for 1M identities with 2×–12× overhead over plaintext identification, and report less than 1% accuracy degradation on LFW, CFP-FP, AgeDB, and IJB-C benchmarks across several face recognition models. They also provide a theoretical analysis (Proposition 1/2, Appendix B) claiming that Tα is an almost isometry, and they include extensions to speaker and fingerprint verification.

Significance. If the efficiency and accuracy results hold, IDFace is a substantial advance over prior HE-based biometric identification: Table 2 shows 16–98× faster identification than HERS and 23.5× faster than MFBR-ID at comparable or better accuracy, with only ~2× overhead over plaintext identification. The accuracy study is unusually broad (six face recognition models, four benchmark datasets, plus speaker and fingerprint evaluations), and the packing/encoding technique is simple and clearly described. However, the theoretical guarantee is weaker than advertised: Proposition 1 relies on an unproved assumption and an asymptotic δ bound that is vacuous at d=512, and the authors themselves concede in Appendices D.3 and D.6 that the uniform-sphere analysis does not match real face distributions and that the 0.111 bound is too coarse to explain observed accuracy. The practical claims rest on experiments rather than on the isometry theorem, so the formal contribution needs substantial revision.

major comments (3)
  1. [Appendix B.2, Lemma 2 / Assumption 1] The proof of Lemma 2, and hence of Proposition 1, is conditional on Assumption 1, which is not proved in the manuscript; the only support is the numerical check in Figure 4. Since Proposition 1 is presented in Section 4.1 as the formal basis for the distance-preservation claim, the proof is incomplete. The authors should either supply an analytic proof of Assumption 1 (for example, a concentration or delta-method argument for the normalized inner product of X and W) or re-label Proposition 1 as conditional/experimental.
  2. [Appendix B.2, proof of Lemma 1] Setting ξ1 = ξ2 = d^{-1/3} in Lemma 1 gives δ = d^{-1}(3ξ1^{-2} + 64ξ2^{-2}) = 67 d^{-1/3}, which exceeds 1 for d = 512 (67/8 ≈ 8.4). Thus the derived probability bound is vacuous at the operating dimension, and the statement "For d = 512 and α = 341, Tα is (0.111, o(1), θ)-isometry" is not a finite-dimensional theorem. The main text should distinguish the asymptotic isometry statement from any usable d=512 guarantee, or provide a non-vacuous finite-d bound.
  3. [Appendix D.3 and D.6] The paper itself concedes that the face feature distribution is "quite far from uniform" and that the theoretical analysis "may or may not fit with reality" (D.3), and that the 0.111 worst-case bound is "too high to explain the small accuracy drop" (D.6). These concessions directly qualify the central theoretical claim and should be stated in Section 4.1 when Proposition 1 is invoked; as written, the main text presents the isometry result without these caveats, and the accuracy guarantee is de facto empirical.
minor comments (4)
  1. [Section 4.1, Proposition 1] The proposition is stated for fixed d=512 with an o(1) term; since o(1) is asymptotic in d, the statement should clarify whether the isometry is claimed for the fixed dimension or for a sequence d→∞ with α=⌊2d/3⌋.
  2. [Section 5.2, Table 3] The sentence "less than 1% performance loss ... even for the setting β=63" should specify the column (341,63); for the (63,63) column, CFP-FP and AgeDB show drops of 1.04 and 1.52 percentage points, respectively.
  3. [Appendix B.2, Lemma 5] The notation is inconsistent: the lemma statement defines X(α) as the α-th order statistic, but the proof uses X(d−α) without redefining it; please align notation so that Pr[E1]=α/d is unambiguous.
  4. [Section 5.3] The security analysis is informal; no formal BTP security games are defined for irreversibility, revocability, and unlinkability. Since the paper invokes ISO/IEC 24745, a precise mapping of the construction to those requirements would strengthen the claims.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity found: α is selected by a combinatorial codebook-size criterion, runtime claims are direct measurements, and the isometry proof, though conditional on an unproved concentration assumption, does not assume its own conclusion.

full rationale

The derivation chain is essentially self-contained. The transformation Tα is defined directly as top-α sign selection, and the isometry analysis in Appendix B computes ϵα,θ from order-statistics integrals rather than from fitted accuracy data. The parameter α=341 is chosen by the independent combinatorial criterion stated in Appendix C.1: since |Z^d_α| = C(d,α)·2^α, 'one can easily derive that |Z^d_α| gets the maximum value when α=⌊2d/3⌋.' This criterion does not use the accuracy benchmarks in Table 3. Efficiency claims are measured operations and runtimes (Table 2), so they are not fitted predictions. The only self-referential element is the remark that Tα is technically the same as the IronMask decoder [58], which shares authors with this paper; however, the paper explicitly states that the almost-isometry property 'has neither been used nor even identified in their work' and supplies its own proof. That self-citation is therefore not load-bearing. The proof of Proposition 1 does rely on Assumption 1, E[⟨X,W⟩/(||X||2·||W||2)] = cosθ + o(1), which is only numerically verified in Figure 4. This is a rigor gap, not circularity: the assumption concerns concentration of the untransformed angle between X and W, while the target statement is about the transformed inner product ⟨Tα(X),Tα(W)⟩. Similarly, the paper's own concessions in D.3 and D.6 that the uniform-sphere model may not match real face distributions and that the 0.111 bound is too coarse to explain observed accuracy weaken the formal guarantee but do not make the conclusion an input. The δ=o(1) bound is asymptotic and vacuous at the operating dimension (67·d^{-1/3} ≈ 8.4 at d=512), again a strength-of-guarantee issue rather than circularity. Overall, no prediction or first-principles result reduces by construction to its own input.

Assumptions & free parameters 4 free parameters · 4 assumptions · 0 invented entities

The central efficiency claim depends on the selected parameters alpha, beta, p, and m; the theoretical isometry bound rests on an unproved probabilistic assumption and the uniform-sphere model. Security relies on the two-server non-collusion assumption. No new physical entities are introduced.

free parameters (4)
  • alpha (enrollment transformation threshold) = 341
    Chosen as floor(2*512/3) to maximize the number of possible ternary vectors |Z^d_alpha|, a design heuristic. It trades accuracy versus efficiency and is not fitted to benchmark accuracy.
  • beta (query transformation threshold) = 63, 127, 341
    Selected as an accuracy-efficiency trade-off. Smaller beta gives fewer homomorphic additions and more packed templates per slot, at the cost of accuracy (Section 5.1).
  • p (encoding base) = beta+1 (e.g., 64, 128, 342)
    Base for packing multiple templates per slot; must exceed the maximum inner product value min(alpha, beta). Derived from beta but controls capacity m.
  • m (templates per slot) = 8, 7, 5 for CKKS (beta=63,127,341); up to 342 for PC
    Determined by p and the plaintext bit precision (50 bits for CKKS, 2048 bits for PC). It directly sets the number of identities processed per batch.
assumptions (4)
  • domain assumption Assumption 1: E[<X,W>/(||X||2*||W||2)] = cos(theta) + o(1)
    Unproved, only numerically verified in Figure 4. Used to prove Lemma 2, which is essential for the isometry bound in Proposition 1 (Appendix B.2).
  • domain assumption Face templates are approximately uniform on S^(d-1)
    The isometry guarantee is proven for uniform sphere sampling, but real face features are non-uniform; the authors acknowledge this gap in Appendix D.6 and rely on empirical benchmarks instead.
  • domain assumption Two servers Slocal and Skey do not collude
    Security relies on the secret key residing only at Skey; if Slocal and Skey collude, encrypted templates can be decrypted (Sections 3.2, 5.3).
  • standard math Asymptotic normality of order statistics (Mosteller [84])
    Used in Lemmas 4-6 to approximate threshold probabilities. The symmetry argument in Lemma 5 relies on asymptotic normality and is heuristic for finite d.

how reviews work

0 comments
Cite this review

Pith. "Pith review of IDFace: Face Template Protection for Efficient and Secure Identification." pith.science (2026). https://pith.science/paper/K32X2WRN

@misc{pith2026250712050,
  author       = {Pith},
  title        = {Pith review of: IDFace: Face Template Protection for Efficient and Secure Identification},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/K32X2WRN}},
  note         = {Machine review of arXiv:2507.12050}
}
read the original abstract

As face recognition systems (FRS) become more widely used, user privacy becomes more important. A key privacy issue in FRS is protecting the user's face template, as the characteristics of the user's face image can be recovered from the template. Although recent advances in cryptographic tools such as homomorphic encryption (HE) have provided opportunities for securing the FRS, HE cannot be used directly with FRS in an efficient plug-and-play manner. In particular, although HE is functionally complete for arbitrary programs, it is basically designed for algebraic operations on encrypted data of predetermined shape, such as a polynomial ring. Thus, a non-tailored combination of HE and the system can yield very inefficient performance, and many previous HE-based face template protection methods are hundreds of times slower than plain systems without protection. In this study, we propose IDFace, a new HE-based secure and efficient face identification method with template protection. IDFace is designed on the basis of two novel techniques for efficient searching on a (homomorphically encrypted) biometric database with an angular metric. The first technique is a template representation transformation that sharply reduces the unit cost for the matching test. The second is a space-efficient encoding that reduces wasted space from the encryption algorithm, thus saving the number of operations on encrypted templates. Through experiments, we show that IDFace can identify a face template from among a database of 1M encrypted templates in 126ms, showing only 2X overhead compared to the identification over plaintexts.

Figures

Figures reproduced from arXiv: 2507.12050 by the authors.

Figure 1
Figure 1. Overview of IDFace. Detailed explanations about each component will be presented in Section 4. Best viewed in color. tuning the FRS, additional training for template protections is allowed to improve performance [17, 62, 89, 98]. How￾ever, this approach is not plausible in open-set face recog￾nition scenarios where the train dataset is completely inde￾pendent from users of a FRS. FRSs are generally deployed in two d… view at source ↗
Figure 2
Figure 2. Elapsed time for Enroll and Identify on various numbers of enrolled identities. Solid line: elapsed time for Enroll. Dashed line: elapsed time for Identify. than a second on the database of 2 20 ≈ 1 M identities. To compare our IDFace with other existing BTPs, we provide the computational cost of each method for enroll￾ment and identification on a database of size 1 M. We re￾implemented IronMask [58], SecureVector [… view at source ↗
Figure 3
Figure 3. Schematic diagram for our strategy on the proof of [PITH_FULL_IMAGE:figures/full_fig_p015_3.png] view at source ↗
Figures from the paper (15 more)
Figure 4
Figure 4. Figure 4: Empirical justification of Assumption 1. Verification of the Assumption 1. To complete the proof, it suffices to check whether Assumption 1 holds or not. To this end, we conducted the following experiment: Let us denote X and Y as two independent random variables follo…
Figure 6
Figure 6. Figure 6: Experimental result on calculating |⟨Tα(x), Tα(y)⟩ − ⟨x, y⟩| and theoretical ϵα,θ with various d and fixed α = ⌊ 2 3 d⌋. The x-axis indicates the cosine value between x and y, and y-axis indicates corresponding range of |⟨Tα(x), Tα(y)⟩ − ⟨x, y⟩|. We highlighted the the…
Figure 5
Figure 5. Figure 5: ϵ and |Zd α| with various α and fixed d = 512. This graph tells us that ϵ is minimized when |Zd α| is maximized. The dashed line indicates when α = 341. Our first goal is to find the desirable parameter α that minimizes the difference between ⟨x, y⟩ and ⟨Tα(x), Tα(y)⟩.…
Figure 7
Figure 7. Figure 7: Various Face Recognition Benchmark results on non-protected template extractor (Plain) and [PITH_FULL_IMAGE:figures/full_fig_p024_7.png]
Figure 8
Figure 8. Figure 8: Various Face Recognition Benchmark results on non-protected template extractor (Plain) and [PITH_FULL_IMAGE:figures/full_fig_p025_8.png]
Figure 9
Figure 9. Figure 9: IJB-C verification/identification benchmark results for non-protected feature extractor (Plain) and [PITH_FULL_IMAGE:figures/full_fig_p026_9.png]
Figure 10
Figure 10. Figure 10: IJB-C verification/identification benchmark results for non-protected feature extractor (Plain) and [PITH_FULL_IMAGE:figures/full_fig_p027_10.png]
Figure 11
Figure 11. Figure 11: The distribution of the rescaled cosine value from each positive, negative pairs on LFW, CFP-FP, AgeDB benchmark datasets. [PITH_FULL_IMAGE:figures/full_fig_p027_11.png]
Figure 12
Figure 12. Figure 12: Score distribution in the IJB-C identification task on AdaFace-IResNet101 [ [PITH_FULL_IMAGE:figures/full_fig_p029_12.png]
Figure 13
Figure 13. Figure 13: Full description of IDFace trade-off trick in 2PCFace by employing different transformation parameters (α, β) in Enroll and Identify, respectively. More precisely, during identification, we can treat z † i,j ∧y ∗ for †, ∗ ∈ {+, −} as look-up components of z † i,j on t…
Figure 14
Figure 14. Figure 14: Full description of 2PCFace. Protocols Ns Nenc Sct IDFaceCKKS 4096 (8, 7, 5) 132KB IDFacePC 1 (341, 292, 227) 0.5KB (α, β) IDFaceCKKS IDFacePC 2PCFace (341, 341) 12.94MB 4.41MB 81.30MB (341, 127) 9.24MB 3.43MB 30.28MB (341, 63) 8.18MB 2.93MB 15.02MB [PITH_FULL_IMAGE:…
Figure 15
Figure 15. Figure 15: Description of (µ, ν)-IDFace H. Application of IDFace for Scenarios with Multiple Devices and Servers Recall that both IDFace and 2PCFace regard the scenario in which there is only a single device for recognition. We now con￾sider an extension for this: The large-scal…
Figure 16
Figure 16. Figure 16: Description of (µ, ν)-MPCFace. (x1, . . . , xµ) of x, i.e., ⊕ µ i=1xi = x, we have that ⟨x, y⟩ = HW(⊕ µ i=1(xi ∧ y)). From this, we extend the phase of broad￾casting xi ∧ y in 2PCFace.Identify to µ parties. We will denote GenShare(x; µ) as an extension of the original…
Figure 17
Figure 17. Figure 17: The overview of space efficient encoding technique. More details are provided in Section [PITH_FULL_IMAGE:figures/full_fig_p040_17.png]
Figure 18
Figure 18. Figure 18: Target application scenario of IDFace. above computation with the encoded vector x † encrypted for † ∈ {+, −}, as described in IDFace.IPDB. For more detailed information, we recommend the reader refer to Section 4.2. We also provide the visualization of the applicatio…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

113 extracted references · 79 canonical work pages

  1. [1]

    Openfhe: Open-source fully homomorphic encryp- tion library

    Ahmad Al Badawi, Jack Bates, Flavio Bergamaschi, David Bruce Cousins, Saroja Erabelli, Nicholas Genise, Shai Halevi, Hamish Hunt, Andrey Kim, Yongwoo Lee, et al. Openfhe: Open-source fully homomorphic encryp- tion library. In proceedings of the 10th workshop on en- crypted computing & applied homomorphic cryptography , pages 53–63, 2022. 7

  2. [2]

    Multiplication-free biometric recognition for faster processing under encryption

    Amina Bassit, Florian Hahn, Raymond Veldhuis, and An- dreas Peter. Multiplication-free biometric recognition for faster processing under encryption. In 2022 IEEE Interna- tional Joint Conference on Biometrics (IJCB) , pages 1–9. IEEE, 2022. 3, 6

  3. [3]

    Improved multiplication-free biomet- ric recognition under encryption

    Amina Bassit, Florian FW Hahn, Raymond NJ Veldhuis, and Andreas Peter. Improved multiplication-free biomet- ric recognition under encryption. IEEE Transactions on Biometrics, Behavior, and Identity Science , 6(3):314–325,

  4. [4]

    Practical biometric search under encryption: Meeting the nist runtime requirement without loss of ac- curacy

    Amina Bassit, Florian Hahn, Raymond Veldhuis, and An- dreas Peter. Practical biometric search under encryption: Meeting the nist runtime requirement without loss of ac- curacy. IEEE Transactions on Biometrics, Behavior, and Identity Science, 2025. 3, 6, 7

  5. [5]

    Hebi: Homomorphically encrypted biometric indexing

    Pia Bauspieß, Marcel Grimmer, Cecilie Fougner, Damien Le Vasseur, Thomas Thaulow St¨ocklin, Christian Rathgeb, Jascha Kolberg, Anamaria Costache, and Christoph Busch. Hebi: Homomorphically encrypted biometric indexing. In 2023 IEEE International Joint Conference on Biometrics (IJCB), pages 1–10. IEEE, 2023. 2, 3, 7

  6. [6]

    Im- proved homomorphically encrypted biometric identifica- tion using coefficient packing

    Pia Bauspieß, Jonas Olafsson, Jascha Kolberg, Pawel Droz- dowski, Christian Rathgeb, and Christoph Busch. Im- proved homomorphically encrypted biometric identifica- tion using coefficient packing. In 2022 International Work- shop on Biometrics and Forensics (IWBF) , pages 1–6, 10.1109/IWBF55382.2022.9794523, 2022. IEEE. 2, 3, 7, 28, 31

  7. [7]

    Mr-rawnet: Speaker verification system with multiple temporal resolu- tions for variable duration utterances using raw waveforms

    Seung bin Kim, Chan yeong Lim, Jungwoo Heo, Ju ho Kim, Hyun seo Shin, Kyo-Won Koo, and Ha-Jin Yu. Mr-rawnet: Speaker verification system with multiple temporal resolu- tions for variable duration utterances using raw waveforms. In Interspeech 2024, pages 2125–2129, 2024. 38

  8. [8]

    Secure face matching using fully homomorphic encryption

    Vishnu Naresh Boddeti. Secure face matching using fully homomorphic encryption. In 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Sys- tems (BTAS), pages 1–10. IEEE, 2018. 1, 2, 3, 6, 7, 28, 31 and fingerprint verification tasks in Appendix I

Show all 113 references
  1. [9]

    Elasticface

    Fadi Boutros. Elasticface. https://github.com/ fdbtrs/ElasticFace. accessed: 2024-05-16. 24

  2. [10]

    Elasticface: Elastic margin loss for deep face recognition

    Fadi Boutros, Naser Damer, Florian Kirchbuchner, and Ar- jan Kuijper. Elasticface: Elastic margin loss for deep face recognition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops , pages 1578–1587, 2022. 1, 3, 8, 24

  3. [11]

    (leveled) fully homomorphic encryption without bootstrap- ping

    Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan. (leveled) fully homomorphic encryption without bootstrap- ping. ACM Transactions on Computation Theory (TOCT), 6(3):1–36, 2014. 3

  4. [12]

    Sfinge (synthetic fingerprint generator)

    Raffaele Cappelli, Dario Maio, Davide Maltoni, et al. Sfinge (synthetic fingerprint generator). 2004. 39

  5. [13]

    Homomorphic encryption for arithmetic of approx- imate numbers

    Jung Hee Cheon, Andrey Kim, Miran Kim, and Yongsoo Song. Homomorphic encryption for arithmetic of approx- imate numbers. In International conference on the the- ory and application of cryptology and information security, pages 409–437. Springer, 2017. 3, 5

  6. [14]

    Blind-match: Efficient homomor- phic encryption-based 1: N matching for privacy-preserving biometric identification

    Hyunmin Choi, Jiwon Kim, Chiyoung Song, Simon S Woo, and Hyoungshick Kim. Blind-match: Efficient homomor- phic encryption-based 1: N matching for privacy-preserving biometric identification. In Proceedings of the 33rd ACM International Conference on Information and Knowledge M...

  7. [15]

    Blind-touch: Homomorphic encryption-based distributed neural network inference for privacy-preserving fingerprint authentication

    Hyunmin Choi, Simon S Woo, and Hyoungshick Kim. Blind-touch: Homomorphic encryption-based distributed neural network inference for privacy-preserving fingerprint authentication. In Proceedings of the AAAI Conference on Artificial Intelligence, pages 21976–21985, 2024. 1

  8. [16]

    CRYPTOLAB. Heaan. https : / / github . com / snucrypto/HEAAN, 2023. 6

  9. [17]

    Fehash: Full entropy hash for face template protec- tion

    Thao M Dang, Lam Tran, Thuc D Nguyen, and Deokjai Choi. Fehash: Full entropy hash for face template protec- tion. In Proceedings of the IEEE/CVF conference on com- puter vision and pattern recognition workshops, pages 810– 811, 2020. 2

  10. [18]

    How iris recognition works

    J Daugman. How iris recognition works. IEEE Transac- tions on Circuits and Systems for Video Technology, 14(1): 21–30, 2004. 1

  11. [19]

    Arcface: Additive angular margin loss for deep face recognition

    Jiankang Deng, Jia Guo, Niannan Xue, and Stefanos Zafeiriou. Arcface: Additive angular margin loss for deep face recognition. In Proceedings of the IEEE/CVF con- ference on computer vision and pattern recognition , pages 4690–4699, 2019. 1, 3, 8

  12. [20]

    Deep rank hashing net- work for cancellable face identification

    Xingbo Dong, Sangrae Cho, Youngsam Kim, Soohyung Kim, and Andrew Beng Jin Teoh. Deep rank hashing net- work for cancellable face identification. Pattern Recogni- tion, 131:108886, 2022. 14

  13. [21]

    Wifakey: Generating cryptographic keys from face in the wild

    Xingbo Dong, Hui Zhang, Yen Lung Lai, Zhe Jin, Jund- uan Huang, Wenxiong Kang, and Andrew Beng Jin Teoh. Wifakey: Generating cryptographic keys from face in the wild. arXiv preprint arXiv:2407.14804, 2024. 14

  14. [22]

    Drozdowski, F

    P. Drozdowski, F. Struck, C. Rathgeb, and C. Busch. Benchmarking binarisation schemes for deep face tem- plates. In 2018 25th IEEE International Conference on Im- age Processing (ICIP), pages 191–195, 2018. 31

  15. [23]

    Drozdowski, N

    P. Drozdowski, N. Buchmann, C. Rathgeb, M. Margraf, and C. Busch. On the application of homomorphic encryption to face identification. In 2019 International Conference of the Biometrics Special Interest Group (BIOSIG), pages 1–5,

  16. [24]

    Feature fusion methods for indexing and retrieval of biometric data: Ap- plication to face recognition with privacy protection

    Pawel Drozdowski, Fabian Stockhardt, Christian Rathgeb, Daile Osorio-Roig, and Christoph Busch. Feature fusion methods for indexing and retrieval of biometric data: Ap- plication to face recognition with privacy protection. IEEE Access, 9:139361–139378, 2021. 2, 3, 7

  17. [25]

    Vec2face: Unveil hu- man faces from their blackbox features in face recognition

    Chi Nhan Duong, Thanh-Dat Truong, Khoa Luu, Kha Gia Quach, Hung Bui, and Kaushik Roy. Vec2face: Unveil hu- man faces from their blackbox features in face recognition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 6132–6141, 2020. 1

  18. [26]

    Learning a fixed-length fingerprint representation

    Joshua J Engelsma, Kai Cao, and Anil K Jain. Learning a fixed-length fingerprint representation. IEEE transactions on pattern analysis and machine intelligence , 43(6):1981– 1997, 2019. 31, 39

  19. [27]

    Hers: Homomorphically encrypted representation search

    Joshua J Engelsma, Anil K Jain, and Vishnu Naresh Bod- deti. Hers: Homomorphically encrypted representation search. IEEE Transactions on Biometrics, Behavior, and Identity Science, 2022. 1, 2, 3, 4, 6, 7, 28, 31

  20. [28]

    Privacy- preserving face recognition

    Zekeriya Erkin, Martin Franz, Jorge Guajardo, Stefan Katzenbeisser, Inald Lagendijk, and Tomas Toft. Privacy- preserving face recognition. In Privacy Enhancing Tech- nologies: 9th International Symposium, PETS 2009, Seat- tle, WA, USA, August 5-7, 2009. Proceedings 9, pages 235–

  21. [29]

    Efficient privacy-preserving biometric identification

    David Evans, Yan Huang, Jonathan Katz, and Lior Malka. Efficient privacy-preserving biometric identification. In Proceedings of the 17th conference Network and Dis- tributed System Security Symposium, NDSS , pages 90–98,

  22. [30]

    Somewhat practical fully homomorphic encryption

    Junfeng Fan and Frederik Vercauteren. Somewhat practical fully homomorphic encryption. Cryptology ePrint Archive,

  23. [31]

    Fully homomorphic encryption using ideal lattices

    Craig Gentry. Fully homomorphic encryption using ideal lattices. In Proceedings of the forty-first annual ACM sym- posium on Theory of computing, pages 169–178, 2009. 1

  24. [32]

    A cryptanalysis of two can- celable biometric schemes based on index-of-max hashing

    Loubna Ghammam, Koray Karabina, Patrick Lacharme, and Kevin Thiry-Atighehchi. A cryptanalysis of two can- celable biometric schemes based on index-of-max hashing. IEEE Transactions on Information Forensics and Security, 15:2869–2880, 2020. 14

  25. [33]

    Mbss: Empowering world-class biometric identification, 2024

    IDEMIA Group. Mbss: Empowering world-class biometric identification, 2024. Accessed:2024-01-28. 36

  26. [34]

    Insightface: 2d and 3d face analysis project

    Jia Guo, Jiangkang Deng, Xiang An, Jack Yu, and Baris Gecer. Insightface: 2d and 3d face analysis project. https:/ /github.com/ deepinsight/ insightface. accessed: 2024-05-16. 22

  27. [35]

    Combining crypto with biometrics effectively

    Feng Hao, Ross Anderson, and John Daugman. Combining crypto with biometrics effectively. IEEE transactions on computers, 55(9):1081–1088, 2006. 1

  28. [36]

    Labeled faces in the wild: A database forstudying face recognition in unconstrained environ- ments

    Gary B Huang, Marwan Mattar, Tamara Berg, and Eric Learned-Miller. Labeled faces in the wild: A database forstudying face recognition in unconstrained environ- ments. In Workshop on faces in’Real-Life’Images: detec- tion, alignment, and recognition, 2008. 2, 7, 23

  29. [37]

    Efficient privacy-preserving face identification protocol

    Hai Huang and Luyao Wang. Efficient privacy-preserving face identification protocol. IEEE Transactions on Services Computing, pages 1–10, 2023. 2, 7, 14, 31

  30. [38]

    Quantized neural networks: Training neural networks with low precision weights and activations

    Itay Hubara, Matthieu Courbariaux, Daniel Soudry, Ran El- Yaniv, and Yoshua Bengio. Quantized neural networks: Training neural networks with low precision weights and activations. Journal of Machine Learning Research , 18 (187):1–30, 2018. 5, 31

  31. [39]

    Grote: Group testing for privacy- preserving face identification

    Alberto Ibarrondo, Herv ´e Chabanne, Vincent Despiegel, and Melek ¨Onen. Grote: Group testing for privacy- preserving face identification. In Proceedings of the Thir- teenth ACM Conference on Data and Application Security and Privacy, pages 117–128, 2023. 3

  32. [40]

    Practi- cal privacy-preserving face authentication for smartphones secure against malicious clients

    Jong-Hyuk Im, Seong-Yun Jeon, and Mun-Kyu Lee. Practi- cal privacy-preserving face authentication for smartphones secure against malicious clients. IEEE Transactions on In- formation Forensics and Security, 15:2386–2401, 2020. 14

  33. [41]

    Approximate nearest neighbors: towards removing the curse of dimensionality

    Piotr Indyk and Rajeev Motwani. Approximate nearest neighbors: towards removing the curse of dimensionality. In Proceedings of the thirtieth annual ACM symposium on Theory of computing, pages 604–613, 1998. 14

  34. [42]

    INTEL. Icpl. https : / / github . com / intel / pailliercryptolib_python, 2023. 6

  35. [43]

    Information security, cybersecurity and privacy protection — biometric information protection

    ISO 24745:22. Information security, cybersecurity and privacy protection — biometric information protection. Standard, International Organization for Standardization, Geneva, CH, 2022. 1, 8

  36. [44]

    Prod- uct quantization for nearest neighbor search

    Herve Jegou, Matthijs Douze, and Cordelia Schmid. Prod- uct quantization for nearest neighbor search. IEEE transac- tions on pattern analysis and machine intelligence , 33(1): 117–128, 2010. 31

  37. [45]

    Unitsface: Unified threshold integrated sample-to-sample loss for face recognition

    Xi Jia, Jiancan Zhou, Linlin Shen, Jinming Duan, et al. Unitsface: Unified threshold integrated sample-to-sample loss for face recognition. Advances in Neural Information Processing Systems, 36:32732–32747, 2023. 1, 3

  38. [46]

    Cancelable biometric schemes for eu- clidean metric and cosine metric.Cybersecurity, 6(1):1–20,

    Yubing Jiang, Peisong Shen, Li Zeng, Xiaojie Zhu, Di Jiang, and Chi Chen. Cancelable biometric schemes for eu- clidean metric and cosine metric.Cybersecurity, 6(1):1–20,

  39. [47]

    Biohashing: two factor authentication featuring fin- gerprint data and tokenised random number

    Andrew Teoh Beng Jin, David Ngo Chek Ling, and Alwyn Goh. Biohashing: two factor authentication featuring fin- gerprint data and tokenised random number. Pattern recog- nition, 37(11):2245–2255, 2004. 14

  40. [48]

    {FaceObfuscator}: Defending deep learning-based privacy attacks with gradient descent- resistant features in face recognition

    Shuaifan Jin, He Wang, Zhibo Wang, Feng Xiao, Ji- ahui Hu, Yuan He, Wenwen Zhang, Zhongjie Ba, Weijie Fang, Shuhong Yuan, et al. {FaceObfuscator}: Defending deep learning-based privacy attacks with gradient descent- resistant features in face recognition. In 33rd USENIX Securi...

  41. [49]

    Ranking-based locality sensi- tive hashing-enabled cancelable biometrics: Index-of-max hashing

    Zhe Jin, Jung Yeon Hwang, Yen-Lung Lai, Soohyung Kim, and Andrew Beng Jin Teoh. Ranking-based locality sensi- tive hashing-enabled cancelable biometrics: Index-of-max hashing. IEEE Transactions on Information Forensics and Security, 13(2):393–407, 2017. 1, 14

  42. [50]

    Securing face templates using deep con- volutional neural network and random projection

    Arun Kumar Jindal, Srinivasa Rao Chalamala, and San- tosh Kumar Jami. Securing face templates using deep con- volutional neural network and random projection. In 2019 IEEE International Conference on Consumer Electronics (ICCE), pages 1–6. IEEE, 2019. 2, 14

  43. [51]

    Se- cure and privacy preserving method for biometric template protection using fully homomorphic encryption

    Arun Kumar Jindal, Imtiyazuddin Shaik, Vasudha Vasudha, Srinivasa Rao Chalamala, Rajan Ma, and Sachin Lodha. Se- cure and privacy preserving method for biometric template protection using fully homomorphic encryption. In 2020 IEEE 19th International Conference on Trust, Securi...

  44. [52]

    A fuzzy commitment scheme

    Ari Juels and Martin Wattenberg. A fuzzy commitment scheme. In Proceedings of the 6th ACM conference on Computer and communications security , pages 28–36,

  45. [53]

    Face recon- struction transfer attack as out-of-distribution generaliza- tion

    Yoon Gyo Jung, Jaewoo Park, Xingbo Dong, Hojin Park, Andrew Beng Jin Teoh, and Octavia Camps. Face recon- struction transfer attack as out-of-distribution generaliza- tion. In European Conference on Computer Vision , pages 396–413. Springer, 2024. 1

  46. [54]

    Controllable inversion of black-box face recognition models via diffusion

    Manuel Kansy, Anton Ra ¨el, Graziana Mignone, Jacek Naruniec, Christopher Schroers, Markus Gross, and Ro- mann M Weber. Controllable inversion of black-box face recognition models via diffusion. In Proceedings of the IEEE/CVF International Conference on Computer Vision , pages...

  47. [55]

    Cvlface: High-performance face recognition all-in-one toolkit

    Minchul Kim. Cvlface: High-performance face recognition all-in-one toolkit. accessed: 2024-07-01. 8, 25

  48. [56]

    Adaface: Quality adaptive margin for face recognition

    Minchul Kim, Anil K Jain, and Xiaoming Liu. Adaface: Quality adaptive margin for face recognition. In Proceed- ings of the IEEE/CVF conference on computer vision and pattern recognition, pages 18750–18759, 2022. 1, 3, 8, 24, 29, 30

  49. [57]

    Keypoint relative position encoding for face recog- nition

    Minchul Kim, Yiyang Su, Feng Liu, Anil Jain, and Xiaom- ing Liu. Keypoint relative position encoding for face recog- nition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 244–255,

  50. [58]

    Ironmask: Modular architecture for protecting deep face template

    Sunpill Kim, Yunseong Jeong, Jinsu Kim, Jungkon Kim, Hyung Tae Lee, and Jae Hong Seo. Ironmask: Modular architecture for protecting deep face template. In Proceed- ings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 16125–16134, 2021. 1, 2, 5, 7, 14

  51. [59]

    Scores tell every- thing about bob: Non-adaptive face reconstruction on face recognition systems

    Sunpill Kim, Yong Kiam Tan, Bora Jeong, Soumik Mondal, Khin Mi Mi Aung, and Jae Hong Seo. Scores tell every- thing about bob: Non-adaptive face reconstruction on face recognition systems. In 2024 IEEE Symposium on Security and Privacy (SP), pages 1684–1702. IEEE, 2024. 1

  52. [60]

    Error-based and entropy- based discretization of continuous features

    Ron Kohavi and Mehran Sahami. Error-based and entropy- based discretization of continuous features. In KDD, pages 114–119, 1996. 31

  53. [61]

    Face template protection using deep convolu- tional neural network

    Arun Kumar Jindal, Srinivas Chalamala, and Santosh Ku- mar Jami. Face template protection using deep convolu- tional neural network. In Proceedings of the IEEE con- ference on computer vision and pattern recognition work- shops, pages 462–470, 2018. 2, 14

  54. [62]

    Deep secure encoding for face tem- plate protection

    Rohit Kumar Pandey, Yingbo Zhou, Bhargava Urala Kota, and Venu Govindaraju. Deep secure encoding for face tem- plate protection. In Proceedings of the IEEE conference on computer vision and pattern recognition workshops, pages 9–15, 2016. 2

  55. [63]

    Efficient known-sample attack for distance- preserving hashing biometric template protection schemes

    Yenlung Lai, Zhe Jin, KokSheik Wong, and Massimo Tistarelli. Efficient known-sample attack for distance- preserving hashing biometric template protection schemes. IEEE Transactions on Information Forensics and Security, 16:3170–3185, 2021. 1, 14

  56. [64]

    Cancellable iris template generation based on indexing-first-one hashing

    Yen-Lung Lai, Zhe Jin, Andrew Beng Jin Teoh, Bok- Min Goi, Wun-She Yap, Tong-Yuen Chai, and Christian Rathgeb. Cancellable iris template generation based on indexing-first-one hashing. Pattern Recognition, 64:105– 117, 2017. 1

  57. [65]

    Privface: fast privacy-preserving face authentication with revocable and reusable biometric credentials

    Jing Lei, Qingqi Pei, Yao Wang, Wenhai Sun, and Xuefeng Liu. Privface: fast privacy-preserving face authentication with revocable and reusable biometric credentials. IEEE Transactions on Dependable and Secure Computing, 19(5): 3101–3112, 2021. 14

  58. [66]

    Trq: Ternary neural networks with residual quantization

    Yue Li, Wenrui Ding, Chunlei Liu, Baochang Zhang, and Guodong Guo. Trq: Ternary neural networks with residual quantization. In Proceedings of the AAAI conference on artificial intelligence, pages 8538–8546, 2021. 5, 31

  59. [67]

    Indexing-min–max hashing: Relaxing the security–performance tradeoff for cancelable finger- print templates

    Yuxing Li, Liaojun Pang, Heng Zhao, Zhicheng Cao, Eryun Liu, and Jie Tian. Indexing-min–max hashing: Relaxing the security–performance tradeoff for cancelable finger- print templates. IEEE Transactions on Systems, Man, and Cybernetics: Systems, 52(10):6314–6325, 2022. 14

  60. [68]

    An analysis on equal width quantization and linearly sep- arable subcode encoding-based discretization and its per- formance resemblances

    Meng-Hui Lim, Andrew Beng Jin Teoh, and Kar-Ann Toh. An analysis on equal width quantization and linearly sep- arable subcode encoding-based discretization and its per- formance resemblances. EURASIP Journal on Advances in Signal Processing, 2011:1–14, 2011. 31

  61. [69]

    Opensphere

    Weiyang Liu and Yandong Wen. Opensphere. https:// github.com/ydwen/opensphere . accessed: 2024- 05-16. 24

  62. [70]

    The era of 1-bit llms: All large language models are in 1.58 bits

    Shuming Ma, Hongyu Wang, Lingxiao Ma, Lei Wang, Wenhui Wang, Shaohan Huang, Li Dong, Ruiping Wang, Jilong Xue, and Furu Wei. The era of 1-bit llms: All large language models are in 1.58 bits. arXiv preprint arXiv:2402.17764, 2024. 5, 31

  63. [71]

    A secure face-verification scheme based on homo- morphic encryption and deep neural networks

    Yukun Ma, Lifang Wu, Xiaofeng Gu, Jiaoyu He, and Zhou Yang. A secure face-verification scheme based on homo- morphic encryption and deep neural networks. IEEE Ac- cess, 5:16532–16538, 2017. 31

  64. [72]

    On the reconstruction of face images from deep face tem- plates

    Guangcan Mai, Kai Cao, Pong C Yuen, and Anil K Jain. On the reconstruction of face images from deep face tem- plates. IEEE transactions on pattern analysis and machine intelligence, 41(5):1188–1202, 2018. 1

  65. [73]

    Secureface: Face template protection

    Guangcan Mai, Kai Cao, Xiangyuan Lan, and Pong C Yuen. Secureface: Face template protection. IEEE Transactions on Information Forensics and Security, 16:262–277, 2020. 14

  66. [74]

    Fvc2004: Third fingerprint ver- ification competition

    Dario Maio, Davide Maltoni, Raffaele Cappelli, Jim L Wayman, and Anil K Jain. Fvc2004: Third fingerprint ver- ification competition. In International conference on bio- metric authentication, pages 1–7. Springer, 2004. 39

  67. [75]

    Handbook of fingerprint recognition

    Davide Maltoni, Dario Maio, Anil K Jain, Salil Prabhakar, et al. Handbook of fingerprint recognition. Springer, 2009. 1

  68. [76]

    Iarpa janus benchmark-c: Face dataset and protocol

    Brianna Maze, Jocelyn Adams, James A Duncan, Nathan Kalka, Tim Miller, Charles Otto, Anil K Jain, W Tyler Niggel, Janet Anderson, Jordan Cheney, et al. Iarpa janus benchmark-c: Face dataset and protocol. In 2018 inter- national conference on biometrics (ICB) , pages 158–165. I...

  69. [77]

    Towards privacy-preserving, real-time and lossless feature matching

    Qiang Meng and Feng Zhou. Towards privacy-preserving, real-time and lossless feature matching. arXiv preprint arXiv:2208.00214, 2022. 7, 31

  70. [78]

    Quang Meng, Torsten Schlett, Kaiyu Yue, and Mar- tin Knoche. Magface. https : / / github . com / IrvingMeng/MagFace. accessed: 2024-05-16. 24

  71. [79]

    Magface: A universal representation for face recognition and quality assessment

    Qiang Meng, Shichao Zhao, Zhida Huang, and Feng Zhou. Magface: A universal representation for face recognition and quality assessment. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , pages 14225–14234, 2021. 1, 3, 8, 24

  72. [80]

    Privacy-preserving face recognition using random fre- quency components

    Yuxi Mi, Yuge Huang, Jiazhen Ji, Minyi Zhao, Jiaxiang Wu, Xingkun Xu, Shouhong Ding, and Shuigeng Zhou. Privacy-preserving face recognition using random fre- quency components. In Proceedings of the IEEE/CVF In- ternational Conference on Computer Vision, pages 19673– 19684, 2023. 14

  73. [81]

    Privacy-preserving face recognition us- ing trainable feature subtraction

    Yuxi Mi, Zhizhou Zhong, Yuge Huang, Jiazhen Ji, Jian- qing Xu, Jun Wang, Shaoming Wang, Shouhong Ding, and Shuigeng Zhou. Privacy-preserving face recognition us- ing trainable feature subtraction. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recogni...

  74. [82]

    Significant fea- ture based representation for template protection

    Deen Dayal Mohan, Nishant Sankaran, Sergey Tulyakov, Srirangaraj Setlur, and Venu Govindaraju. Significant fea- ture based representation for template protection. In Pro- ceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops , pages 2389–2396,

  75. [83]

    Agedb: the first manually collected, in-the-wild age database

    Stylianos Moschoglou, Athanasios Papaioannou, Chris- tos Sagonas, Jiankang Deng, Irene Kotsia, and Stefanos Zafeiriou. Agedb: the first manually collected, in-the-wild age database. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops , pa...

  76. [84]

    On Some Useful ”Inefficient” Statis- tics

    Frederick Mosteller. On Some Useful ”Inefficient” Statis- tics. The Annals of Mathematical Statistics , 17(4):377 – 408, 1946. 17, 18

  77. [85]

    A note on a method for generating points uniformly on n-dimensional spheres

    Mervin E Muller. A note on a method for generating points uniformly on n-dimensional spheres. Communications of the ACM, 2(4):19–20, 1959. 16

  78. [86]

    V oxceleb: Large-scale speaker verification in the wild

    Arsha Nagrani, Joon Son Chung, Weidi Xie, and Andrew Zisserman. V oxceleb: Large-scale speaker verification in the wild. Computer Speech & Language, 60:101027, 2020. 38

  79. [87]

    Fingerprint-based fuzzy vault: Implementation and perfor- mance

    Karthik Nandakumar, Anil K Jain, and Sharath Pankanti. Fingerprint-based fuzzy vault: Implementation and perfor- mance. IEEE transactions on information forensics and se- curity, 2(4):744–757, 2007. 1

  80. [88]

    Nist 2024 speark recognition evaluation (sre24)

    NIST. Nist 2024 speark recognition evaluation (sre24). ac- cessed: 2024-10-21. 38

  81. [89]

    Stable hash generation for efficient privacy-preserving face identification

    Dail ´e Osorio-Roig, Christian Rathgeb, Pawel Drozdowski, and Christoph Busch. Stable hash generation for efficient privacy-preserving face identification. IEEE Transactions on Biometrics, Behavior, and Identity Science , 4(3):333– 348, 2022. 2, 3, 7, 31

  82. [90]

    Security analysis on locality-sensitive hashing-based biometric tem- plate protection schemes

    Seunghun Paik, Sunpill Kim, and Jae Hong Seo. Security analysis on locality-sensitive hashing-based biometric tem- plate protection schemes. In 34th British Machine Vision Conference 2023, BMVC 2023, Aberdeen, UK, November 20-24, 2023. BMV A, 2023. 14

  83. [91]

    Public-key cryptosystems based on compos- ite degree residuosity classes

    Pascal Paillier. Public-key cryptosystems based on compos- ite degree residuosity classes. In International conference on the theory and applications of cryptographic techniques, pages 223–238. Springer, 1999. 3, 5

  84. [92]

    Benchmarking fixed-length finger- print representations across different embedding sizes and sensor types

    Tim Rohwedder, Dail ´e Osorio-Roig, Christian Rathgeb, and Christoph Busch. Benchmarking fixed-length finger- print representations across different embedding sizes and sensor types. In 2023 International Conference of the Bio- metrics Special Interest Group (BIOSIG), pages 1–6. IEEE,

  85. [93]

    Frontal to profile face verification in the wild

    Soumyadip Sengupta, Jun-Cheng Chen, Carlos Castillo, Vishal M Patel, Rama Chellappa, and David W Jacobs. Frontal to profile face verification in the wild. In 2016 IEEE Winter Conference on Applications of Computer Vi- sion (WACV), pages 1–9. IEEE, 2016. 2, 7, 23

  86. [94]

    Face recon- struction from facial templates by learning latent space of a generator network

    Hatef Otroshi Shahreza and S ´ebastien Marcel. Face recon- struction from facial templates by learning latent space of a generator network. In Thirty-seventh Conference on Neural Information Processing Systems, 2023. 1

  87. [95]

    Template inversion attack against face recognition systems using 3d face reconstruction

    Hatef Otroshi Shahreza and S ´ebastien Marcel. Template inversion attack against face recognition systems using 3d face reconstruction. In Proceedings of the IEEE/CVF In- ternational Conference on Computer Vision, pages 19662– 19672, 2023

  88. [96]

    Face reconstruction from face embeddings us- ing adapter to a face foundation model

    Hatef Otroshi Shahreza, Anjith George, and S ´ebastien Marcel. Face reconstruction from face embeddings us- ing adapter to a face foundation model. arXiv preprint arXiv:2411.03960, 2024. 1

  89. [97]

    Extremely-large-scale biometric authentication system-its practical implementa- tion

    Leiming Su and Shizuo Sakamoto. Extremely-large-scale biometric authentication system-its practical implementa- tion. NEC Technical Journal, 7(2):57, 2012. 36

  90. [98]

    Zero-shot deep hashing and neural network based error cor- rection for face template protection

    Veeru Talreja, Matthew C Valenti, and Nasser M Nasrabadi. Zero-shot deep hashing and neural network based error cor- rection for face template protection. In 2019 IEEE 10th In- ternational Conference on Biometrics Theory, Applications and Systems (BTAS), pages 1–10. IEEE, 2019. 2, 14

  91. [99]

    Practical biometric authentication with template pro- tection

    Pim Tuyls, Anton HM Akkermans, Tom AM Kevenaar, Geert-Jan Schrijen, Asker M Bazen, and Raimond NJ Veld- huis. Practical biometric authentication with template pro- tection. In Audio-and Video-Based Biometric Person Au- thentication: 5th International Conference, AVBPA 2005, Hi...

  92. [100]

    Scipy 1.0: fundamental algorithms for scien- tific computing in python

    Pauli Virtanen, Ralf Gommers, Travis E Oliphant, Matt Haberland, Tyler Reddy, David Cournapeau, Evgeni Burovski, Pearu Peterson, Warren Weckesser, Jonathan Bright, et al. Scipy 1.0: fundamental algorithms for scien- tific computing in python. Nature methods, 17(3):261–272,

  93. [101]

    The eu general data protection regulation (gdpr)

    Paul V oigt and Axel V on dem Bussche. The eu general data protection regulation (gdpr). A Practical Guide, 1st Ed., Cham: Springer International Publishing , 10(3152676): 10–5555, 2017. 1

  94. [102]

    Interpretable security anal- ysis of cancellable biometrics using constrained-optimized similarity-based attack

    Hanrui Wang, Xingbo Dong, Zhe Jin, Andrew Beng Jin Teoh, and Massimo Tistarelli. Interpretable security anal- ysis of cancellable biometrics using constrained-optimized similarity-based attack. In Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision...

  95. [103]

    Privacy-preserving adversarial facial features

    Zhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang, Ji- ahui Hu, Yan Wang, Peng Sun, Wei Yuan, Kaixin Liu, and Kui Ren. Privacy-preserving adversarial facial features. In Proceedings of the IEEE/CVF Conference on Computer Vi- sion and Pattern Recognition, pages 8212–8221, 2023. 2, 14

  96. [104]

    Sphereface2: Binary classification is all you need for deep face recognition

    Yandong Wen, Weiyang Liu, Adrian Weller, Bhiksha Raj, and Rita Singh. Sphereface2: Binary classification is all you need for deep face recognition. InInternational Conference on Learning Representations, 2022. 1, 3, 8, 24

  97. [105]

    Assessing privacy risks from feature vector reconstruction attacks

    Emily Wenger, Francesca Falzon, Josephine Passananti, Haitao Zheng, and Ben Y Zhao. Assessing privacy risks from feature vector reconstruction attacks. arXiv preprint arXiv:2202.05760, 2022. 1

  98. [106]

    Pushing the limits of raw waveform speaker recognition

    Jee weon Jung, Youjin Kim, Hee-Soo Heo, Bong-Jin Lee, Youngki Kwon, and Joon Son Chung. Pushing the limits of raw waveform speaker recognition. In Interspeech 2022, pages 2228–2232, 2022. 38

  99. [107]

    Reshape dimensions network for speaker recognition

    Ivan Yakovlev, Rostislav Makarov, Andrei Balykin, Pavel Malov, Anton Okhotnikov, and Nikita Torgashov. Reshape dimensions network for speaker recognition. InInterspeech 2024, pages 3235–3239, 2024. 38

  100. [108]

    Secure iris verifi- cation

    Shenglin Yang and Ingrid Verbauwhede. Secure iris verifi- cation. In 2007 IEEE International Conference on Acous- tics, Speech and Signal Processing-ICASSP’07 , pages II–

  101. [109]

    Uniface: Unified cross-entropy loss for deep face recognition

    Jiancan Zhou, Xi Jia, Qiufu Li, Linlin Shen, and Jin- ming Duan. Uniface: Unified cross-entropy loss for deep face recognition. In Proceedings of the IEEE/CVF Inter- national Conference on Computer Vision , pages 20730– 20739, 2023. 1, 3

  102. [110]

    Trained ternary quantization

    Chenzhuo Zhu, Song Han, Huizi Mao, and William J Dally. Trained ternary quantization. In International Conference on Learning Representations, 2017. 5, 31

  103. [111]

    Webface260m: A benchmark unveiling the power of million-scale deep face recognition

    Zheng Zhu, Guan Huang, Jiankang Deng, Yun Ye, Junjie Huang, Xinze Chen, Jiagang Zhu, Tian Yang, Jiwen Lu, Dalong Du, et al. Webface260m: A benchmark unveiling the power of million-scale deep face recognition. In Pro- ceedings of the IEEE/CVF Conference on Computer Vision and P...

  104. [112]

    By the symmetry of the normal distribution, we can do the same approximation to I mm XW which results in the same bound. Also, for P −(θ, ξ) = Z ∞ c+ξ Z − c+ξ cos θ −u −∞ fU V(u, v)dvdu, we can apply a similar argument for I pm XW and I mp XW, namely, Pr I pm XW − P −(θ, ξ2)d ...

  105. [113]

    bad” events. We leave detailed investigations about the phenomenon, e.g., clarifying what conditions make “bad

    On the other hand, on the right hand side (Gallery 2), the number of samples in the 2nd and 4th quadrants is similar when FPIR=1e-4, whereas there are more samples in 4th quadrant when FPIR=1e-2. We figured out that this corresponds to the benchmark result provided in Tab. 6. ...

Pith tools

Reviewed August 6, 2026 · model on record in the stance chip above.