REVIEW 3 major objections 5 minor 1 cited by
Towards Privacy-preserving Photorealistic Self-avatars in Mixed Reality
T0 review · 3 major / 5 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read This paper introduces two algorithms, AvatarLDP and AvatarRotation, that de-identify photorealistic self-avatars by perturbing only the identity embedding inside generative models, preserving demographic attributes and expression while…
desk verdict First real attempt at DP for 3D avatar identity, with honest evaluation and a clever PCA remap, but the formal guarantee is mis-calibrated and the end-to-end privacy claim outruns what the disentanglement delivers. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the identity embedding vector $x_{id}$ produced by the model's identity encoder, viewed as a point on the unit hypersphere $S^{n-1}$. Privacy operations act on this vector alone: AvatarLDP samples a replacement from the von Mises-Fisher distribution $\mathrm{VMF}(x_{id}, \varepsilon)$—a directional distribution concentrated around a mean direction—whose metric-privacy guarantee ($\varepsilon d_\angle$ and therefore $\varepsilon$-LDP) is established in the cited literature and whose concentration $\varepsilon$ acts as the privacy budget; AvatarRotation forms a random orthonormal basis containing $x_{id}$ and applies a higher-dimensional rotation matrix with fixed angle $\theta$, so every sample is moved exactly $\theta$ away while the direction stays random. Because some models, such as the codec avatar, embed identity into sparse, non-metric spaces, the machinery includes a PCA remap to $\mathbb{R}^{16}$, privacy operations there, then a softmax-weighted interpolation of the nearest real embeddings to return to the model's native embedding space. The entire scheme rests on these embeddings being sufficiently disentangled: changing $x_{id}$ alone should change identity attributes while leaving expression, pose, lighting, and demographic attributes intact.
What would settle it
Take a trained identity-encoding generative model and replace the identity embedding with a uniformly random point on the hypersphere while keeping the contextual embedding fixed. If the fraction of such avatars still matched to their source identity is substantially above random chance—the paper reports about 15% for SimSwap and GHOST—then identity is leaking through non-identity channels, and the empirical privacy floor is set by the generator rather than by the privacy mechanism. A complementary test is to drive AvatarLDP to $\varepsilon \to 0$ on a deliberately entangled model and measure whether expression or pose classifiers drift; if they do, the claim that non-identity attributes are preserved fails.
Extended reading notes
Core claim
The discovery this paper is trying to establish is that de-identifying a photorealistic avatar does not require blurring pixels, retraining generators, or degrading realism: it can be done by editing one vector, the identity embedding, at a point inside the generation pipeline. Identity-encoding models such as SimSwap, GHOST, and the Relightable Gaussian Codec Avatar map an input face to a high-dimensional identity vector $x_{id}$; the proposed methods treat that vector as a point on the unit hypersphere $S^{n-1}$, where identity similarity is angular distance. AvatarLDP draws the replacement identity from the von Mises-Fisher distribution $\mathrm{VMF}(x_{id}, \varepsilon)$, whose concentration parameter $\varepsilon$ controls how far the new identity wanders and which yields a provable $\varepsilon$-LDP / $\varepsilon d_\angle$ guarantee. AvatarRotation instead rotates $x_{id}$ by a fixed angle $\theta$ around a random axis, producing a user-specified minimum identity offset with uncertainty in direction. For 3D codec avatars whose identity embeddings are too sparse for angular sampling, the paper adds a PCA projection into a dense 16-dimensional angular space, resampling there, and reconstructing a plausible embedding as a softmax-weighted average of nearby real identities. The result, on the paper's evidence, is an avatar that looks like the user's demographic and expressive self but defeats identity lookup, impersonation, and linkage from screenshots or stored features.
Load-bearing premise
The load-bearing premise is that a generative model's identity embedding is disentangled enough from expression, pose, lighting, and demographics that replacing or rotating only that embedding changes who the avatar looks like while leaving everything else intact—yet the paper's own results show random identity sampling still yields roughly 15% re-identification for SimSwap and GHOST, so the privacy guarantee inherits the generator's imperfect disentanglement.
Editorial extensions
If this is right
- Public mixed-reality environments can render photorealistic avatars while the user's true face never leaves the device: identity is altered on the device before any external renderer or server receives it.
- AvatarLDP's guarantee is a formal local differential privacy bound on the released identity embedding, so it holds against adversaries who know the generation pipeline and the privacy parameters, to the extent that the generator disentangles identity.
- AvatarRotation gives users a concrete privacy dial: increasing $\theta$ produces a larger enforced identity offset, with $\theta = 150°$ lowering rank-1 identification to about 1% on the tested 2D face-swap models.
- Because the composition of AvatarLDP and AvatarRotation inherits the DP guarantee through post-processing, applications can combine provable uncertainty with a user-specified minimum offset.
- The methods operate on embeddings rather than pixels or rendered frames, so they transfer across generative architectures and can be dropped into existing avatar pipelines without retraining.
Reading between the lines
- The formal privacy guarantee covers the identity embedding, but the privacy a user actually experiences is bounded by the generator's disentanglement; the observed ~15% re-identification under random identity sampling implies that platform claims should read 'de-identified up to the generator's identity channel,' not 'de-identified in the face-recognition sense.'
- The PCA remap-and-reconstruct step is a general adapter: any generative model with a sparse or non-metric identity latent space could be retrofitted with the same privacy operations, which generalizes the method well beyond the three tested architectures.
- Because re-identification difficulty grows with the number of identities in the gallery, a large metaverse with millions of users would likely need much milder $\varepsilon$ or $\theta$ values to reach the same empirical privacy, improving the utility trade-off; that prediction is testable by scaling the authors' CelebA evaluation to a larger face gallery.
- Facial appearance is only one identifying stream; the paper itself notes body motion, gaze, and voice also identify users, so this method is a necessary but not sufficient component of end-to-end privacy in mixed reality and should be composed with per-modality anonymization.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes two mechanisms, AvatarLDP and AvatarRotation, for de-identifying photorealistic self-avatars by perturbing the identity embedding inside identity-encoding generative models. AvatarLDP samples a new identity vector from a von Mises-Fisher distribution centered on the original embedding and claims ε-LDP guarantees; AvatarRotation rotates the identity vector by a user-specified angle along a random direction. The methods are implemented on two 2D face-swapping models (SimSwap and GHOST) and one 3D codec avatar model, and evaluated with rank-k identification, EER, SSIM, and demographic/expression classifiers. The paper reports that strong privacy settings reduce rank-1 identification to near the random-sampling floor while largely preserving photorealism and non-identity attributes, and it compares favorably against PixelDP, MetricSVD, and IdentityDP baselines.
Significance. The paper is a useful first exploration of privacy-preserving rendering for photorealistic 3D avatars, a timely problem as social VR and MR deploy realistic avatars. Its strengths include an honest empirical evaluation, explicit acknowledgment of identity-disentanglement leakage, and released code for the algorithms and evaluation pipeline, which supports reproducibility. If the formal claims are corrected, the work would be a solid contribution: it demonstrates that embedding-space perturbation can be adapted across heterogeneous generative architectures and provides a concrete comparison point for future privacy mechanisms in XR. The central formal claims, however, currently require revision: the ε calibration of the VMF mechanism is inconsistent with the paper's own Theorem 1, and the DP guarantee is argued for the identity embedding rather than the rendered avatar, leaving an unquantified residual leakage path through unperturbed context features.
major comments (3)
- [Section V-D and Eq. (1)] The VMF mechanism is claimed to satisfy ε-LDP, but this is not what follows from the paper's own Theorem 1. Theorem 1 states that an ε d_X-private mechanism A_ε must be composed with the sensitivity Δ of the query to yield ε-DP, i.e., A_{ε/Δ} ∘ f is ε-DP. On the unit hypersphere, the maximum angular distance is π, so using the d_∠ metric requires sampling from VMF(x_id, ε/π) to achieve ε-LDP; using the Euclidean d_2 metric, whose maximum on S^{n-1} is 2, requires VMF(x_id, ε/2). Equation (1) instead uses VMF(x_id, ε) and the text repeatedly states that this is ε-LDP. The actual guarantee is therefore ε·π-LDP (or 2ε-LDP) for the stated mechanism, and the ε values in Tables I–III are not directly comparable with the ε of IdentityDP. This is a load-bearing error in the formal privacy claim and should be corrected by reparameterizing the concentration or by explicitly reporting the privacy parameter after sensitivity scaling.
- [Section VI-A, Eq. (1), Tables I and III] The differential privacy guarantee applies to the sampled identity embedding x̃_id, not to the rendered avatar. The full mechanism is A(source) = G(VMF(Enc_id(source)), Enc_ctx(source)), where Enc_ctx(source) and the generator G are not post-processing of x̃_id alone, so the standard DP post-processing property does not transfer the guarantee to the output avatar. The paper's own random-sampling rows demonstrate this: with the identity embedding drawn uniformly at random (ε→0, so no identity information remains in that path), SimSwap retains rank-1 re-identification of 14.54% and GHOST 14.96%, against a chance baseline near 0.1%. This residual matching must come from context features or other non-perturbed channels. The abstract's claim that AvatarLDP 'provides differential privacy guarantees' for user appearance and the phrase 'without privacy risk' are therefore unsupported. Section VIII-B acknowledges the disentanglement limitation, but it is presented as future work rather than as a qualification of the main privacy claim. The manuscript should be reframed to state that the formal guarantee is embedding-level, and the avatar-level residual re-identification risk should be reported as part of the headline results.
- [Section VI-C and Table II] The 3D evaluation is restricted to the N=256 identities used to fit the PCA remapping in Eqs. (4)–(5). The same identities form both the PCA training set and the evaluation gallery, and no held-out identities are used. This makes the 3D rank-1 rates, such as the 1.95% random-sampling floor, hard to interpret for generalization to new users: the nearest-neighbor reconstruction in Eq. (5) may behave differently for an identity outside the PCA training set, and the privacy-utility trade-off may be confounded by the model's memorization of the training identities. The claim that the methods 'generalize across generative architectures in 2D and 3D' needs support from an evaluation with held-out identities or an external 3D avatar dataset, or the claim should be explicitly scoped to the 256-identity setting.
minor comments (5)
- [Section V-D] The heading and text misspell Weggenmann and Kerschbaum as 'Kershbaum' in several places; the name should be corrected.
- [Section VI-A, Eq. (2)] The quantities b1 and b2 are used in Rodrigues' formula before their definition is fully explained; the sentence defining them as columns of U/|U| should be clarified and placed before Eq. (3).
- [Section VII-A and Table II] The 3D rank-1 estimates are computed on only 256 identities, so confidence intervals or a statement of statistical uncertainty would help; with 256 trials, the difference between 0.78% and 1.95% is within a plausible sampling range.
- [Section VIII-D] There is a typo, 'phone scanes', which should read 'phone scans'.
- [Figure 9] The failure cases show only the SimSwap architecture; since GHOST also shows a random-sampling re-identification floor of 14.96%, including GHOST failure cases or explaining why they are omitted would strengthen the disentanglement discussion.
Circularity Check
No significant circularity: the formal privacy guarantee is an imported external theorem and the empirical evaluation uses external benchmarks with disclosed limitations.
full rationale
I walked the paper's derivation chain. AvatarLDP's ε-LDP guarantee is not derived from the paper's own outputs; it is explicitly imported: "Weggenmann and Kerschbaum proved the VMF distribution is a valid mechanism to satisfy ε LDP and εd∠ privacy [78]" (Section V-C), and Eq. (1) instantiates that mechanism. AvatarRotation's property that d∠(x, x′) ≡ θ is definitional to a rotation, but the privacy and utility claims are measured against external face recognizers and the CelebA/LFW datasets, not against the method's own fitted parameters. The PCA remapping in Section VI-C is a preprocessing step for the 3D model, and its outputs are evaluated with rendered 2D portraits against an independently constructed registry; no fitted value is renamed as a prediction. The self-citations [59], [100], and [104] concern face swaps and gaze/multimodal anonymization, and none is load-bearing for the central DP derivation. The residual identity leakage under random sampling (~15% for SimSwap and GHOST, Tables I and III) is disclosed in Section VII-A and again in Section VIII-B as an assumption violation of identity disentanglement; that is an empirical limitation and correctness risk, not a circular reduction. The skeptic's concern that the formal DP guarantee applies to the sampled embedding rather than the full rendered avatar is a scoping caveat, not circularity, because the paper does not claim post-processing over the unperturbed context features. Overall, no step reduces by construction to its own inputs.
Assumptions & free parameters
free parameters (3)
- PCA dimension (n=16) =
16
- Softmax scale lambda =
32
- Nearest-neighbor count j =
1..8
assumptions (4)
- domain assumption Identity is sufficiently disentangled from non-identity attributes in the generative model's embedding space.
- domain assumption Identity embeddings can be faithfully represented on a unit hypersphere with angular distance as the relevant metric.
- ad hoc to paper PCA of the 256 training identities produces a low-dimensional angular space where nearest-neighbor reconstruction yields plausible, de-identified avatars.
- standard math The VMF mechanism (Weggenmann and Kerschbaum) is a valid dX-private mechanism.
Cite this review
Pith. "Pith review of Towards Privacy-preserving Photorealistic Self-avatars in Mixed Reality." pith.science (2026). https://pith.science/paper/FRSJPZSX
@misc{pith2026250722153,
author = {Pith},
title = {Pith review of: Towards Privacy-preserving Photorealistic Self-avatars in Mixed Reality},
year = {2026},
howpublished = {\url{https://pith.science/paper/FRSJPZSX}},
note = {Machine review of arXiv:2507.22153}
}
read the original abstract
Photorealistic 3D avatar generation has rapidly improved in recent years, and realistic avatars that match a user's true appearance are more feasible in Mixed Reality (MR) than ever before. Yet, there are known risks to sharing one's likeness online, and photorealistic MR avatars could exacerbate these risks. If user likenesses were to be shared broadly, there are risks for cyber abuse or targeted fraud based on user appearances. We propose an alternate avatar rendering scheme for broader social MR -- synthesizing realistic avatars that preserve a user's demographic identity while being distinct enough from the individual user to protect facial biometric information. We introduce a methodology for privatizing appearance by isolating identity within the feature space of identity-encoding generative models. We develop two algorithms that then obfuscate identity: \epsmethod{} provides differential privacy guarantees and \thetamethod{} provides fine-grained control for the level of identity offset. These methods are shown to successfully generate de-identified virtual avatars across multiple generative architectures in 2D and 3D. With these techniques, it is possible to protect user privacy while largely preserving attributes related to sense of self. Employing these techniques in public settings could enable the use of photorealistic avatars broadly in MR, maintaining high realism and immersion without privacy risk.
Figures
Figures from the paper (8 more)
Forward citations
Cited by 1 Pith paper
-
3D FaceShell: Attribute Transfer in 3D Face Avatars as a VLM Defense Mechanism
An optimized, view-consistent 3D Gaussian shell around a face avatar reliably changes which facial attributes vision-language models report, while preserving identity and appearance.
Reference graph
Works this paper leans on
-
[1]
Deep relightable appearance models for animatable faces,
S. Bi, S. Lombardi, S. Saito, T. Simon, S.-E. Wei, K. Mcphail, R. Ra- mamoorthi, Y . Sheikh, and J. Saragih, “Deep relightable appearance models for animatable faces,” ACM Trans. Graph., vol. 40, no. 4, pp. 89:1–89:15, Jul. 2021
2021
-
[2]
Dual-Space NeRF: Learning Animatable Avatars and Scene Lighting in Separate Spaces,
Y . Zhi, S. Qian, X. Yan, and S. Gao, “Dual-Space NeRF: Learning Animatable Avatars and Scene Lighting in Separate Spaces,” in 2022 International Conference on 3D Vision (3DV) , Sep. 2022, pp. 1–10, iSSN: 2475-7888
2022
-
[3]
Relightable Gaussian Codec Avatars,
S. Saito, G. Schwartz, T. Simon, J. Li, and G. Nam, “Relightable Gaussian Codec Avatars,” in Computer Vision and Pattern Recognition, 2024, pp. 130–141
2024
-
[4]
URAvatar: Universal Relightable Gaussian Codec Avatars,
J. Li, C. Cao, G. Schwartz, R. Khirodkar, C. Richardt, T. Simon, Y . Sheikh, and S. Saito, “URAvatar: Universal Relightable Gaussian Codec Avatars,” in SIGGRAPH Asia 2024 Conference Papers , ser. SA ’24. New York, NY , USA: Association for Computing Machinery, Dec. 2024, pp. 1–11
2024
-
[5]
MonoGaussianAvatar: Monocular Gaussian Point-based Head Avatar,
Y . Chen, L. Wang, Q. Li, H. Xiao, S. Zhang, H. Yao, and Y . Liu, “MonoGaussianAvatar: Monocular Gaussian Point-based Head Avatar,” in ACM SIGGRAPH 2024 Conference Papers , ser. SIGGRAPH ’24. New York, NY , USA: Association for Computing Machinery, Jul. 2024, pp. 1–9
2024
-
[6]
3D Gaussian Blendshapes for Head Avatar Animation,
S. Ma, Y . Weng, T. Shao, and K. Zhou, “3D Gaussian Blendshapes for Head Avatar Animation,” in ACM SIGGRAPH 2024 Conference Papers, ser. SIGGRAPH ’24. New York, NY , USA: Association for Computing Machinery, Jul. 2024, pp. 1–10
2024
-
[7]
Media2Face: Co-speech Facial Animation Gen- eration With Multi-Modality Guidance,
Q. Zhao, P. Long, Q. Zhang, D. Qin, H. Liang, L. Zhang, Y . Zhang, J. Yu, and L. Xu, “Media2Face: Co-speech Facial Animation Gen- eration With Multi-Modality Guidance,” in ACM SIGGRAPH 2024 Conference Papers , ser. SIGGRAPH ’24. New York, NY , USA: Association for Computing Machinery, Jul. 2024, pp. 1–13
2024
-
[8]
SqueezeMe: Mobile-Ready Distillation of Gaussian Full-Body Avatars
S. Saito, S. Pidhorskyi, I. Santesteban, F. Iandola, D. Gupta, A. Pahuja, N. Bartolovic, F. Yu, E. Garbin, and T. Simon, “SqueezeMe: Efficient Gaussian Avatars for VR,” Dec. 2024, arXiv:2412.15171 [cs] version: 2
work page Pith review arXiv 2024
Show all 104 references
-
[9]
Is Photorealism Important for Perception of Expressive Virtual Humans in Virtual Reality?
K. Zibrek, S. Martin, and R. McDonnell, “Is Photorealism Important for Perception of Expressive Virtual Humans in Virtual Reality?” ACM Trans. Appl. Percept., vol. 16, no. 3, pp. 14:1–14:19, Sep. 2019
2019
-
[10]
The Influence of Avatar Representation on Interpersonal Communication in Virtual Social Environments,
S. Aseeri and V . Interrante, “The Influence of Avatar Representation on Interpersonal Communication in Virtual Social Environments,” IEEE Transactions on Visualization and Computer Graphics , vol. 27, no. 5, pp. 2608–2617, May 2021, conference Name: IEEE Transactions on Visua...
2021
-
[11]
Body, Avatar, and Me: The Presentation and Perception of Self in Social Virtual Reality,
G. Freeman and D. Maloney, “Body, Avatar, and Me: The Presentation and Perception of Self in Social Virtual Reality,” Proc. ACM Hum.- Comput. Interact., vol. 4, no. CSCW3, pp. 239:1–239:27, Jan. 2021
2021
-
[12]
Meeting Your Virtual Twin: Effects of Photorealism and Personaliza- tion on Embodiment, Self-Identification and Perception of Self-Avatars in Virtual Reality,
A. Salagean, E. Crellin, M. Parsons, D. Cosker, and D. Stanton Fraser, “Meeting Your Virtual Twin: Effects of Photorealism and Personaliza- tion on Embodiment, Self-Identification and Perception of Self-Avatars in Virtual Reality,” in Proceedings of the 2023 CHI Conference on ...
2023
-
[13]
A Review on Virtual Reality Skill Training Applications,
B. Xie, H. Liu, R. Alghofaili, Y . Zhang, Y . Jiang, F. D. Lobo, C. Li, W. Li, H. Huang, M. Akdere, C. Mousas, and L.-F. Yu, “A Review on Virtual Reality Skill Training Applications,” Frontiers in Virtual Reality, vol. 2, Apr. 2021, publisher: Frontiers
2021
-
[14]
Survey of conversational agents in health,
J. L. Z. Montenegro, C. A. da Costa, and R. da Rosa Righi, “Survey of conversational agents in health,” Expert Systems with Applications , vol. 129, pp. 56–67, Sep. 2019
2019
-
[15]
Preservice Teachers’ encounter with Social VR – Exploring Virtual Teaching and Learning Processes in Initial Teacher Education
G. Ripka, S. Grafe, and M. E. Latoschik, “Preservice Teachers’ encounter with Social VR – Exploring Virtual Teaching and Learning Processes in Initial Teacher Education.” Association for the Advance- ment of Computing in Education (AACE), Oct. 2020, pp. 549–562
2020
-
[16]
Secrets and Likes: The Drive for Privacy and the Difficulty of Achieving It in the Digital Age,
A. Acquisti, L. Brandimarte, and G. Loewenstein, “Secrets and Likes: The Drive for Privacy and the Difficulty of Achieving It in the Digital Age,” Journal of Consumer Psychology , vol. 30, no. 4, pp. 736–758, 2020
2020
-
[17]
Zooming Into Video Confer- encing Privacy,
D. Kagan, G. F. Alpert, and M. Fire, “Zooming Into Video Confer- encing Privacy,” IEEE Transactions on Computational Social Systems , vol. 11, no. 1, pp. 933–944, Feb. 2024, conference Name: IEEE Transactions on Computational Social Systems
2024
-
[18]
Biometrics in extended reality: a review,
A. Agarwal, R. Ramachandra, S. Venkatesh, and S. R. M. Prasanna, “Biometrics in extended reality: a review,” Discover Artificial Intelli- gence, vol. 4, no. 1, p. 81, Nov. 2024
2024
-
[19]
SoK: Managing risks of linkage attacks on data privacy,
J. Powar and A. R. Beresford, “SoK: Managing risks of linkage attacks on data privacy,” Proceedings on Privacy Enhancing Technologies , 2023
2023
-
[20]
User Identity Linkage on Social Networks: A Review of Modern Techniques and Applications,
C. Senette, M. Siino, and M. Tesconi, “User Identity Linkage on Social Networks: A Review of Modern Techniques and Applications,” IEEE Access, vol. 12, pp. 171 241–171 268, 2024, conference Name: IEEE Access
2024
-
[21]
Authentic volumetric avatars from a phone scan,
C. Cao, T. Simon, J. K. Kim, G. Schwartz, M. Zollhoefer, S.-S. Saito, S. Lombardi, S.-E. Wei, D. Belko, S.-I. Yu, Y . Sheikh, and J. Saragih, “Authentic volumetric avatars from a phone scan,” ACM Trans. Graph., vol. 41, no. 4, pp. 163:1–163:19, Jul. 2022
2022
-
[22]
Deepfake in the Metaverse: Security Implications for Virtual Gaming, Meetings, and Offices,
S. Tariq, A. Abuadbba, and K. Moore, “Deepfake in the Metaverse: Security Implications for Virtual Gaming, Meetings, and Offices,” in Proceedings of the 2nd Workshop on Security Implications of Deepfakes and Cheapfakes , ser. WDC ’23. New York, NY , USA: Association for Comput...
2023
-
[23]
Stay Connected in An Immersive World: Why Teenagers Engage in Social Virtual Reality,
D. Maloney, G. Freeman, and A. Robb, “Stay Connected in An Immersive World: Why Teenagers Engage in Social Virtual Reality,” in Proceedings of the 20th Annual ACM Interaction Design and Children Conference, ser. IDC ’21. New York, NY , USA: Association for Computing Machinery,...
2021
-
[24]
Privacy Research with Marginalized Groups: What We Know, What’s Needed, and What’s Next,
S. Sannon and A. Forte, “Privacy Research with Marginalized Groups: What We Know, What’s Needed, and What’s Next,” Proceedings of the ACM on Human-Computer Interaction , vol. 6, no. CSCW2, pp. 455:1–455:33, Nov. 2022
2022
-
[25]
GHOST—A New Face Swap Approach for Image and Video Domains,
A. Groshev, A. Maltseva, D. Chesakov, A. Kuznetsov, and D. Dim- itrov, “GHOST—A New Face Swap Approach for Image and Video Domains,” IEEE Access, vol. 10, pp. 83 452–83 462, 2022, conference Name: IEEE Access
2022
-
[26]
A Review on Generative Adversarial Networks: Algorithms, Theory, and Applications,
J. Gui, Z. Sun, Y . Wen, D. Tao, and J. Ye, “A Review on Generative Adversarial Networks: Algorithms, Theory, and Applications,” IEEE Transactions on Knowledge and Data Engineering , vol. 35, no. 4, pp. 3313–3332, Apr. 2023, conference Name: IEEE Transactions on Knowledge and ...
2023
-
[27]
Diffusion Models: A Comprehensive Survey of Methods and Applications,
L. Yang, Z. Zhang, Y . Song, S. Hong, R. Xu, Y . Zhao, W. Zhang, B. Cui, and M.-H. Yang, “Diffusion Models: A Comprehensive Survey of Methods and Applications,” ACM Comput. Surv., vol. 56, no. 4, pp. 105:1–105:39, Nov. 2023. 15
2023
-
[28]
Can You Tell Real from Fake Face Images? Perception of Computer- Generated Faces by Humans,
E. Bozkir, C. Riedmiller, A. N. Skodras, G. Kasneci, and E. Kasneci, “Can You Tell Real from Fake Face Images? Perception of Computer- Generated Faces by Humans,” ACM Trans. Appl. Percept. , vol. 22, no. 2, pp. 6:1–6:23, Nov. 2024
2024
-
[29]
Analyzing and Improving the Image Quality of StyleGAN,
T. Karras, S. Laine, M. Aittala, J. Hellsten, J. Lehtinen, and T. Aila, “Analyzing and Improving the Image Quality of StyleGAN,” in Com- puter Vision and Pattern Recognition , 2020, pp. 8110–8119
2020
-
[30]
SimSwap: An Efficient Framework For High Fidelity Face Swapping,
R. Chen, X. Chen, B. Ni, and Y . Ge, “SimSwap: An Efficient Framework For High Fidelity Face Swapping,” in Proceedings of the 28th ACM International Conference on Multimedia, ser. MM ’20. New York, NY , USA: Association for Computing Machinery, Oct. 2020, pp. 2003–2011
2020
-
[31]
Live speech portraits: real-time photore- alistic talking-head animation,
Y . Lu, J. Chai, and X. Cao, “Live speech portraits: real-time photore- alistic talking-head animation,” ACM Trans. Graph., vol. 40, no. 6, pp. 220:1–220:17, Dec. 2021
2021
-
[32]
Neural Radiance Field-based Visual Rendering: A Comprehensive Review,
M. Yao, Y . Huo, Y . Ran, Q. Tian, R. Wang, and H. Wang, “Neural Radiance Field-based Visual Rendering: A Comprehensive Review,” Mar. 2024, arXiv:2404.00714 [cs]
2024 arXiv
-
[33]
Recent advances in 3D Gaussian splatting,
T. Wu, Y .-J. Yuan, L.-X. Zhang, J. Yang, Y .-P. Cao, L.-Q. Yan, and L. Gao, “Recent advances in 3D Gaussian splatting,” Computational Visual Media, vol. 10, no. 4, pp. 613–642, Aug. 2024
2024
-
[34]
VRMM: A V olumetric Relightable Morphable Head Model,
H. Yang, M. Zheng, C. Ma, Y .-K. Lai, P. Wan, and H. Huang, “VRMM: A V olumetric Relightable Morphable Head Model,” in ACM SIGGRAPH 2024 Conference Papers, ser. SIGGRAPH ’24. New York, NY , USA: Association for Computing Machinery, Jul. 2024, pp. 1–11
2024
-
[35]
Acceptance and Influencing Factors of Social Virtual Reality in the Urban Elderly,
D. Shao and I.-J. Lee, “Acceptance and Influencing Factors of Social Virtual Reality in the Urban Elderly,” Sustainability, vol. 12, no. 22, p. 9345, Jan. 2020, number: 22 Publisher: Multidisciplinary Digital Publishing Institute
2020
-
[36]
Social Virtual Reality as a Mental Health Tool: How People Use VRChat to Support Social Connectedness and Wellbeing,
M. T. Deighan, A. Ayobi, and A. A. O’Kane, “Social Virtual Reality as a Mental Health Tool: How People Use VRChat to Support Social Connectedness and Wellbeing,” in Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems , ser. CHI ’23. New York, NY , USA:...
2023
-
[37]
Feelings of presence and perceived social support in social virtual reality plat- forms,
V . van Brakel, M. Barreda- ´Angeles, and T. Hartmann, “Feelings of presence and perceived social support in social virtual reality plat- forms,” Computers in Human Behavior, vol. 139, p. 107523, Feb. 2023
2023
-
[38]
GAN-Based Facial Attribute Manipulation,
Y . Liu, Q. Li, Q. Deng, Z. Sun, and M.-H. Yang, “GAN-Based Facial Attribute Manipulation,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 45, no. 12, pp. 14 590–14 610, Dec. 2023, conference Name: IEEE Transactions on Pattern Analysis and Machine Intelligence
2023
-
[39]
InjectionGAN: Unified Gen- erative Adversarial Networks for Arbitrary Image Attribute Editing,
C. Ding, W. Kang, J. Zhu, and S. Du, “InjectionGAN: Unified Gen- erative Adversarial Networks for Arbitrary Image Attribute Editing,” IEEE Access , vol. 8, pp. 117 726–117 735, 2020, conference Name: IEEE Access
2020
-
[40]
HeadArtist: Text-conditioned 3D Head Generation with Self Score Distillation,
H. Liu, X. Wang, Z. Wan, Y . Shen, Y . Song, J. Liao, and Q. Chen, “HeadArtist: Text-conditioned 3D Head Generation with Self Score Distillation,” in ACM SIGGRAPH 2024 Conference Papers , ser. SIG- GRAPH ’24. New York, NY , USA: Association for Computing Machinery, Jul. 2024, pp. 1–12
2024
-
[41]
Deep Deformable 3D Caricatures with Learned Shape Control,
Y . Jung, W. Jang, S. Kim, J. Yang, X. Tong, and S. Lee, “Deep Deformable 3D Caricatures with Learned Shape Control,” in ACM SIGGRAPH 2022 Conference Proceedings, ser. SIGGRAPH ’22. New York, NY , USA: Association for Computing Machinery, Jul. 2022, pp. 1–9
2022
-
[42]
Universal Facial Encoding of Codec Avatars from VR Headsets,
S. Bai, T.-L. Wang, C. Li, A. Venkatesh, T. Simon, C. Cao, G. Schwartz, J. Saragih, Y . Sheikh, and S.-E. Wei, “Universal Facial Encoding of Codec Avatars from VR Headsets,” ACM Trans. Graph., vol. 43, no. 4, pp. 93:1–93:22, Jul. 2024
2024
-
[43]
Personalized persuasion: Quantifying susceptibility to information exploitation in spear-phishing attacks,
T. Xu, K. Singh, and P. Rajivan, “Personalized persuasion: Quantifying susceptibility to information exploitation in spear-phishing attacks,” Applied Ergonomics, vol. 108, p. 103908, Apr. 2023
2023
-
[44]
Analysis of the communication between colluding applications on modern smartphones,
C. Marforio, H. Ritzdorf, A. Francillon, and S. Capkun, “Analysis of the communication between colluding applications on modern smartphones,” in Proceedings of the 28th Annual Computer Security Applications Conference , ser. ACSAC ’12. New York, NY , USA: Association for Compu...
2012
-
[45]
Online social networks security and privacy: comprehensive review and analysis,
A. K. Jain, S. R. Sahoo, and J. Kaubiyal, “Online social networks security and privacy: comprehensive review and analysis,” Complex & Intelligent Systems, vol. 7, no. 5, pp. 2157–2177, Oct. 2021
2021
-
[46]
Deepfake generation and detection, a survey,
T. Zhang, “Deepfake generation and detection, a survey,” Multimedia Tools and Applications, vol. 81, no. 5, pp. 6259–6276, Feb. 2022
2022
-
[47]
Do (Microtargeted) Deepfakes Have Real Effects on Political Attitudes?
T. Dobber, N. Metoui, D. Trilling, N. Helberger, and C. de Vreese, “Do (Microtargeted) Deepfakes Have Real Effects on Political Attitudes?” The International Journal of Press/Politics , vol. 26, no. 1, pp. 69–91, Jan. 2021, publisher: SAGE Publications Inc
2021
-
[48]
Deepfake: Creation, Purpose, Risks,
A. Busacca and M. A. Monaca, “Deepfake: Creation, Purpose, Risks,” in Innovations and Economic and Social Changes due to Artificial Intelligence: The State of the Art , D. Marino and M. A. Monaca, Eds. Cham: Springer Nature Switzerland, 2023, pp. 55–68
2023
-
[49]
Blur filtration fails to preserve privacy for home-based video conferencing,
C. Neustaedter, S. Greenberg, and M. Boyle, “Blur filtration fails to preserve privacy for home-based video conferencing,” ACM Trans. Comput.-Hum. Interact., vol. 13, no. 1, pp. 1–36, Mar. 2006
2006
-
[50]
Faceless Person Recognition: Privacy Implications in Social Media,
S. J. Oh, R. Benenson, M. Fritz, and B. Schiele, “Faceless Person Recognition: Privacy Implications in Social Media,” in Computer Vision – ECCV 2016, ser. Lecture Notes in Computer Science, B. Leibe, J. Matas, N. Sebe, and M. Welling, Eds. Cham: Springer International Publishi...
2016
-
[51]
Can we still avoid automatic face detection?
M. J. Wilber, V . Shmatikov, and S. Belongie, “Can we still avoid automatic face detection?” in 2016 IEEE Winter Conference on Ap- plications of Computer Vision (WACV) , Mar. 2016, pp. 1–9
2016
-
[52]
Blur vs. Block: Investigating the Effectiveness of Privacy-Enhancing Obfuscation for Images,
Y . Li, N. Vishwamitra, B. P. Knijnenburg, H. Hu, and K. Caine, “Blur vs. Block: Investigating the Effectiveness of Privacy-Enhancing Obfuscation for Images,” in 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW) , Jul. 2017, pp. 1343– 1351, iSSN...
2017
-
[53]
Defeating Image Obfus- cation with Deep Learning,
R. McPherson, R. Shokri, and V . Shmatikov, “Defeating Image Obfus- cation with Deep Learning,” Sep. 2016, arXiv:1609.00408 [cs]
2016 arXiv
-
[54]
ArcFace for Disguised Face Recognition,
J. Deng and S. Zafeririou, “ArcFace for Disguised Face Recognition,” 2019, pp. 0–0
2019
-
[55]
Effective De-identification Generative Adversarial Network for Face Anonymization,
Z. Kuang, H. Liu, J. Yu, A. Tian, L. Wang, J. Fan, and N. Babaguchi, “Effective De-identification Generative Adversarial Network for Face Anonymization,” in Proceedings of the 29th ACM International Confer- ence on Multimedia, ser. MM ’21. New York, NY , USA: Association for C...
2021
-
[56]
Differential Privacy,
C. Dwork, “Differential Privacy,” in Automata, Languages and Pro- gramming, ser. Lecture Notes in Computer Science, M. Bugliesi, B. Preneel, V . Sassone, and I. Wegener, Eds. Berlin, Heidelberg: Springer, 2006, pp. 1–12
2006
-
[57]
What Can We Learn Privately?
S. P. Kasiviswanathan, H. K. Lee, K. Nissim, S. Raskhodnikova, and A. Smith, “What Can We Learn Privately?” SIAM Journal on Computing, vol. 40, no. 3, pp. 793–826, Jan. 2011, publisher: Society for Industrial and Applied Mathematics
2011
-
[58]
Deepfakes for Medical Video De- Identification: Privacy Protection and Diagnostic Information Preser- vation,
B. Zhu, H. Fang, Y . Sui, and L. Li, “Deepfakes for Medical Video De- Identification: Privacy Protection and Diagnostic Information Preser- vation,” in Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society , ser. AIES ’20. New York, NY , USA: Association for Comput...
2020
-
[59]
Practical Digital Dis- guises: Leveraging Face Swaps to Protect Patient Privacy,
E. Wilson, F. Shic, J. Skytta, and E. Jain, “Practical Digital Dis- guises: Leveraging Face Swaps to Protect Patient Privacy,” Apr. 2022, arXiv:2204.03559 [cs]
2022 arXiv
-
[60]
A3GAN: Attribute-Aware Anonymization Networks for Face De-identification,
L. Zhai, Q. Guo, X. Xie, L. Ma, Y . E. Wang, and Y . Liu, “A3GAN: Attribute-Aware Anonymization Networks for Face De-identification,” in Proceedings of the 30th ACM International Conference on Multime- dia, ser. MM ’22. New York, NY , USA: Association for Computing Machinery, ...
2022
-
[61]
Face image de- identification by feature space adversarial perturbation,
H. Xue, B. Liu, X. Yuan, M. Ding, and T. Zhu, “Face image de- identification by feature space adversarial perturbation,” Concurrency and Computation: Practice and Experience , vol. 35, no. 5, p. e7554, 2023
2023
-
[62]
CIAGAN: Conditional Iden- tity Anonymization Generative Adversarial Networks,
M. Maximov, I. Elezi, and L. Leal-Taixe, “CIAGAN: Conditional Iden- tity Anonymization Generative Adversarial Networks,” in Computer Vision and Pattern Recognition , 2020, pp. 5447–5456
2020
-
[63]
Achieving Privacy- Preserving Multi-View Consistency with Advanced 3D-Aware Face De- identification,
J. Cao, B. Liu, Y . Wen, R. Xie, and L. Song, “Achieving Privacy- Preserving Multi-View Consistency with Advanced 3D-Aware Face De- identification,” in Proceedings of the 5th ACM International Conference on Multimedia in Asia , ser. MMAsia ’23. New York, NY , USA: Association ...
2024
-
[64]
IdentityDP: Differential private identification protection for face images,
Y . Wen, B. Liu, M. Ding, R. Xie, and L. Song, “IdentityDP: Differential private identification protection for face images,” Neurocomputing, vol. 501, pp. 197–211, Aug. 2022
2022
-
[65]
Demonstrating Eye Movement Biometrics in Virtual Reality,
D. J. Lohr, S. Johnson, S. Aziz, and O. Komogortsev, “Demonstrating Eye Movement Biometrics in Virtual Reality,” in Proceedings of the 2023 Symposium on Eye Tracking Research and Applications , ser. ETRA ’23. New York, NY , USA: Association for Computing Machinery, May 2023, pp. 1–2
2023
-
[66]
A Secure Authentication Framework to Guarantee the Traceability of Avatars in Metaverse,
K. Yang, Z. Zhang, T. Youliang, and J. Ma, “A Secure Authentication Framework to Guarantee the Traceability of Avatars in Metaverse,” IEEE Transactions on Information Forensics and Security , vol. 18, pp. 3817–3832, 2023, conference Name: IEEE Transactions on Information Foren...
2023
-
[67]
Privacy and security for online social networks: challenges and opportunities,
C. Zhang, J. Sun, X. Zhu, and Y . Fang, “Privacy and security for online social networks: challenges and opportunities,” IEEE Network, vol. 24, no. 4, pp. 13–18, Jul. 2010
2010
-
[68]
Exploring the Privacy Risks of Adversarial VR Game Design,
V . Nair, G. M. Garrido, D. Song, and J. O’Brien, “Exploring the Privacy Risks of Adversarial VR Game Design,” Proceedings on Privacy Enhancing Technologies, 2023
2023
-
[69]
Security and privacy in virtual reality: a literature survey,
A. Giaretta, “Security and privacy in virtual reality: a literature survey,” Virtual Reality, vol. 29, no. 1, p. 10, Dec. 2024
2024
-
[70]
BlendFace: Re-designing Identity Encoders for Face-Swapping,
K. Shiohara, X. Yang, and T. Taketomi, “BlendFace: Re-designing Identity Encoders for Face-Swapping,” 2023, pp. 7634–7644
2023
-
[71]
DDDM-VC: Decoupled De- noising Diffusion Models with Disentangled Representation and Prior Mixup for Verified Robust V oice Conversion,
H.-Y . Choi, S.-H. Lee, and S.-W. Lee, “DDDM-VC: Decoupled De- noising Diffusion Models with Disentangled Representation and Prior Mixup for Verified Robust V oice Conversion,”Proceedings of the AAAI Conference on Artificial Intelligence , vol. 38, no. 16, pp. 17 862– 17 870, ...
2024
-
[72]
Our Data, Ourselves: Privacy Via Distributed Noise Generation,
C. Dwork, K. Kenthapadi, F. McSherry, I. Mironov, and M. Naor, “Our Data, Ourselves: Privacy Via Distributed Noise Generation,” in Advances in Cryptology - EUROCRYPT 2006 , S. Vaudenay, Ed. Berlin, Heidelberg: Springer, 2006, pp. 486–503
2006
-
[73]
Calibrating Noise to Sensitivity in Private Data Analysis,
C. Dwork, F. McSherry, K. Nissim, and A. Smith, “Calibrating Noise to Sensitivity in Private Data Analysis,” in Theory of Cryptography , ser. Lecture Notes in Computer Science, S. Halevi and T. Rabin, Eds. Berlin, Heidelberg: Springer, 2006, pp. 265–284
2006
-
[74]
Privacy integrated queries: an extensible platform for privacy-preserving data analysis,
F. D. McSherry, “Privacy integrated queries: an extensible platform for privacy-preserving data analysis,” in Proceedings of the 2009 ACM SIGMOD International Conference on Management of data , ser. SIGMOD ’09. New York, NY , USA: Association for Computing Machinery, Jun. 2009...
2009
-
[75]
Concentrated Differential Privacy: Simplifi- cations, Extensions, and Lower Bounds,
M. Bun and T. Steinke, “Concentrated Differential Privacy: Simplifi- cations, Extensions, and Lower Bounds,” in Theory of Cryptography , ser. Lecture Notes in Computer Science, M. Hirt and A. Smith, Eds. Berlin, Heidelberg: Springer, 2016, pp. 635–658
2016
-
[76]
Invited Paper: Local Differential Privacy on Metric Spaces: Optimizing the Trade-Off with Utility,
M. Alvim, K. Chatzikokolakis, C. Palamidessi, and A. Pazii, “Invited Paper: Local Differential Privacy on Metric Spaces: Optimizing the Trade-Off with Utility,” in 2018 IEEE 31st Computer Security Foun- dations Symposium (CSF) . Oxford: IEEE, Jul. 2018, pp. 262–267, iSSN: 2374-8303
2018
-
[77]
Simulation of the von mises fisher distribution,
A. T. Wood, “Simulation of the von mises fisher distribution,” Com- munications in Statistics - Simulation and Computation , vol. 23, no. 1, pp. 157–164, Jan. 1994
1994
-
[78]
Differential Privacy for Direc- tional Data,
B. Weggenmann and F. Kerschbaum, “Differential Privacy for Direc- tional Data,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’21. New York, NY , USA: Association for Computing Machinery, Nov. 2021, pp. 1205–1222
2021
-
[79]
DP-V AE: Human-Readable Text Anonymization for Online Reviews with Differentially Private Variational Autoencoders,
B. Weggenmann, V . Rublack, M. Andrejczuk, J. Mattern, and F. Ker- schbaum, “DP-V AE: Human-Readable Text Anonymization for Online Reviews with Differentially Private Variational Autoencoders,” in Pro- ceedings of the ACM Web Conference 2022 , ser. WWW ’22. New York, NY , USA:...
2022
-
[80]
Euler–Rodrigues formula variations, quaternion conjugation and intrinsic connections,
J. S. Dai, “Euler–Rodrigues formula variations, quaternion conjugation and intrinsic connections,” Mechanism and Machine Theory , vol. 92, pp. 144–152, Oct. 2015
2015
-
[81]
Arbitrary Style Transfer in Real-Time With Adaptive Instance Normalization,
X. Huang and S. Belongie, “Arbitrary Style Transfer in Real-Time With Adaptive Instance Normalization,” 2017, pp. 1501–1510
2017
-
[82]
U-Net: Convolutional Networks for Biomedical Image Segmentation,
O. Ronneberger, P. Fischer, and T. Brox, “U-Net: Convolutional Networks for Biomedical Image Segmentation,” in Medical Image Computing and Computer-Assisted Intervention – MICCAI 2015 , ser. Lecture Notes in Computer Science, N. Navab, J. Hornegger, W. M. Wells, and A. F. Fran...
2015
-
[83]
ArcFace: Additive Angular Margin Loss for Deep Face Recognition,
J. Deng, J. Guo, N. Xue, and S. Zafeiriou, “ArcFace: Additive Angular Margin Loss for Deep Face Recognition,” in Computer Vision and Pattern Recognition, 2019, pp. 4690–4699
2019
-
[84]
Codec Avatar Studio: Paired Human Captures for Complete, Driveable, and Generalizable Avatars,
J. Martinez, E. Kim, J. Romero, T. Bagautdinov, S. Saito, S.-I. Yu et al. , “Codec Avatar Studio: Paired Human Captures for Complete, Driveable, and Generalizable Avatars,” Nov. 2024
2024
-
[85]
Autoencoders, Unsupervised Learning, and Deep Archi- tectures,
P. Baldi, “Autoencoders, Unsupervised Learning, and Deep Archi- tectures,” in Proceedings of ICML Workshop on Unsupervised and Transfer Learning . JMLR Workshop and Conference Proceedings, Jun. 2012, pp. 37–49, iSSN: 1938-7228
2012
-
[86]
Auto-Encoding Variational Bayes,
D. P. Kingma and M. Welling, “Auto-Encoding Variational Bayes,” Dec. 2022, arXiv:1312.6114 [stat]
2022 arXiv
-
[87]
Improved Training of Wasserstein GANs,
I. Gulrajani, F. Ahmed, M. Arjovsky, V . Dumoulin, and A. C. Courville, “Improved Training of Wasserstein GANs,” in Advances in Neural Information Processing Systems , vol. 30. Curran Associates, Inc., 2017
2017
-
[88]
Deep Learning Face Attributes in the Wild,
Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep Learning Face Attributes in the Wild,” in 2015 IEEE International Conference on Computer Vision (ICCV), Dec. 2015, pp. 3730–3738, iSSN: 2380-7504
2015
-
[89]
Labeled Faces in the Wild: A Database forStudying Face Recognition in Unconstrained Environments,
G. B. Huang, M. Mattar, T. Berg, and E. Learned-Miller, “Labeled Faces in the Wild: A Database forStudying Face Recognition in Unconstrained Environments,” 2008
2008
-
[90]
Deep face recognition,
O. Parkhi, A. Vedaldi, and A. Zisserman, “Deep face recognition,” BMVC 2015 - Proceedings of the British Machine Vision Conference 2015, 2015, publisher: British Machine Vision Association
2015
-
[91]
HyperExtended LightFace: A Facial Attribute Analysis Framework,
S. I. Serengil and A. Ozpinar, “HyperExtended LightFace: A Facial Attribute Analysis Framework,” in 2021 International Conference on Engineering and Emerging Technologies (ICEET), Oct. 2021, pp. 1–4, iSSN: 2409-2983
2021
-
[92]
Image Pixelization with Differential Privacy,
L. Fan, “Image Pixelization with Differential Privacy,” in Data and Applications Security and Privacy XXXII , F. Kerschbaum and S. Para- boschi, Eds. Cham: Springer International Publishing, 2018, pp. 148– 162
2018
-
[93]
Practical Image Obfuscation with Provable Privacy,
——, “Practical Image Obfuscation with Provable Privacy,” in 2019 IEEE International Conference on Multimedia and Expo (ICME) , Jul. 2019, pp. 784–789, iSSN: 1945-788X
2019
-
[94]
The Algorithmic Foundations of Differential Privacy,
C. Dwork and A. Roth, “The Algorithmic Foundations of Differential Privacy,” Foundations and Trends® in Theoretical Computer Science , vol. 9, no. 3–4, pp. 211–407, Aug. 2014, publisher: Now Publishers, Inc
2014
-
[95]
Guidelines for Eval- uating Differential Privacy Guarantees,
J. Near, D. Darais, N. Lefkovitz, and G. Howarth, “Guidelines for Eval- uating Differential Privacy Guarantees,” National Institute of Standards and Technology, Tech. Rep. NIST Special Publication (SP) 800-226, Mar. 2025
2025
-
[96]
Biometric Performance as a Function of Gallery Size,
L. Friedman, H. Stern, V . Prokopenko, S. Djanian, H. Griffith, and O. Komogortsev, “Biometric Performance as a Function of Gallery Size,” Applied Sciences, vol. 12, no. 21, p. 11144, Jan. 2022, number: 21 Publisher: Multidisciplinary Digital Publishing Institute
2022
-
[97]
Differentially Private Speaker Anonymization,
A. S. Shamsabadi, B. M. L. Srivastava, A. Bellet, N. Vauquier, E. Vincent, M. Maouche, M. Tommasi, and N. Papernot, “Differentially Private Speaker Anonymization,” Proceedings on Privacy Enhancing Technologies, 2023
2023
-
[98]
De-Anonymizing Avatars in Virtual Reality: Attacks and Countermeasures,
Y . Meng, Y . Zhan, J. Li, S. Du, H. Zhu, and X. Shen, “De-Anonymizing Avatars in Virtual Reality: Attacks and Countermeasures,” IEEE Trans- actions on Mobile Computing, vol. 23, no. 12, pp. 13 342–13 357, Dec. 2024
2024
-
[99]
Deep Mo- tion Masking for Secure, Usable, and Scalable Real-Time Anonymiza- tion of Ecological Virtual Reality Motion Data,
V . Nair, W. Guo, J. F. O’Brien, L. Rosenberg, and D. Song, “Deep Mo- tion Masking for Secure, Usable, and Scalable Real-Time Anonymiza- tion of Ecological Virtual Reality Motion Data,” in 2024 IEEE Con- ference on Virtual Reality and 3D User Interfaces Abstracts and Workshops...
2024
-
[100]
Privacy-Preserving Gaze Data Streaming in Immersive Interactive Virtual Reality: Robustness and User Experience,
E. Wilson, A. Ibragimov, M. J. Proulx, S. D. Tetali, K. Butler, and E. Jain, “Privacy-Preserving Gaze Data Streaming in Immersive Interactive Virtual Reality: Robustness and User Experience,” IEEE Transactions on Visualization and Computer Graphics , vol. 30, no. 5, pp. 2257–2...
2024
-
[101]
Speaker Anonymization Using Neural Audio Codec Language Models,
M. Panariello, F. Nespoli, M. Todisco, and N. Evans, “Speaker Anonymization Using Neural Audio Codec Language Models,” in ICASSP 2024 - 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) , Apr. 2024, pp. 4725–4729, iSSN: 2379-190X
2024
-
[102]
Robust De-anonymization of Large Sparse Datasets,
A. Narayanan and V . Shmatikov, “Robust De-anonymization of Large Sparse Datasets,” in 2008 IEEE Symposium on Security and Privacy (sp 2008), May 2008, pp. 111–125, iSSN: 2375-1207
2008
-
[103]
BehaVR: User Identification Based on VR Sensor Data,
I. Jarin, Y . Duan, R. Trimananda, H. Cui, S. Elmalaki, and A. Markopoulou, “BehaVR: User Identification Based on VR Sensor Data,” 2025
2025
-
[104]
Toward Practical Privacy in XR: Empirical Analysis of Multimodal Anonymization Mechanisms,
A. Ibragimov, E. Wilson, K. R. B. Butler, and E. Jain, “Toward Practical Privacy in XR: Empirical Analysis of Multimodal Anonymization Mechanisms,” Jun. 2025, arXiv:2506.13882 [cs]
2025
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.