Pith. sign in

REVIEW 3 major objections 3 minor 224 references

Face De-Identification: A Domain-Centric Survey from Capture to Processing

T0 review · 3 major / 3 minor · reviewed 2026-08-01 · deepseek-v4-flash

Pith's one-line read This survey argues that face de-identification is best understood as a three-domain problem—physical, sensor, and digital—and that fragmented evaluation, not a lack of methods, is the field's main obstacle.

desk verdict Comprehensive survey with a genuinely useful taxonomy; the evaluation-fragmentation analysis is the strongest part, and the corpus-bias concern is real but not disqualifying. read the letter →

arxiv 2607.25926 v1 pith:KNKNBDCR submitted 2026-07-28 cs.CV cs.AI

classification cs.CVcs.AI
keywords facede-identificationprivacypreservationdomain-centrictaxonomyphysical-domainattackssensor-domainopticsevaluationprotocolsrecognitionsurvey
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey tries to establish that face de-identification is best understood as a problem distributed across the entire image-acquisition pipeline, not just a post-processing task. It organizes 112 methods into three domains—physical (altering the subject before capture), sensor (encoding privacy in optics or low-resolution capture), and digital (post-capture processing)—and claims this is the first unified treatment of all three. The paper's central diagnosis is that the field's evaluation is fragmented: physical methods report privacy almost exclusively, sensor methods report privacy plus utility, and digital methods are heterogeneous, with 60 of 69 metrics used by fewer than 10% of papers. A sympathetic reader would care because the paper argues this fragmentation, not a shortage of methods, is what blocks reliable progress, and it lays out what standardized benchmarks would need to measure.

What carries the argument

The organizing device is a domain-centric taxonomy with three classes—physical, sensor, and digital—defined by where in the imaging pipeline the privacy transformation occurs (before, during, or after capture). Carrying the argument is the cross-domain interaction analysis: an intervention at an earlier stage changes what later stages must do (e.g., physical perturbations must survive the ISP pipeline; a strong sensor-phase mask can be paired with a digital refiner), so the choice of domain is really a choice of trust model. The paper also formalizes De-ID as joint maximization of privacy, utility, visual quality, and optional reversibility, which anchors the evaluation-protocol analysis.

What would settle it

A reproducible systematic review (multiple databases, snowballing, independent screening) that uncovers many missing physical or sensor methods would shift the reported 23/10/79 domain split and the Fig. 9 evaluation statistics; if the omissions are large enough, the 'first unified survey' claim and the fragmentation diagnosis lose force. Conversely, a standardized benchmark on which physical methods demonstrably preserve utility would show the 'physical reports privacy only' pattern is a reporting artifact rather than an inherent limitation.

Watch

Extended reading notes

Core claim

The paper's central claim is that every face de-identification method can be located at one of three points in the acquisition pipeline—before capture (physical), during capture (sensor), or after capture (digital)—and that this placement determines the method's trust model, its privacy-utility trade-offs, and its evaluation practice. Reviewing 112 methods, the authors find that evaluation practice is fragmented across domains and metrics: physical-domain methods report privacy metrics only, sensor-domain methods report privacy and utility together, and digital methods vary widely, with only three metrics (attack success rate, SSIM, FID) used by more than a quarter of papers. On the authors'

Load-bearing premise

The paper's field-wide conclusions rest on the assumption that its 112-method corpus, assembled from a keyword-based literature search with a subjective timeline-selection rule, is representative of face De-ID research as a whole.

Editorial extensions

If this is right

  • If the taxonomy is right, comparisons of face De-ID methods that ignore the capture stage will misattribute differences in performance to algorithm choice when they actually stem from where the identity signal is suppressed.
  • If the evaluation-fragmentation diagnosis is right, reported success rates across papers are not comparable until a common protocol (datasets, thresholds, metric families) is adopted.
  • The finding that sensor-domain methods are the only group that consistently reports both privacy and utility supports the paper's claim that privacy-by-design at capture offers the most balanced trade-off.
  • The pattern that physical methods report privacy only suggests that physical De-ID research is still attack-centric; closing the utility gap there is a concrete next step.
  • Standardized benchmarks that jointly measure privacy, utility, and quality would let the field move from per-method claims to cross-domain comparison, which the paper identifies as the primary bottleneck.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editor's extension: the domain-centric taxonomy predicts that cross-domain co-design—e.g., a physical perturbation optimized through a differentiable camera pipeline and paired with a digital utility-restoring refiner—will outperform single-domain methods once benchmarks include realistic capture conditions.
  • Editor's extension: the paper's 'choice of domain is a choice of trust model' framing implies that evaluation protocols should record where raw identity first exists in digital form, a variable the survey does not itself tabulate.
  • Editor's extension: the fragmentation statistics in Table 3 could be condensed into a per-domain metric-adoption entropy; computed from the survey's own data, that index would give a reproducible number for how close the field is to standardization.
  • Editor's extension: because the survey notes fairness under optical and physical distortion is underexplored, a standardized benchmark stratified by race, gender, and age would likely reorder current methods' reported privacy-utility trade-offs.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 3 minor

Summary. The paper presents a domain-centric survey of face de-identification, organizing 112 methods into physical, sensor, and digital domains according to where in the acquisition pipeline privacy transformation occurs. It proposes a common framework with four objectives (privacy, utility, visual quality, reversibility), reviews methodologies in each domain, tabulates evaluation datasets and metrics, and diagnoses severe fragmentation in evaluation protocols. The paper claims to be the first unified treatment spanning capture to processing and ends with open problems and future directions.

Significance. If the corpus and evaluation analysis are reliable, this survey provides a useful organizing framework for a fragmented field. The domain-centric taxonomy is natural and the compilation in Table 3, together with the evaluation-protocol analysis in Section 4 and Fig. 9, constitutes a substantive contribution. The authors also provide a project page, which supports reproducibility of the resource itself. The central diagnostic claim—that physical-domain methods measure privacy only, sensor-domain methods measure privacy plus utility, and digital-domain methods are heterogeneous—would be practically important. However, this claim rests on a non-reproducible literature selection, and the manuscript contains an internal inconsistency between the text and its own table/figures.

major comments (3)
  1. [Sec. 2, Fig. 2, Table 3] The corpus underlying the central claims is not reproducibly constructed. The text reports that methods were collected via Google Scholar using only three keyword queries ('face de-identification', 'face privacy preserving', 'face adversarial attack') with no search date, no hit counts, no deduplication procedure, and no screening protocol. The timeline criterion in Sec. 2 requires 'at least two of four' subjective conditions. This makes the 112-method corpus, and therefore the Fig. 9 fragmentation statistics and the 'first unified' framing, non-auditable. In particular, the query 'face adversarial attack' will preferentially retrieve attack-oriented works and may miss physical/sensor De-ID papers framed as privacy-preserving imaging or utility-preserving capture. I do not doubt the individual method descriptions, but the literature-coverage claim is load-bearing for the survey's main di
  2. [Sec. 4.1, Sec. 4.3 vs Fig. 9, Table 3] The text's central diagnosis is internally inconsistent with the authors' own data. Section 4.1 states that 'physical-domain methods (23 techniques) report privacy exclusively', and Section 4.3 repeats that 'all 23 physical-domain methods report privacy metrics exclusively'. Yet Fig. 9 reports physical-domain quality reporting at 17%, and Table 3 lists quality metrics for at least four physical methods: VLA [114] reports Similarity/Distance/SelfDis, SASMask [67] reports SSIM, ARA [73] reports BRISQUE/NIQE, and Optical De-ID [53] reports RMSE. This discrepancy directly affects the paper's headline evaluation-fragmentation conclusion. Please correct either the text, the table, or the figure, and ensure the same claim is not restated in Sec. 5.
  3. [Sec. 4.2, Fig. 9] The metric classification underlying Fig. 9 needs justification. For example, 'Similarity, Distance, SelfDis' in the VLA row of Table 3 appears under the Quality column, but cosine similarity and L2 distance are embedding-space privacy metrics in Sec. 4.2.1. Similarly, some methods listed as reporting 'Privacy' use only 'Subjective' or 'k-anonymity' without an FR metric. Since Fig. 9 is the primary evidence for evaluation fragmentation, the classification of each metric into Privacy/Utility/Quality and the counting rule (methods vs. metric instances) should be stated explicitly.
minor comments (3)
  1. [Sec. 1, Table 1] The comparison in Table 1 is useful, but some entries may be debatable (e.g., [26] 'Privacy–enhancing face biometrics' is marked as covering sensor and digital but not physical). A sentence justifying the table's coding criteria would help readers assess the novelty claim.
  2. [References] Reference [35] contains a typo: 'IEEE TP AMI' should be 'IEEE TPAMI'. Please also check venue capitalization for consistency.
  3. [Sec. 4.1, Table 2] The text says 66 distinct datasets appear in Table 3, but only 29 are distilled in Table 2. Since no list of the remaining 37 datasets is provided, consider adding a supplementary table or pointing to the project page for the full dataset list.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the survey's taxonomy and evaluation analysis are descriptive and do not reduce to any fitted parameter or self-cited premise.

full rationale

This is a survey paper whose central claims are (1) a domain-centric taxonomy (physical/sensor/digital) and (2) a meta-analysis of evaluation fragmentation. Both are organizational and descriptive rather than derived from a fitted model or from the authors' own methods. Equation (1) is a problem-formulation template, not an estimation or prediction step. The 112-method corpus and Fig. 9 statistics are compiled from the surveyed papers' own reported metrics, so the fragmentation finding is a summary of external reports rather than a circular derivation. The paper's self-citations (e.g., ProjAttacker [18], ARA [73], WeakenDiff [11], OBF [168], DeID-rPPG [139]) appear as surveyed methods, dataset entries, or illustrative examples; they are not invoked as load-bearing theorems or as justification for the taxonomy. For instance, Sec. 2.5 cites ProjAttacker alongside the external AT3D to illustrate physical-sensor co-design, but the survey's validity does not depend on the correctness of that specific self-cited method. The main limitation is corpus representativeness: the selection criteria in Sec. 2 and the Google Scholar queries in Fig. 2 are subjective and not fully reproducible, which is a coverage/validity concern, not circularity. No step reduces to its own input by construction.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The survey introduces no fitted parameters and no new physical or conceptual entities. Its conclusions rest on the validity of its organizing taxonomy, the representativeness of its literature corpus, and background assumptions borrowed from the cited privacy and face-recognition literature.

assumptions (4)
  • domain assumption The physical/sensor/digital trichotomy is an exhaustive and meaningful partition of face De-ID methods.
    Section 2.4 defines the taxonomy by where the privacy transformation occurs; the survey's central organizing claim depends on this partition being valid and complete.
  • domain assumption The 112-method corpus is representative of the face De-ID literature.
    Section 2 and Fig. 2 describe Google Scholar keyword collection and subjective timeline criteria; coverage bias would weaken the evaluation-fragmentation analysis.
  • domain assumption A strong face recognizer is the appropriate primary adversary for evaluating de-identification.
    Section 2.2 states that most De-ID approaches assume a face-recognition adversary; this assumption shapes the privacy metrics catalogued in Section 4.2.
  • domain assumption Formal privacy notions cited from prior work (k-anonymity, differential privacy) are correct as stated.
    The survey's descriptions of guarantees (e.g., recognition accuracy <= 1/k for k-Same, Section 3.3.2) rely on established results from cited literature rather than re-deriving them.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Face De-Identification: A Domain-Centric Survey from Capture to Processing." pith.science (2026). https://pith.science/paper/KNKNBDCR

@misc{pith2026260725926,
  author       = {Pith},
  title        = {Pith review of: Face De-Identification: A Domain-Centric Survey from Capture to Processing},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/KNKNBDCR}},
  note         = {Machine review of arXiv:2607.25926}
}
read the original abstract

Face de-identification (De-ID) aims to remove or conceal personally identifiable facial features in images or videos to prevent identity recognition while preserving utility for downstream tasks. With the rising emphasis on data privacy and responsible AI, face De-ID has emerged as an active research area spanning computer vision and privacy-preserving communities. Early approaches, and many contemporary ones, operate in the digital domain by modifying pixel-level or appearance-level features through post-capture processing. Recent advances extend face De-ID beyond post-processing by integrating privacy mechanisms directly into sensors during image acquisition, bridging sensing systems and downstream vision algorithms. In parallel, physical-domain methods explore wearable accessories and materials that conceal identity information in real-world environments prior to capture. In this survey, we present the first unified overview that spans the full data acquisition pipeline, encompassing the physical, sensor, and digital domains. Through this domain-centric lens, we systematically analyze current methodologies, technical progress, and the distinct challenges inherent to each stage. We then review and organize existing evaluation protocols, examining current practices and highlighting the critical need for standardized, comprehensive benchmarks. Finally, we identify key open problems and outline emerging research directions to guide future work in this rapidly evolving field. To support ongoing research, we maintain a project page that organizes relevant literature with collected datasets and open source code: https://github.com/CV-AC/Awesome-FaceDe-ID.

Figures

Figures reproduced from arXiv: 2607.25926 by the authors.

Figure 1
Figure 1. Overall perspective of this face De-ID survey paper. The process begins in physical world, where identity cues are modified directly on the subject through adversarial wearables, cosmetics, or projection-based interventions. It then transitions through the sensor-capturing stage, where privacy-preserving optics and computational imaging en￾code De-ID at the sensor level. Finally, in digital space, post￾capture algor… view at source ↗
Figure 2
Figure 2. Cumulative growth of face De-ID methods across domains. Data collected via Google Scholar using key￾words: ”face de-identification”, ”face privacy preserving”, and ”face adversarial attack”. This paper provides a unique and up-to-date survey of the rapidly growing area of face De-ID ( [PITH_FULL_IMAGE:figures/full_fig_p002_2.png] view at source ↗
Figure 3
Figure 3. Conceptual (left) and historical (right) overview of face De-ID, clarifying the paper’s domain-centric taxonomy. 2.2 Face De-ID vs. Face Identification Face identification maximizes the discriminability of identity-bearing cues, whereas face De-ID suppresses those cues while preserving non-identity information. Most face De-ID approaches therefore assume a strong face recogni￾tion (FR) adversary as their primary thr… view at source ↗
Figures from the paper (6 more)
Figure 4
Figure 4. Figure 4: Hierarchical taxonomy of face De-ID methodolo￾gies. Each domain is further categorized into specific sub￾classes based on their technical approaches. lighting that creates naturally-appearing yet recognition￾disrupting effects) [PITH_FULL_IMAGE:figures/full_fig_p004_4.png]
Figure 5
Figure 5. Figure 5: Sample figures of representative physical-domain face De-ID methods. Wearable adversarial accessories: (a), (b), (d), (e), (f), (g). Projected perturbations: (c), (i). Adversarial illumination: (h). GAN [58], StyleGAN [59], [60]), constraining them toward natural face …
Figure 6
Figure 6. Figure 6: Taxonomy of sensor-domain face De-ID paradigms. (a) Optical privacy-preserving designs encode privacy in the camera optics: a point source is shaped by a lens and phase mask into a point spread function (PSF) recorded by the sensor, yielding a de-identified image while…
Figure 7
Figure 7. Figure 7: Traditional digital-domain face De-ID approaches. (a) Handcrafted filters, including blur, pixelization, and mask￾ing, uniformly reduce the recognizability of the facial region, alongside spatially adaptive filtering (EmotionPreserve [81]) that selectively blurs identi…
Figure 8
Figure 8. Figure 8: Architectural paradigms of contemporary digital-domain face De-ID. (Left) Adversarial perturbation-based meth￾ods inject imperceptible noise at the pixel level to mislead face recognizers. (Middle) GAN-based generative approaches synthesize identity-removed faces throu…
Figure 9
Figure 9. Figure 9: Evaluation-protocol fragmentation across the surveyed face De-ID methods. Left: per-domain reporting rates of the three evaluation aspects. Physical-domain methods (n=23) report privacy universally but utility never and quality rarely; sensor-domain methods report priv…

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

224 extracted references · 5 linked inside Pith

  1. [114]

    Vla: A practical visible light-based attack on face recognition systems in physical world,

    M. Shen, Z. Liao, L. Zhu, K. Xu, and X. Du, “Vla: A practical visible light-based attack on face recognition systems in physical world,”ACM IMWUT, vol. 3, no. 3, pp. 1–19, 2019. 9, 11

  2. [67]

    Stealthy physical masked face recognition attack via adversarial style optimization,

    H. Gong, M. Dong, S. Ma, S. Camtepe, S. Nepal, and C. Xu, “Stealthy physical masked face recognition attack via adversarial style optimization,”TMM, vol. 26, pp. 5014–5025, 2023. 5, 11

  3. [73]

    Adversarial relighting against face recognition,

    Q. Zhang, Q. Guo, R. Gao, F. Juefei-Xu, H. Yu, and W. Feng, “Adversarial relighting against face recognition,”TIFS, vol. 19, pp. 9145–9157, 2024. 5, 11, 13

  4. [53]

    Physical-world optical adversarial attacks on 3d face recognition,

    Y. Li, Y. Li, X. Dai, S. Guo, and B. Xiao, “Physical-world optical adversarial attacks on 3d face recognition,” inCVPR, 2023, pp. 24 699–24 708. 5, 6, 11

  5. [1]

    Face recognition: A literature survey,

    W. Zhao, R. Chellappa, P . J. Phillips, and A. Rosenfeld, “Face recognition: A literature survey,”CSUR, vol. 35, no. 4, pp. 399– 458, 2003. 1, 15

  6. [2]

    3d face recognition: Two decades of progress and prospects,

    Y. Guo, H. Wang, L. Wang, Y. Lei, L. Liu, and M. Bennamoun, “3d face recognition: Two decades of progress and prospects,”CSUR, vol. 56, no. 3, pp. 1–39, 2023. 1

  7. [3]

    Privacy-preserving face recognition using trainable feature subtraction,

    Y. Mi, Z. Zhong, Y. Huang, J. Ji, J. Xu, J. Wang, S. Wang, S. Ding, and S. Zhou, “Privacy-preserving face recognition using trainable feature subtraction,” inCVPR, 2024, pp. 297–307. 1

  8. [4]

    Toward a privacy-preserving face recognition system: A survey of leakages and solutions,

    L. Laishram, M. Shaheryar, J. T. Lee, and S. K. Jung, “Toward a privacy-preserving face recognition system: A survey of leakages and solutions,”CSUR, vol. 57, no. 6, pp. 1–38, 2025. 1, 2, 15

Show all 224 references
  1. [5]

    Regulation (eu) 2024/1689 of the european parliament and of the council of 13 june 2024 laying down harmonised rules on artificial intelligence,

    European Union, “Regulation (eu) 2024/1689 of the european parliament and of the council of 13 june 2024 laying down harmonised rules on artificial intelligence,”Official Journal of the European Union, vol. L, no. 2024/1689, 2024, entered into force: 2 August 2024. [Online]. A...

  2. [6]

    A digital mask to safeguard patient privacy,

    Y. Yang, J. Lyu, R. Wang, Q. Wen, L. Zhao, W. Chen, S. Bi, J. Meng, K. Mao, Y. Xiaoet al., “A digital mask to safeguard patient privacy,”Nature Medicine, vol. 28, no. 9, pp. 1883–1892,

  3. [7]

    Disguise without disruption: Utility-preserving face de- identification,

    Z. Cai, Z. Gao, B. Planche, M. Zheng, T. Chen, M. S. Asif, and Z. Wu, “Disguise without disruption: Utility-preserving face de- identification,” inAAAI, vol. 38, no. 2, 2024, pp. 918–926. 1, 9, 12, 13

  4. [8]

    Techniques for addressing funda- mental privacy and disruption tradeoffs in awareness support systems,

    S. E. Hudson and I. Smith, “Techniques for addressing funda- mental privacy and disruption tradeoffs in awareness support systems,” inACM CSCW, 1996, pp. 248–257. 1, 2, 7, 11

  5. [9]

    Preserving privacy by de-identifying face images,

    E. M. Newton, L. Sweeney, and B. Malin, “Preserving privacy by de-identifying face images,”IEEE TKDE, vol. 17, no. 2, pp. 232–243, 2005. 1, 2, 7, 11, 13

  6. [10]

    Adv- attribute: Inconspicuous and transferable adversarial attack on face recognition,

    S. Jia, B. Yin, T. Yao, S. Ding, C. Shen, X. Yang, and C. Ma, “Adv- attribute: Inconspicuous and transferable adversarial attack on face recognition,” inNIPS, 2022, pp. 34 136–34 147. 1, 8, 9, 11

  7. [11]

    Enhancing facial privacy protection via weakening diffusion purification,

    A. Salar, Q. Liu, Y. Tian, and G. Zhao, “Enhancing facial privacy protection via weakening diffusion purification,” inCVPR, 2025, pp. 8235–8244. 1, 8, 11, 14

  8. [12]

    A3gan: Attribute-aware anonymization networks for face de- identification,

    L. Zhai, Q. Guo, X. Xie, L. Ma, Y. E. Wang, and Y. Liu, “A3gan: Attribute-aware anonymization networks for face de- identification,” inACM MM, 2022, pp. 5303–5313. 1, 9, 12

  9. [13]

    Face anonymization made simple,

    H.-W. Kung, T. Varanka, S. Saha, T. Sim, and N. Sebe, “Face anonymization made simple,” inWACV. IEEE, 2025, pp. 1040–

  10. [14]

    Privacy preserving optics for miniature vision sensors,

    F. Pittaluga and S. J. Koppal, “Privacy preserving optics for miniature vision sensors,” inCVPR, 2015, pp. 314–324. 1, 2, 6, 11

  11. [15]

    Privacy- preserving optics for enhancing protection in face de- identification,

    J. Lopez, C. Hinojosa, H. Arguello, and B. Ghanem, “Privacy- preserving optics for enhancing protection in face de- identification,” inCVPR, 2024, pp. 12 120–12 129. 1, 4, 6, 11

  12. [16]

    Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,

    M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,” inACM SIGSAC, 2016, pp. 1528–1540. 1, 2, 4, 5, 11, 13

  13. [17]

    Adv-makeup: A new imperceptible and transferable attack on face recognition,

    B. Yin, W. Wang, T. Yao, J. Guo, Z. Kong, S. Ding, J. Li, and C. Liu, “Adv-makeup: A new imperceptible and transferable attack on face recognition,” inIJCAI, 2021, pp. 1–7. 1, 5, 6, 11

  14. [18]

    Projattacker: A configurable physical adversarial attack for face recognition via projector,

    Y. Liu, H. Wei, C. Jia, R. Xiao, W. Ruan, X. Wei, J. T. Zhou, and Z. Wang, “Projattacker: A configurable physical adversarial attack for face recognition via projector,” inCVPR, 2025, pp. 21 248–21 257. 1, 4, 5, 6, 11, 13

  15. [19]

    Privacy intelligence: A survey on image privacy in online social networks,

    C. Liu, T. Zhu, J. Zhang, and W. Zhou, “Privacy intelligence: A survey on image privacy in online social networks,”CSUR, vol. 55, no. 8, pp. 1–35, 2022. 2, 15

  16. [20]

    Benchmarking 3d face de-identification with preserving facial attributes,

    K. H. Cheng, Z. Yu, H. Chen, and G. Zhao, “Benchmarking 3d face de-identification with preserving facial attributes,” inICIP. IEEE, 2022, pp. 656–660. 2

  17. [21]

    Presentation-level privacy protection techniques for automated face recognition—a survey,

    M. R. Hasan, R. Guest, and F. Deravi, “Presentation-level privacy protection techniques for automated face recognition—a survey,” CSUR, vol. 55, no. 13s, pp. 1–27, 2023. 2

  18. [22]

    Face de-identification: State-of-the-art methods and comparative studies,

    J. Cao, X. Chen, B. Liu, M. Ding, R. Xie, L. Song, Z. Li, and W. Zhang, “Face de-identification: State-of-the-art methods and comparative studies,”arXiv preprint arXiv:2411.09863, 2024. 2

  19. [23]

    Visual privacy protection methods: A survey,

    J. R. Padilla-L ´opez, A. A. Chaaraoui, and F. Fl ´orez-Revuelta, “Visual privacy protection methods: A survey,”Expert Systems with Applications, vol. 42, no. 9, pp. 4177–4195, 2015. 2

  20. [24]

    An overview of face de-identification in still images and videos,

    S. Ribaric and N. Pavesic, “An overview of face de-identification in still images and videos,” inFG, vol. 4. IEEE, 2015, pp. 1–6. 2

  21. [25]

    De-identification for privacy protection in multimedia content: A survey,

    S. Ribaric, A. Ariyaeeinia, and N. Pavesic, “De-identification for privacy protection in multimedia content: A survey,”Signal Processing: Image Communication, vol. 47, pp. 131–151, 2016. 2

  22. [26]

    Privacy–enhancing face biomet- rics: A comprehensive survey,

    B. Meden, P . Rot, P . Terh¨orst, N. Damer, A. Kuijper, W. J. Scheirer, A. Ross, P . Peer, and V . ˇStruc, “Privacy–enhancing face biomet- rics: A comprehensive survey,”TIFS, vol. 16, pp. 4147–4183, 2021. 2

  23. [27]

    Person de- identification: A comprehensive review of methods, datasets, applications, and ethical aspects along with new dimensions,

    W. Khan, L. Topham, U. Khayam, S. Ortega-Martorell, P . Heather, D. Ansell, D. Al-Jumeily, and A. Hussain, “Person de- identification: A comprehensive review of methods, datasets, applications, and ethical aspects along with new dimensions,” IEEE TBBIS, pp. 293–312, 2024. 2, 15

  24. [28]

    Y. Wen, B. Liu, L. Song, J. Cao, and R. Xie,Face De-identification: Safeguarding Identities in the Digital Era. Springer, 2024. 2

  25. [29]

    Faces in the fog: A deep dive into face de-identification techniques and their comparative analysis,

    S. Goswami, S. K. Paul, S. Jawlia, and A. Goel, “Faces in the fog: A deep dive into face de-identification techniques and their comparative analysis,” inDICCT. IEEE, 2025, pp. 603–608. 2

  26. [30]

    Privacy-driven faces: A survey on generative facial de-identification,

    S. Park, H. Kim, S.-K. Choi, T. Kim, and E. Park, “Privacy-driven faces: A survey on generative facial de-identification,” inWSIDC, 2025, pp. 27–32. 2

  27. [31]

    Eigenfaces for recognition,

    M. Turk and A. Pentland, “Eigenfaces for recognition,”Journal of Cognitive Neuroscience, vol. 3, no. 1, pp. 71–86, 1991. 2

  28. [32]

    Towards effective adversarial textured 3d meshes on physical face recognition,

    X. Yang, C. Liu, L. Xu, Y. Wang, Y. Dong, N. Chen, H. Su, and J. Zhu, “Towards effective adversarial textured 3d meshes on physical face recognition,” inCVPR, 2023, pp. 4119–4128. 2, 3, 4, 5, 6, 11, 13

  29. [33]

    G²face: High-fidelity reversible face anonymization via SUBMIT TO IEEE TRANSACTIONS ON PATTERN ANAL YSIS AND MACHINE INTELLIGENCE 17 generative and geometric priors,

    H. Yang, X. Xu, C. Xu, H. Zhang, J. Qin, Y. Wang, P .-A. Heng, and S. He, “G²face: High-fidelity reversible face anonymization via SUBMIT TO IEEE TRANSACTIONS ON PATTERN ANAL YSIS AND MACHINE INTELLIGENCE 17 generative and geometric priors,”TIFS, vol. 19, pp. 8773–8785,

  30. [34]

    A survey on differential privacy for unstructured data content,

    Y. Zhao and J. Chen, “A survey on differential privacy for unstructured data content,”CSUR, vol. 54, no. 10s, pp. 1–28, 2022. 2

  31. [35]

    Federated learning for generalization, robustness, fairness: A survey and benchmark,

    W. Huang, M. Ye, Z. Shi, G. Wan, H. Li, B. Du, and Q. Yang, “Federated learning for generalization, robustness, fairness: A survey and benchmark,”IEEE TP AMI, vol. 46, no. 12, pp. 9387– 9406, 2024. 2

  32. [36]

    Tamarin: Verifi- cation of large-scale, real-world, cryptographic protocols,

    D. Basin, C. Cremers, J. Dreier, and R. Sasse, “Tamarin: Verifi- cation of large-scale, real-world, cryptographic protocols,”IEEE Security & Privacy, vol. 20, no. 3, pp. 24–32, 2022. 2

  33. [37]

    Balancing privacy and performance: A many-in-one approach for image anonymization,

    X. Jia, J. Du, H. Wei, R. Xue, Z. Wang, H. Zhu, and J. Chen, “Balancing privacy and performance: A many-in-one approach for image anonymization,” inAAAI, vol. 39, no. 17, 2025, pp. 17 608–17 616. 2

  34. [38]

    Anonymization techniques for behavioral biometric data: A survey,

    S. Hanisch, P . Arias-Cabarcos, J. Parra-Arnau, and T. Strufe, “Anonymization techniques for behavioral biometric data: A survey,”CSUR, vol. 57, no. 11, pp. 1–54, 2025. 2, 15

  35. [39]

    Facenet: A unified embedding for face recognition and clustering,

    F. Schroff, D. Kalenichenko, and J. Philbin, “Facenet: A unified embedding for face recognition and clustering,” inCVPR, 2015, pp. 815–823. 3

  36. [40]

    Sphereface: Deep hypersphere embedding for face recognition,

    W. Liu, Y. Wen, Z. Yu, M. Li, B. Raj, and L. Song, “Sphereface: Deep hypersphere embedding for face recognition,” inCVPR, 2017, pp. 212–220. 3

  37. [41]

    Arcface: Additive angular margin loss for deep face recognition,

    J. Deng, J. Guo, N. Xue, and S. Zafeiriou, “Arcface: Additive angular margin loss for deep face recognition,” inCVPR, 2019, pp. 4690–4699. 3

  38. [42]

    Adaface: Quality adaptive margin for face recognition,

    M. Kim, A. K. Jain, and X. Liu, “Adaface: Quality adaptive margin for face recognition,” inCVPR, 2022, pp. 18 750–18 759. 3

  39. [43]

    Reti- naface: Single-shot multi-level face localisation in the wild,

    J. Deng, J. Guo, E. Ververas, I. Kotsia, and S. Zafeiriou, “Reti- naface: Single-shot multi-level face localisation in the wild,” in CVPR, 2020, pp. 5203–5212. 3

  40. [44]

    Opticaldr: A deep optical imaging model for privacy-protective depression recognition,

    Y. Pan, J. Jiang, K. Jiang, Z. Wu, K. Yu, and X. Liu, “Opticaldr: A deep optical imaging model for privacy-protective depression recognition,” inCVPR, 2024, pp. 1303–1312. 3, 6, 11, 13, 15

  41. [45]

    Ciagan: Conditional identity anonymization generative adversarial networks,

    M. Maximov, I. Elezi, and L. Leal-Taix ´e, “Ciagan: Conditional identity anonymization generative adversarial networks,” in CVPR, 2020, pp. 5447–5456. 3, 12

  42. [46]

    Generative adver- sarial nets,

    I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde- Farley, S. Ozair, A. Courville, and Y. Bengio, “Generative adver- sarial nets,” inNIPS, 2014, pp. 1–9. 3, 5

  43. [47]

    Denoising diffusion probabilistic models,

    J. Ho, A. Jain, and P . Abbeel, “Denoising diffusion probabilistic models,” inNIPS, 2020, pp. 6840–6851. 3

  44. [48]

    Privacy- preserving human activity recognition from extreme low reso- lution,

    M. Ryoo, B. Rothrock, C. Fleming, and H. J. Yang, “Privacy- preserving human activity recognition from extreme low reso- lution,” inAAAI, vol. 31, no. 1, 2017, pp. 1–8. 4, 6, 7, 11

  45. [49]

    Advhat: Real-world adversarial attack on arcface face id system,

    S. Komkov and A. Petiushko, “Advhat: Real-world adversarial attack on arcface face id system,” inICPR. IEEE, 2021, pp. 819–

  46. [50]

    Adversarial light projection attacks on face recognition systems: A feasibility study,

    D.-L. Nguyen, S. S. Arora, Y. Wu, and H. Yang, “Adversarial light projection attacks on face recognition systems: A feasibility study,” inCVPRW, 2020, pp. 814–815. 5, 6, 11

  47. [51]

    Adversarial mask: Real-world universal adversarial attack on face recognition models,

    A. Zolfi, S. Avidan, Y. Elovici, and A. Shabtai, “Adversarial mask: Real-world universal adversarial attack on face recognition models,” inMLKDD. Springer, 2022, pp. 304–320. 5, 6, 11

  48. [52]

    Adversarial sticker: A stealthy attack method in the physical world,

    X. Wei, Y. Guo, and J. Yu, “Adversarial sticker: A stealthy attack method in the physical world,”IEEE TP AMI, vol. 45, no. 3, pp. 2711–2725, 2022. 5, 11

  49. [54]

    A general framework for adversarial examples with objectives,

    M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “A general framework for adversarial examples with objectives,”ACM TPS, vol. 22, no. 3, pp. 1–30, 2019. 4, 11, 13

  50. [55]

    On adversarial patches: Real-world attack on arcface-100 face recognition system,

    M. Pautov, G. Melnikov, E. Kaziakhmedov, K. Kireev, and A. Petiushko, “On adversarial patches: Real-world attack on arcface-100 face recognition system,” inSIBIRCON. IEEE, 2019, pp. 0391–0396. 4, 11

  51. [56]

    Powerful physical adver- sarial examples against practical face recognition systems,

    I. Singh, T. Araki, and K. Kakizaki, “Powerful physical adver- sarial examples against practical face recognition systems,” in WACV, 2022, pp. 301–310. 4, 6, 11

  52. [57]

    Improving transferability of adversarial patches on face recognition with generative models,

    Z. Xiao, X. Gao, C. Fu, Y. Dong, W. Gao, X. Zhang, J. Zhou, and J. Zhu, “Improving transferability of adversarial patches on face recognition with generative models,” inCVPR, 2021, pp. 11 845– 11 854. 4, 5, 11

  53. [58]

    Progressive growing of gans for improved quality, stability, and variation,

    T. Karras, T. Aila, S. Laine, and J. Lehtinen, “Progressive growing of gans for improved quality, stability, and variation,” inICLR, 2018, pp. 1–12. 5, 10, 11, 12

  54. [59]

    A style-based generator archi- tecture for generative adversarial networks,

    T. Karras, S. Laine, and T. Aila, “A style-based generator archi- tecture for generative adversarial networks,” inCVPR, 2019, pp. 4401–4410. 5, 10, 11, 12

  55. [60]

    Analyzing and improving the image quality of stylegan,

    T. Karras, S. Laine, M. Aittala, J. Hellsten, J. Lehtinen, and T. Aila, “Analyzing and improving the image quality of stylegan,” in CVPR, 2020, pp. 8110–8119. 5, 11

  56. [61]

    Robust physical-world attacks on face recognition,

    X. Zheng, Y. Fan, B. Wu, Y. Zhang, J. Wang, and S. Pan, “Robust physical-world attacks on face recognition,”PR, vol. 133, p. 109009, 2023. 5, 11

  57. [62]

    Eap: An effective black-box impersonation adversarial patch attack method on face recogni- tion in the physical world,

    X. Liu, F. Shen, J. Zhao, and C. Nie, “Eap: An effective black-box impersonation adversarial patch attack method on face recogni- tion in the physical world,”Neurocomputing, vol. 580, p. 127517,

  58. [63]

    Simultaneously optimiz- ing perturbations and positions for black-box adversarial patch attacks,

    X. Wei, Y. Guo, J. Yu, and B. Zhang, “Simultaneously optimiz- ing perturbations and positions for black-box adversarial patch attacks,”IEEE TP AMI, vol. 45, no. 7, pp. 9041–9054, 2023. 5, 11

  59. [64]

    Effective and robust physical-world attacks on deep learning face recognition systems,

    M. Shen, H. Yu, L. Zhu, K. Xu, Q. Li, and J. Hu, “Effective and robust physical-world attacks on deep learning face recognition systems,”TIFS, vol. 16, pp. 4063–4077, 2021. 5, 11

  60. [65]

    Grad-cam: Visual explanations from deep networks via gradient-based localization,

    R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-cam: Visual explanations from deep networks via gradient-based localization,” inICCV, 2017, pp. 618–626. 5

  61. [66]

    Very deep convolutional net- works for large-scale image recognition,

    K. Simonyan and A. Zisserman, “Very deep convolutional net- works for large-scale image recognition,” inICLR, 2015. 5

  62. [68]

    Fooling face recognition systems through physical adversarial attack,

    S. Bhilare and A. Hati, “Fooling face recognition systems through physical adversarial attack,” inICCVIP. Springer, 2024, pp. 420–

  63. [69]

    Explaining and har- nessing adversarial examples,

    I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and har- nessing adversarial examples,” inICLR, Y. Bengio and Y. LeCun, Eds., 2015, pp. 1–11. 5

  64. [70]

    Regressing robust and discriminative 3d morphable models with a very deep neural network,

    A. Tuan Tran, T. Hassner, I. Masi, and G. Medioni, “Regressing robust and discriminative 3d morphable models with a very deep neural network,” inCVPR, 2017, pp. 5163–5172. 5

  65. [71]

    Face3dadv: Exploiting robust adversarial 3d patches on physical face recognition,

    X. Yang, L. Xu, T. Pang, Y. Dong, Y. Wang, H. Su, and J. Zhu, “Face3dadv: Exploiting robust adversarial 3d patches on physical face recognition,”IJCV, vol. 133, no. 1, pp. 353–371, 2025. 5, 6, 11

  66. [72]

    The invisible polyjuice potion: an effective physical adversarial attack against face recognition,

    Y. Wang, Z. Liu, B. Luo, R. Hui, and F. Li, “The invisible polyjuice potion: an effective physical adversarial attack against face recognition,” inACM SIGSAC, 2024, pp. 3346–3360. 5, 6, 11

  67. [74]

    k-anonymity: A model for protecting privacy,

    L. Sweeney, “k-anonymity: A model for protecting privacy,” IJUFKS, vol. 10, no. 05, pp. 557–570, 2002. 6, 7

  68. [75]

    Pre-capture privacy for small vision sensors,

    F. Pittaluga and S. J. Koppal, “Pre-capture privacy for small vision sensors,”IEEE TP AMI, vol. 39, no. 11, pp. 2215–2226, 2016. 6, 11

  69. [76]

    Learning privacy- preserving optics for human pose estimation,

    C. Hinojosa, J. C. Niebles, and H. Arguello, “Learning privacy- preserving optics for human pose estimation,” inICCV, 2021, pp. 2573–2582. 6, 11

  70. [77]

    Privhar: Recognizing human actions from privacy- preserving lens,

    C. Hinojosa, M. Marquez, H. Arguello, E. Adeli, L. Fei-Fei, and J. C. Niebles, “Privhar: Recognizing human actions from privacy- preserving lens,” inECCV, 2022, pp. 314–332. 6, 11, 13

  71. [78]

    Learning phase mask for privacy-preserving passive depth estimation,

    Z. Tasneem, G. Milione, Y.-H. Tsai, X. Yu, A. Veeraragha- van, M. Chandraker, and F. Pittaluga, “Learning phase mask for privacy-preserving passive depth estimation,” inECCV. Springer, 2022, pp. 504–521. 6, 11, 13

  72. [79]

    Learn- ing a dynamic privacy-preserving camera robust to inversion attacks,

    J. Cheng, X. Dai, J. Wan, N. Antipa, and N. Vasconcelos, “Learn- ing a dynamic privacy-preserving camera robust to inversion attacks,” inECCV. Springer, 2024, pp. 349–367. 6, 7, 11, 13

  73. [80]

    Extreme low resolution activity recognition with multi-siamese embedding learning,

    M. Ryoo, K. Kim, and H. Yang, “Extreme low resolution activity recognition with multi-siamese embedding learning,” inAAAI, vol. 32, no. 1, 2018. 6, 7, 11

  74. [81]

    Face de- identification with expressions preservation,

    G. Letournel, A. Bugeau, V .-T. Ta, and J.-P . Domenger, “Face de- identification with expressions preservation,” inICIP. IEEE, 2015, pp. 4366–4370. 7, 8, 11

  75. [82]

    The effects of filtered video on awareness and privacy,

    M. Boyle, C. Edwards, and S. Greenberg, “The effects of filtered video on awareness and privacy,” inACM CSCW, 2000, pp. 1–10. 7, 11

  76. [83]

    Blur filtration fails to preserve privacy for home-based video conferencing,

    C. Neustaedter, S. Greenberg, and M. Boyle, “Blur filtration fails to preserve privacy for home-based video conferencing,”ACM TOCHI, vol. 13, no. 1, pp. 1–36, 2006. 7, 11 SUBMIT TO IEEE TRANSACTIONS ON PATTERN ANAL YSIS AND MACHINE INTELLIGENCE 18

  77. [84]

    Things that see,

    J. L. Crowley, J. Coutazet al., “Things that see,”Communications of the ACM, pp. 1–10, 2000. 7, 11

  78. [85]

    Integrating utility into face de-identification,

    R. Gross, E. Airoldi, B. Malin, and L. Sweeney, “Integrating utility into face de-identification,” inPETW. Springer, 2005, pp. 227–

  79. [86]

    Model-based face de-identification,

    R. Gross, L. Sweeney, F. De la Torre, and S. Baker, “Model-based face de-identification,” inCVPRW, 2006, pp. 161–161. 7, 11

  80. [87]

    Towards real-world face de- identification,

    R. Gross and L. Sweeney, “Towards real-world face de- identification,” inICB. IEEE, 2007, pp. 1–8. 7, 11

  81. [88]

    Semi- supervised learning of multi-factor models for face de- identification,

    R. Gross, L. Sweeney, F. De La Torre, and S. Baker, “Semi- supervised learning of multi-factor models for face de- identification,” inCVPR, 2008, pp. 1–8. 8, 11

  82. [89]

    Face de-identification with perfect privacy protection,

    L. Meng and Z. Sun, “Face de-identification with perfect privacy protection,” inICICTEM. IEEE, 2014, pp. 1234–1239. 8, 11

  83. [90]

    Garp-face: Balancing pri- vacy protection and utility preservation in face de-identification,

    L. Du, M. Yi, E. Blasch, and H. Ling, “Garp-face: Balancing pri- vacy protection and utility preservation in face de-identification,” inIJCB. IEEE, 2014, pp. 1–8. 8, 11

  84. [91]

    Attribute preserved face de- identification,

    A. Jourabloo, X. Yin, and X. Liu, “Attribute preserved face de- identification,” inICB. IEEE, 2015, pp. 278–285. 8, 11

  85. [92]

    Face de-identification using facial identity preserving features,

    H. Chi and Y. H. Hu, “Face de-identification using facial identity preserving features,” inGCSIP. IEEE, 2015, pp. 586–590. 8, 11

  86. [93]

    k-same-net: k- anonymity with generative deep neural networks for face dei- dentification,

    B. Meden, ˇZ. Emer ˇsiˇc, V . ˇStruc, and P . Peer, “k-same-net: k- anonymity with generative deep neural networks for face dei- dentification,”Entropy, vol. 20, no. 1, p. 60, 2018. 8, 11

  87. [94]

    Attributes preserving face de- identification,

    B. Yan, M. Pei, and Z. Nie, “Attributes preserving face de- identification,” inICCVW, 2019, pp. 1217–1221. 8, 11

  88. [95]

    Efficient decision-based black-box adversarial attacks on face recognition,

    Y. Dong, H. Su, B. Wu, Z. Li, W. Liu, T. Zhang, and J. Zhu, “Efficient decision-based black-box adversarial attacks on face recognition,” inCVPR, 2019, pp. 7714–7722. 8, 9, 11

  89. [96]

    Adversarial face de-identification,

    E. Chatzikyriakidis, C. Papaioannidis, and I. Pitas, “Adversarial face de-identification,” inICIP. IEEE, 2019, pp. 684–688. 8, 9, 11

  90. [97]

    Advfaces: Adversarial face synthesis,

    D. Deb, J. Zhang, and A. K. Jain, “Advfaces: Adversarial face synthesis,” inIJCB. IEEE, 2020, pp. 1–10. 8, 11

  91. [98]

    Face image de- identification by feature space adversarial perturbation,

    H. Xue, B. Liu, X. Yuan, M. Ding, and T. Zhu, “Face image de- identification by feature space adversarial perturbation,”CCPE, vol. 35, no. 5, p. e7554, 2023. 8, 9, 11

  92. [99]

    To- wards face encryption by generating adversarial identity masks,

    X. Yang, Y. Dong, T. Pang, H. Su, J. Zhu, Y. Chen, and H. Xue, “To- wards face encryption by generating adversarial identity masks,” inICCV, 2021, pp. 3897–3907. 8, 9, 11

  93. [100]

    Face image de-identification based on feature embedding,

    G. Hanawa, K. Ito, and T. Aoki, “Face image de-identification based on feature embedding,”EURASIP Journal on Image and Video Processing, vol. 2024, no. 1, p. 25, 2024. 8, 11

  94. [101]

    Adv-inversion: Stealthy adversarial attacks via gan-inversion for facial privacy protection,

    H. Wang, W. Luo, X. Xie, P . Zheng, W. Huang, and J. Huang, “Adv-inversion: Stealthy adversarial attacks via gan-inversion for facial privacy protection,”TIFS, pp. 1–15, 2025. 8, 9, 11

  95. [102]

    Protecting facial privacy: Generating adversarial identity masks via style-robust makeup transfer,

    S. Hu, X. Liu, Y. Zhang, M. Li, L. Y. Zhang, H. Jin, and L. Wu, “Protecting facial privacy: Generating adversarial identity masks via style-robust makeup transfer,” inCVPR, 2022, pp. 15 014– 15 023. 8, 11

  96. [103]

    Generating adversarial examples by makeup attacks on face recognition,

    Z.-A. Zhu, Y.-Z. Lu, and C.-K. Chiang, “Generating adversarial examples by makeup attacks on face recognition,” inICIP. IEEE, 2019, pp. 2516–2520. 8, 11

  97. [104]

    Clip2protect: Pro- tecting facial privacy using text-guided makeup via adversarial latent search,

    F. Shamshad, M. Naseer, and K. Nandakumar, “Clip2protect: Pro- tecting facial privacy using text-guided makeup via adversarial latent search,” inCVPR, 2023, pp. 20 595–20 605. 8, 11

  98. [105]

    Diffprotect: Generate adver- sarial examples with diffusion models for facial privacy protec- tion,

    J. Liu, C. P . Lau, and R. Chellappa, “Diffprotect: Generate adver- sarial examples with diffusion models for facial privacy protec- tion,”arXiv preprint arXiv:2305.13625, pp. 1–14, 2023. 8, 11, 14

  99. [106]

    Adv-cpg: A customized portrait generation framework with facial adversarial attacks,

    J. Wang, H. Zhang, and Y. Yuan, “Adv-cpg: A customized portrait generation framework with facial adversarial attacks,” inCVPR, 2025, pp. 21 001–21 010. 8, 11

  100. [107]

    Towards transferable adversarial attack against deep face recognition,

    Y. Zhong and W. Deng, “Towards transferable adversarial attack against deep face recognition,”TIFS, vol. 16, pp. 1452–1466, 2020. 8, 9, 11

  101. [108]

    Sibling- attack: Rethinking transferable adversarial attacks against face recognition,

    Z. Li, B. Yin, T. Yao, J. Guo, S. Ding, S. Chen, and C. Liu, “Sibling- attack: Rethinking transferable adversarial attacks against face recognition,” inCVPR, 2023, pp. 24 626–24 637. 8, 9, 11

  102. [109]

    Transferable black-box attack against face recognition with spatial mutable adversarial patch,

    H. Ma, K. Xu, X. Jiang, Z. Zhao, and T. Sun, “Transferable black-box attack against face recognition with spatial mutable adversarial patch,”TIFS, vol. 18, pp. 5636–5650, 2023. 8, 11

  103. [110]

    Toward transferable attack via adversarial diffusion in face recognition,

    C. Hu, Y. Li, Z. Feng, and X. Wu, “Toward transferable attack via adversarial diffusion in face recognition,”TIFS, vol. 19, pp. 5506–5519, 2024. 8, 11

  104. [111]

    Improving the transferability of adversarial attacks on face recognition with diverse parameters augmentation,

    F. Zhou, B. Yin, H. Ling, Q. Zhou, and W. Wang, “Improving the transferability of adversarial attacks on face recognition with diverse parameters augmentation,” inCVPR, 2025, pp. 3516–

  105. [112]

    Discrete point- wise attack is not enough: Generalized manifold adversarial attack for face recognition,

    Q. Li, Y. Hu, Y. Liu, D. Zhang, X. Jin, and Y. Chen, “Discrete point- wise attack is not enough: Generalized manifold adversarial attack for face recognition,” inCVPR, 2023, pp. 20 575–20 584. 8, 11

  106. [113]

    Universal adversarial spoofing attacks against face recognition,

    T. Amada, S. P . Liew, K. Kakizaki, and T. Araki, “Universal adversarial spoofing attacks against face recognition,” inIJCB. IEEE, 2021, pp. 1–7. 8, 11

  107. [115]

    Personalized pri- vacy protection mask against unauthorized facial recognition,

    K.-H. Chow, S. Hu, T. Huang, and L. Liu, “Personalized pri- vacy protection mask against unauthorized facial recognition,” inECCV. Springer, 2024, pp. 434–450. 9, 11

  108. [116]

    Veil privacy on visual data: Concealing privacy for humans, unveiling for dnns,

    S. Pang, R. Ma, B. Li, Y. Zhou, and Y. Yao, “Veil privacy on visual data: Concealing privacy for humans, unveiling for dnns,” in ECCV. Springer, 2024, pp. 280–297. 9, 10, 12

  109. [117]

    De-identification without losing faces,

    Y. Li and S. Lyu, “De-identification without losing faces,” in IHMSW, 2019, pp. 83–88. 9, 12

  110. [118]

    Epd- net: A gan-based architecture for face de-identification from images,

    A. Aggarwal, R. Rathore, P . Chattopadhyay, and L. Wang, “Epd- net: A gan-based architecture for face de-identification from images,” inIOTEM. IEEE, 2020, pp. 1–7. 9, 12

  111. [119]

    Live face de-identification in video,

    O. Gafni, L. Wolf, and Y. Taigman, “Live face de-identification in video,” inICCV, 2019, pp. 9378–9387. 9, 12

  112. [120]

    Privacy-protective-gan for privacy preserving face de-identification,

    Y. Wu, F. Yang, Y. Xu, and H. Ling, “Privacy-protective-gan for privacy preserving face de-identification,”JCST, vol. 34, no. 1, pp. 47–60, 2019. 9, 11

  113. [121]

    I know that person: Generative full body and face de-identification of people in images,

    K. Brkic, I. Sikiric, T. Hrkac, and Z. Kalafatic, “I know that person: Generative full body and face de-identification of people in images,” inCVPRW. IEEE, 2017, pp. 1319–1328. 9, 11

  114. [122]

    Effective de-identification generative adversarial network for face anonymization,

    Z. Kuang, H. Liu, J. Yu, A. Tian, L. Wang, J. Fan, and N. Babaguchi, “Effective de-identification generative adversarial network for face anonymization,” inACM MM, 2021, pp. 3182–

  115. [123]

    Privacy preserva- tion through facial de-identification with simultaneous emotion preservation,

    A. Agarwal, P . Chattopadhyay, and L. Wang, “Privacy preserva- tion through facial de-identification with simultaneous emotion preservation,”SIVP, vol. 15, no. 5, pp. 951–958, 2021. 9, 12

  116. [124]

    A systematical solution for face de-identification,

    S. Yang, W. Wang, Y. Cheng, and J. Dong, “A systematical solution for face de-identification,” inCCBR. Springer, 2021, pp. 20–30. 9, 12

  117. [125]

    Sf-gan: Face de- identification method without losing facial attribute informa- tion,

    Y. Li, Q. Lu, Q. Tao, X. Zhao, and Y. Yu, “Sf-gan: Face de- identification method without losing facial attribute informa- tion,”IEEE SPL, vol. 28, pp. 1345–1349, 2021. 9, 12

  118. [126]

    Anonymousnet: Natural face de-identification with measurable privacy,

    T. Li and L. Lin, “Anonymousnet: Natural face de-identification with measurable privacy,” inCVPRW, 2019, pp. 0–10. 9, 10, 12

  119. [127]

    Identi- tymask: Deep motion flow guided reversible face video de- identification,

    Y. Wen, B. Liu, J. Cao, R. Xie, L. Song, and Z. Li, “Identi- tymask: Deep motion flow guided reversible face video de- identification,”IEEE TCSVT, vol. 32, no. 12, pp. 8353–8367, 2022. 9, 10, 12, 15

  120. [128]

    Personalized and invertible face de-identification by disentangled identity infor- mation manipulation,

    J. Cao, B. Liu, Y. Wen, R. Xie, and L. Song, “Personalized and invertible face de-identification by disentangled identity infor- mation manipulation,” inICCV, 2021, pp. 3334–3342. 9, 10, 12

  121. [129]

    The uu-net: Reversible face de-identification for visual surveillance video footage,

    H. Proenc ¸a, “The uu-net: Reversible face de-identification for visual surveillance video footage,”IEEE TCSVT, vol. 32, no. 2, pp. 496–509, 2022. 9, 12

  122. [130]

    Divide and conquer: a two-step method for high quality face de-identification with model explainability,

    Y. Wen, B. Liu, J. Cao, R. Xie, and L. Song, “Divide and conquer: a two-step method for high quality face de-identification with model explainability,” inICCV, 2023, pp. 5148–5157. 9, 10, 12

  123. [131]

    Examining stylegan as a utility-preserving face de-identification method,

    S. M. S. M. Khorzooghi and S. Nilizadeh, “Examining stylegan as a utility-preserving face de-identification method,” inPET, 2023, p. 341–358. 9, 12

  124. [132]

    Attribute- preserving face dataset anonymization via latent code optimiza- tion,

    S. Barattin, C. Tzelepis, I. Patras, and N. Sebe, “Attribute- preserving face dataset anonymization via latent code optimiza- tion,” inCVPR, 2023, pp. 8001–8010. 9, 10, 12, 13

  125. [133]

    Face deidentification with controllable privacy protection,

    B. Meden, M. Gonzalez-Hernandez, P . Peer, and V . ˇStruc, “Face deidentification with controllable privacy protection,”IVC, vol. 134, p. 104678, 2023. 10, 12, 13

  126. [134]

    Diffam: Diffusion- based adversarial makeup transfer for facial privacy protection,

    Y. Sun, L. Yu, H. Xie, J. Li, and Y. Zhang, “Diffam: Diffusion- based adversarial makeup transfer for facial privacy protection,” inCVPR, 2024, pp. 24 584–24 594. 10, 12

  127. [135]

    Diff-privacy: Diffusion-based face privacy protection,

    X. He, M. Zhu, D. Chen, N. Wang, and X. Gao, “Diff-privacy: Diffusion-based face privacy protection,”IEEE TCSVT, vol. 34, no. 12, pp. 13 164–13 176, 2024. 10, 12, 13

  128. [136]

    Facial identity editing: Towards effective de-identification,

    J. Park, S. Lee, M. Shaheryar, and S. K. Jung, “Facial identity editing: Towards effective de-identification,” inICIP. IEEE, 2025, pp. 1792–1797. 10, 12, 14

  129. [137]

    A de-identification face recognition using extracted thermal features based on deep learn- SUBMIT TO IEEE TRANSACTIONS ON PATTERN ANAL YSIS AND MACHINE INTELLIGENCE 19 ing,

    C.-H. Lin, Z.-H. Wang, and G.-J. Jong, “A de-identification face recognition using extracted thermal features based on deep learn- SUBMIT TO IEEE TRANSACTIONS ON PATTERN ANAL YSIS AND MACHINE INTELLIGENCE 19 ing,”IEEE Sensors Journal, vol. 20, no. 16, pp. 9510–9517, 2020. 10, 12

  130. [138]

    Achieving privacy- preserving multi-view consistency with advanced 3d-aware face de-identification,

    J. Cao, B. Liu, Y. Wen, R. Xie, and L. Song, “Achieving privacy- preserving multi-view consistency with advanced 3d-aware face de-identification,” inACM MM Asia, 2023, pp. 1–7. 10, 12

  131. [139]

    De-identification of facial videos while preserving remote physiological utility,

    M. Savic and G. Zhao, “De-identification of facial videos while preserving remote physiological utility,” inBMVC. BMVA Press, 2023, pp. 1–14. 10, 12, 13, 15

  132. [140]

    Facemotionpreserve: A generative approach for facial de-identification and medical in- formation preservation,

    B. Zhu, C. Zhang, Y. Sui, and L. Li, “Facemotionpreserve: A generative approach for facial de-identification and medical in- formation preservation,”Scientific Reports, vol. 14, no. 1, p. 17275,

  133. [141]

    Towards face de-identification for wearable cameras,

    B. Puangthamawathanakun, C. Arpnikanondt, W. Krathu, G. Healy, and C. Gurrin, “Towards face de-identification for wearable cameras,” inICCMI, 2023, pp. 210–216. 10, 12

  134. [142]

    3d face de-identification with preserving multi-facial attributes: A benchmark,

    Y. Liu, K. H. Cheng, M. Savic, H. Chen, Z. Yu, and G. Zhao, “3d face de-identification with preserving multi-facial attributes: A benchmark,”IEEE TBIOM, pp. 1–14, 2025. 10, 12

  135. [143]

    Labeled faces in the wild: A database for studying face recognition in unconstrained environments,

    G. B. Huang, M. Mattar, T. Berg, and E. Learned-Miller, “Labeled faces in the wild: A database for studying face recognition in unconstrained environments,” inWorkshop on Faces in’Real- Life’Images, 2008, pp. 1–11. 10, 11, 12

  136. [144]

    Deep learning face attributes in the wild,

    Z. Liu, P . Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” inICCV, 2015, pp. 3730–3738. 10, 11, 12

  137. [145]

    Vggface2: A dataset for recognising faces across pose and age,

    Q. Cao, L. Shen, W. Xie, O. M. Parkhi, and A. Zisserman, “Vggface2: A dataset for recognising faces across pose and age,” inFG. IEEE, 2018, pp. 67–74. 10, 11, 12

  138. [146]

    Learning face representation from scratch,

    D. Yi, Z. Lei, S. Liao, and S. Z. Li, “Learning face representation from scratch,”arXiv preprint arXiv:1411.7923, pp. 1–9, 2014. 10, 11, 12

  139. [147]

    Ms-celeb-1m: A dataset and benchmark for large-scale face recognition,

    Y. Guo, L. Zhang, Y. Hu, X. He, and J. Gao, “Ms-celeb-1m: A dataset and benchmark for large-scale face recognition,” in ECCV. Springer, 2016, pp. 87–102. 10, 11

  140. [148]

    The megaface benchmark: 1 million faces for recog- nition at scale,

    I. Kemelmacher-Shlizerman, S. M. Seitz, D. Miller, and E. Brossard, “The megaface benchmark: 1 million faces for recog- nition at scale,” inCVPR, 2016, pp. 4873–4882. 10, 11

  141. [149]

    At- tribute and simile classifiers for face verification,

    N. Kumar, A. C. Berg, P . N. Belhumeur, and S. K. Nayar, “At- tribute and simile classifiers for face verification,” inICCV. IEEE, 2009, pp. 365–372. 10, 11, 12

  142. [150]

    Agedb: The first manually collected, in-the- wild age database,

    S. Moschoglou, A. Papaioannou, C. Sagonas, J. Deng, I. Kotsia, and S. Zafeiriou, “Agedb: The first manually collected, in-the- wild age database,” inCVPRW, 2017, pp. 51–59. 10, 11

  143. [151]

    Frontal to profile face verification in the wild,

    S. Sengupta, J.-C. Chen, C. Castillo, V . M. Patel, R. Chellappa, and D. W. Jacobs, “Frontal to profile face verification in the wild,” in WACV. IEEE, 2016, pp. 1–9. 10, 11

  144. [152]

    The feret database and evaluation procedure for face-recognition algo- rithms,

    P . J. Phillips, H. Wechsler, J. Huang, and P . J. Rauss, “The feret database and evaluation procedure for face-recognition algo- rithms,”IVC, vol. 16, no. 5, pp. 295–306, 1998. 10, 11

  145. [153]

    Multi- pie,

    R. Gross, I. Matthews, J. Cohn, T. Kanade, and S. Baker, “Multi- pie,” inFG, 2008, pp. 1–8. 10, 11

  146. [154]

    Morph: A longitudinal image database of normal adult age-progression,

    K. Ricanek and T. Tesafaye, “Morph: A longitudinal image database of normal adult age-progression,” inFG. IEEE, 2006, pp. 341–345. 10, 11

  147. [155]

    Presentation and validation of the radboud faces database,

    O. Langner, R. Dotsch, G. Bijlstra, D. H. Wigboldus, S. T. Hawk, and A. Van Knippenberg, “Presentation and validation of the radboud faces database,”Cognition and Emotion, vol. 24, no. 8, pp. 1377–1388, 2010. 10, 11, 12

  148. [156]

    The extended cohn-kanade dataset (ck+): A com- plete dataset for action unit and emotion-specified expression,

    P . Lucey, J. F. Cohn, T. Kanade, J. Saragih, Z. Ambadar, and I. Matthews, “The extended cohn-kanade dataset (ck+): A com- plete dataset for action unit and emotion-specified expression,” inCVPRW. IEEE, 2010, pp. 94–101. 10, 11, 13

  149. [157]

    Affectnet: A database for facial expression, valence, and arousal computing in the wild,

    A. Mollahosseini, B. Hasani, and M. H. Mahoor, “Affectnet: A database for facial expression, valence, and arousal computing in the wild,”IEEE TAC, vol. 10, no. 1, pp. 18–31, 2017. 10, 12

  150. [158]

    Ladn: Local adversarial disentangling network for facial makeup and de-makeup,

    Q. Gu, G. Wang, M. T. Chiu, Y.-W. Tai, and C.-K. Tang, “Ladn: Local adversarial disentangling network for facial makeup and de-makeup,” inICCV, 2019, pp. 10 481–10 490. 10, 11, 12

  151. [159]

    Face recognition in uncon- strained videos with matched background similarity,

    L. Wolf, T. Hassner, and I. Maoz, “Face recognition in uncon- strained videos with matched background similarity,” inCVPR. IEEE, 2011, pp. 529–534. 10, 11, 12

  152. [160]

    Voxceleb: A large- scale speaker identification dataset,

    A. Nagraniy, J. S. Chungy, and A. Zisserman, “Voxceleb: A large- scale speaker identification dataset,” inISCA, vol. 2017, 2017, pp. 2616–2620. 10, 12

  153. [161]

    Multi-region probabilistic his- tograms for robust and scalable identity inference,

    C. Sanderson and B. C. Lovell, “Multi-region probabilistic his- tograms for robust and scalable identity inference,” inICB. Springer, 2009, pp. 199–208. 10, 12

  154. [162]

    Ego4d: Around the world in 3,000 hours of egocentric video,

    K. Grauman, A. Westbury, E. Byrne, Z. Chavis, A. Furnari, R. Girdhar, J. Hamburger, H. Jiang, M. Liu, X. Liuet al., “Ego4d: Around the world in 3,000 hours of egocentric video,” inCVPR, 2022, pp. 18 995–19 012. 10, 12

  155. [163]

    Bosphorus database for 3d face analysis,

    A. Savran, N. Aly ¨uz, H. Dibeklio ˘glu, O. C ¸ eliktutan, B. G¨okberk, B. Sankur, and L. Akarun, “Bosphorus database for 3d face analysis,” inBIMW. Springer, 2008, pp. 47–56. 10, 11, 12

  156. [164]

    A 3d facial expression database for facial behavior research,

    L. Yin, X. Wei, Y. Sun, J. Wang, and M. J. Rosato, “A 3d facial expression database for facial behavior research,” inFG. IEEE, 2006, pp. 211–216. 10, 12

  157. [165]

    Kinectfacedb: A kinect database for face recognition,

    R. Min, N. Kose, and J.-L. Dugelay, “Kinectfacedb: A kinect database for face recognition,”TSMCS, vol. 44, no. 11, pp. 1534– 1548, 2014. 10, 11

  158. [166]

    Siat-3dfe: A high-resolution 3d facial expression dataset,

    Y. Ye, Z. Song, J. Guo, and Y. Qiao, “Siat-3dfe: A high-resolution 3d facial expression dataset,”IEEE Access, vol. 8, pp. 48 205– 48 211, 2020. 10, 11

  159. [167]

    Non-contact video-based pulse rate measurement on a mobile service robot,

    R. Stricker, S. M ¨uller, and H.-M. Gross, “Non-contact video-based pulse rate measurement on a mobile service robot,” inIEEE RHIC. IEEE, 2014, pp. 1056–1062. 10, 12, 13

  160. [168]

    The obf database: A large face video database for remote physiological signal measurement and atrial fibrillation detection,

    X. Li, I. Alikhani, J. Shi, T. Seppanen, J. Junttila, K. Majamaa- Voltti, M. Tulppo, and G. Zhao, “The obf database: A large face video database for remote physiological signal measurement and atrial fibrillation detection,” inFG. IEEE, 2018, pp. 242–249. 10, 12, 13

  161. [169]

    Avec 2013: The con- tinuous audio/visual emotion and depression recognition chal- lenge,

    M. Valstar, B. Schuller, K. Smith, F. Eyben, B. Jiang, S. Bilakhia, S. Schnieder, R. Cowie, and M. Pantic, “Avec 2013: The con- tinuous audio/visual emotion and depression recognition chal- lenge,” inACM IWAVEC, 2013, pp. 3–10. 10, 11, 13

  162. [170]

    Avec 2014: 3d dimensional affect and depression recognition challenge,

    M. Valstar, B. Schuller, K. Smith, T. Almaev, F. Eyben, J. Krajewski, R. Cowie, and M. Pantic, “Avec 2014: 3d dimensional affect and depression recognition challenge,” inACM IWAVEC, 2014, pp. 3–10. 10, 11, 13

  163. [171]

    Hmdb: A large video database for human motion recognition,

    H. Kuehne, H. Jhuang, E. Garrote, T. Poggio, and T. Serre, “Hmdb: A large video database for human motion recognition,” inICCV. IEEE, 2011, pp. 2556–2563. 10, 11

  164. [172]

    First- person animal activity recognition from egocentric videos,

    Y. Iwashita, A. Takamine, R. Kurazume, and M. S. Ryoo, “First- person animal activity recognition from egocentric videos,” in ICPR. IEEE, 2014, pp. 4310–4315. 10, 11

  165. [173]

    First-person activity recognition: What are they doing to me?

    M. S. Ryoo and L. Matthies, “First-person activity recognition: What are they doing to me?” inCVPR, 2013, pp. 2730–2737. 11

  166. [174]

    Towards a visual privacy advisor: Understanding and predicting privacy risks in images,

    T. Orekondy, B. Schiele, and M. Fritz, “Towards a visual privacy advisor: Understanding and predicting privacy risks in images,” inICCV, 2017, pp. 3686–3695. 11

  167. [175]

    Privacy- preserving deep action recognition: An adversarial learning framework and a new dataset,

    Z. Wu, H. Wang, Z. Wang, H. Jin, and Z. Wang, “Privacy- preserving deep action recognition: An adversarial learning framework and a new dataset,”IEEE TP AMI, vol. 44, no. 4, pp. 2126–2139, 2020. 11

  168. [176]

    Indoor seg- mentation and support inference from rgbd images,

    N. Silberman, D. Hoiem, P . Kohli, and R. Fergus, “Indoor seg- mentation and support inference from rgbd images,” inECCV. Springer, 2012, pp. 746–760. 11

  169. [177]

    Fame-a flexible appearance modeling environment,

    M. B. Stegmann, B. K. Ersboll, and R. Larsen, “Fame-a flexible appearance modeling environment,”IEEE TMI, vol. 22, no. 10, pp. 1319–1331, 2003. 11

  170. [178]

    An approach to the de-identification of faces in different poses,

    B. Samarzija and S. Ribaric, “An approach to the de-identification of faces in different poses,” inICICTEM. IEEE, 2014, pp. 1246–

  171. [179]

    Photorealistic face de-identification by aggregating donors’ face components,

    S. Mosaddegh, L. Simon, and F. Jurie, “Photorealistic face de-identification by aggregating donors’ face components,” in ACCV. Springer, 2014, pp. 159–174. 11

  172. [180]

    The muct landmarked face database,

    S. Milborrow, J. Morkel, and F. Nicolls, “The muct landmarked face database,”PRASA, vol. 201, no. 0, p. 535, 2010. 11

  173. [181]

    The put face database,

    A. Kasinski, A. Florek, and A. Schmidt, “The put face database,” IPC, vol. 13, no. 3-4, pp. 59–64, 2008. 11

  174. [182]

    Facetracer: A search engine for large collections of images with faces,

    N. Kumar, P . Belhumeur, and S. Nayar, “Facetracer: A search engine for large collections of images with faces,” inECCV. Springer, 2008, pp. 340–353. 11

  175. [183]

    A data-driven approach to cleaning large face datasets,

    H.-W. Ng and S. Winkler, “A data-driven approach to cleaning large face datasets,” inICIP. IEEE, 2014, pp. 343–347. 11

  176. [184]

    Face recognition using 2d and 3d facial data,

    K. Chang, K. Bowyer, and P . Flynn, “Face recognition using 2d and 3d facial data,” inACM MUAW, 2003, pp. 25–32. 11

  177. [185]

    The cas-peal large-scale chinese face database and baseline evaluations,

    W. Gao, B. Cao, S. Shan, X. Chen, D. Zhou, X. Zhang, and D. Zhao, “The cas-peal large-scale chinese face database and baseline evaluations,”TSMC, vol. 38, no. 1, pp. 149–161, 2007. 11

  178. [186]

    Robust face detection using the hausdorff distance,

    O. Jesorsky, K. J. Kirchberg, and R. W. Frischholz, “Robust face detection using the hausdorff distance,” inICAVBP A. Springer, 2001, pp. 90–95. 11, 12 SUBMIT TO IEEE TRANSACTIONS ON PATTERN ANAL YSIS AND MACHINE INTELLIGENCE 20

  179. [187]

    Xm2vtsdb: The extended m2vts database,

    K. Messer, J. Matas, J. Kittler, J. Luettin, G. Maitreet al., “Xm2vtsdb: The extended m2vts database,” inICAVBP A, vol

  180. [188]

    The devil of face recognition is in the noise,

    F. Wang, L. Chen, C. Li, S. Huang, Y. Chen, C. Qian, and C. C. Loy, “The devil of face recognition is in the noise,” inECCV, 2018, pp. 765–780. 11

  181. [189]

    Beautygan: Instance-level facial makeup transfer with deep generative adversarial network,

    T. Li, R. Qian, C. Dong, S. Liu, Q. Yan, W. Zhu, and L. Lin, “Beautygan: Instance-level facial makeup transfer with deep generative adversarial network,” inACM MM, 2018, pp. 645–653. 11

  182. [190]

    Consistentid: Portrait generation with multimodal fine-grained identity preserving,

    J. Huang, X. Dong, W. Song, Z. Chong, Z. Tang, J. Zhou, Y. Cheng, L. Chen, H. Li, Y. Yanet al., “Consistentid: Portrait generation with multimodal fine-grained identity preserving,”arXiv preprint arXiv:2404.16771, 2024. 11

  183. [191]

    Clothing co-parsing by joint image segmentation and labeling,

    W. Yang, P . Luo, and L. Lin, “Clothing co-parsing by joint image segmentation and labeling,” inCVPR, 2014, pp. 3182–3189. 11

  184. [192]

    Hu- man3.6m: Large scale datasets and predictive methods for 3d human sensing in natural environments,

    C. Ionescu, D. Papava, V . Olaru, and C. Sminchisescu, “Hu- man3.6m: Large scale datasets and predictive methods for 3d human sensing in natural environments,”IEEE TP AMI, vol. 36, no. 7, pp. 1325–1339, 2013. 11

  185. [193]

    Be- yond frontal faces: Improving person recognition using multiple cues,

    N. Zhang, M. Paluri, Y. Taigman, R. Fergus, and L. Bourdev, “Be- yond frontal faces: Improving person recognition using multiple cues,” inCVPR, 2015, pp. 4804–4813. 12, 15

  186. [194]

    Deepprivacy: A genera- tive adversarial network for face anonymization,

    H. Hukkel ˚as, R. Mester, and F. Lindseth, “Deepprivacy: A genera- tive adversarial network for face anonymization,” inInternational Symposium on Visual Computing. Springer, 2019, pp. 565–578. 12

  187. [195]

    Wider face: A face detection benchmark,

    S. Yang, P . Luo, C.-C. Loy, and X. Tang, “Wider face: A face detection benchmark,” inCVPR, 2016, pp. 5525–5533. 12

  188. [196]

    Mots: Multi-object tracking and seg- mentation,

    P . Voigtlaender, M. Krause, A. Osep, J. Luiten, B. B. G. Sekar, A. Geiger, and B. Leibe, “Mots: Multi-object tracking and seg- mentation,” inCVPR, 2019, pp. 7942–7951. 12

  189. [197]

    From facial expression recognition to interpersonal relation prediction,

    Z. Zhang, P . Luo, C. C. Loy, and X. Tang, “From facial expression recognition to interpersonal relation prediction,”IJCV, vol. 126, no. 5, pp. 550–569, 2018. 12

  190. [198]

    Driver drowsiness detec- tion via a hierarchical temporal deep belief network,

    C.-H. Weng, Y.-H. Lai, and S.-H. Lai, “Driver drowsiness detec- tion via a hierarchical temporal deep belief network,” inACCV. Springer, 2016, pp. 117–133. 12

  191. [199]

    The p-destre: A fully annotated dataset for pedestrian detec- tion, tracking, and short/long-term re-identification from aerial devices,

    S. A. Kumar, E. Yaghoubi, A. Das, B. Harish, and H. Proenc ¸a, “The p-destre: A fully annotated dataset for pedestrian detec- tion, tracking, and short/long-term re-identification from aerial devices,”TIFS, vol. 16, pp. 1696–1708, 2020. 12

  192. [200]

    Mars: A video benchmark for large-scale person re- identification,

    L. Zheng, Z. Bie, Y. Sun, J. Wang, C. Su, S. Wang, and Q. Tian, “Mars: A video benchmark for large-scale person re- identification,” inECCV. Springer, 2016, pp. 868–884. 12

  193. [201]

    Dart- blur: Privacy preservation with detection artifact suppression,

    B. Jiang, B. Bai, H. Lin, Y. Wang, Y. Guo, and L. Fang, “Dart- blur: Privacy preservation with detection artifact suppression,” inCVPR, 2023, pp. 16 479–16 488. 12

  194. [202]

    Fddb: A benchmark for face detection in unconstrained settings,

    V . Jain and E. Learned-Miller, “Fddb: A benchmark for face detection in unconstrained settings,” UMass Amherst Technical Report, Tech. Rep., 2010. 12

  195. [203]

    Crowdhuman: A benchmark for detecting human in a crowd,

    S. Shao, Z. Zhao, B. Li, T. Xiao, G. Yu, X. Zhang, and J. Sun, “Crowdhuman: A benchmark for detecting human in a crowd,” arXiv preprint arXiv:1805.00123, pp. 1–9, 2018. 12

  196. [204]

    Verifiable facial de-identification in video surveillance,

    S. Park, H. Na, and D. Choi, “Verifiable facial de-identification in video surveillance,”IEEE Access, vol. 12, pp. 67 758–67 771, 2024. 12, 13

  197. [205]

    Rbgan: Realistic-generation and balanced-utility gan for face de-identification,

    Y. Zhang, Y. Fang, Y. Cao, and J. Wu, “Rbgan: Realistic-generation and balanced-utility gan for face de-identification,”IVC, vol. 141, p. 104868, 2024. 12

  198. [206]

    Face de-identification using face caricature,

    L. Laishram, J. T. Lee, and S. K. Jung, “Face de-identification using face caricature,”IEEE Access, vol. 12, pp. 19 344–19 354,

  199. [207]

    Parameterisation of a stochastic model for human face identification,

    F. S. Samaria and A. C. Harter, “Parameterisation of a stochastic model for human face identification,” inIEEE Workshop on Appli- cations of Computer Vision. IEEE, 1994, pp. 138–142. 12

  200. [208]

    A high-resolution spontaneous 3d dynamic facial expression database,

    X. Zhang, L. Yin, J. F. Cohn, S. Canavan, M. Reale, A. Horowitz, and P . Liu, “A high-resolution spontaneous 3d dynamic facial expression database,” inFG Workshop. IEEE, 2013, pp. 1–6. 12

  201. [209]

    Face-deid-net: Generative face de-identification with identity removal and attribute preserva- tion for latent diffusion model training,

    Y. Zeng, M. Zhang, and H. Xin, “Face-deid-net: Generative face de-identification with identity removal and attribute preserva- tion for latent diffusion model training,” inICSIP. IEEE, 2025, pp. 489–495. 12

  202. [210]

    Mystyle: A personalized generative prior,

    Y. Nitzan, K. Aberman, Q. He, O. Liba, M. Yarom, Y. Gandelsman, I. Mosseri, Y. Pritch, and D. Cohen-Or, “Mystyle: A personalized generative prior,”TOG, vol. 41, no. 6, pp. 1–10, 2022. 12

  203. [211]

    Visual context-aware attribute-preserving face de-identification,

    H. Kim, J. Shim, S. Park, and E. Hwang, “Visual context-aware attribute-preserving face de-identification,”Neurocomputing, vol. 638, p. 130205, 2025. 12

  204. [212]

    Maskgan: Towards diverse and interactive facial image manipulation,

    C.-H. Lee, Z. Liu, L. Wu, and P . Luo, “Maskgan: Towards diverse and interactive facial image manipulation,” inCVPR, 2020, pp. 5549–5558. 12

  205. [213]

    An overview of research activities in facial age estimation using the fg-net aging database,

    G. Panis and A. Lanitis, “An overview of research activities in facial age estimation using the fg-net aging database,” inECCV. Springer, 2014, pp. 737–750. 12

  206. [214]

    Child face age-progression via deep feature aging,

    D. Deb, D. Aggarwal, and A. K. Jain, “Child face age-progression via deep feature aging,”arXiv preprint arXiv:2003.08788, 2020. 12

  207. [215]

    Longitudinal study of child face recognition,

    D. Deb, N. Nain, and A. K. Jain, “Longitudinal study of child face recognition,” inICB. IEEE, 2018, pp. 225–232. 12

  208. [216]

    Facial action coding system: A technique for the measurement of facial movement,

    W. V . Friesen and P . Ekman, “Facial action coding system: A technique for the measurement of facial movement,”Palo Alto, vol. 3, no. 2, p. 5, 1978. 13

  209. [217]

    Image quality assessment: From error visibility to structural similarity,

    Z. Wang, A. C. Bovik, H. R. Sheikh, and E. P . Simoncelli, “Image quality assessment: From error visibility to structural similarity,” IEEE TIP, vol. 13, no. 4, pp. 600–612, 2004. 13

  210. [218]

    Gans trained by a two time-scale update rule converge to a local nash equilibrium,

    M. Heusel, H. Ramsauer, T. Unterthiner, B. Nessler, and S. Hochreiter, “Gans trained by a two time-scale update rule converge to a local nash equilibrium,” inNIPS, 2017, pp. 815–

  211. [219]

    Rethinking the inception architecture for computer vision,

    C. Szegedy, V . Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in CVPR, 2016, pp. 2818–2826. 13

  212. [220]

    The unreasonable effectiveness of deep features as a perceptual metric,

    R. Zhang, P . Isola, A. A. Efros, E. Shechtman, and O. Wang, “The unreasonable effectiveness of deep features as a perceptual metric,” inCVPR, 2018, pp. 586–595. 13

  213. [221]

    Deep gait recognition: A survey,

    A. Sepas-Moghaddam and A. Etemad, “Deep gait recognition: A survey,”IEEE TP AMI, vol. 45, no. 1, pp. 264–284, 2022. 15

  214. [222]

    General data protection regulation,

    European Parliament and the Council of the European Union, “General data protection regulation,” Official Journal of the European Union, pp. 1–88, May 2016, oJ L 119, 4.5.2016. [Online]. Available: http://data.europa.eu/eli/reg/2016/679/oj 15 Hui Weireceived the PhD degree in ...

  215. [964]

    Washington, DC, 1999, pp. 965–966. 11, 12

  216. [2005]

    She is a member of Academia Europaea, a member of Finnish Academy of Sciences and Letters, Fellow of IEEE, IAPR, ELLIS and AAIA

    She is currently an Academy Professor and full Professor (tenured in 2017) with Univer- sity of Oulu, and a PI with ELLIS Institute Fin- land. She is a member of Academia Europaea, a member of Finnish Academy of Sciences and Letters, Fellow of IEEE, IAPR, ELLIS and AAIA. Her c...

Pith tools

Reviewed August 1, 2026 · model on record in the stance chip above.