REVIEW 1 major objections 2 minor 27 references
A Utility-Preserving GAN for Face Obscuration
T0 review · 1 major / 2 minor · reviewed 2026-05-25 · grok-4.3
Pith's one-line read A generative model called UP-GAN obscures facial identity while preserving age, gender, skin tone, pose, and expression.
desk verdict UP-GAN applies a GAN to face obscuration while preserving utility attributes, but the abstract's performance claim has no supporting numbers and the evaluation may not transfer beyond the tested recognizer. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
UP-GAN, a generative adversarial network that separates identity features from utility attributes during image synthesis.
What would settle it
An identity classifier that achieves high accuracy on UP-GAN obscured faces at rates similar to its accuracy on the original unprocessed faces.
Extended reading notes
Core claim
The authors present UP-GAN as a utility-preserving generative model that conceals facial identity through adversarial training while retaining utility attributes, and they report that it outperforms prior obscuration methods on both identity concealment and utility retention.
Load-bearing premise
Facial identity can be separated from utility attributes such as age and gender so that a generative model can hide one without damaging the others.
Editorial extensions
If this is right
- Obscured images from sources such as news or mapping services can retain utility for analysis while reducing re-identification risk.
- Utility attributes including age, gender, skin tone, pose, and expression remain measurable after obscuration.
- The method provides stronger protection than Gaussian blurring or pixelation against modern re-identification attacks.
- The same separation principle could apply to other image datasets that require both privacy and downstream utility.
Reading between the lines
- Real-time versions of this model could be inserted into video pipelines to anonymize faces on the fly.
- Training recognition systems on UP-GAN outputs might reduce privacy leakage in public datasets.
- The approach raises the question of whether similar separation can be achieved for non-facial identifiers such as gait or clothing.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes UP-GAN, a utility-preserving generative adversarial network for face obscuration. The method is intended to conceal identity while retaining non-identifying attributes (age, gender, skin tone, pose, expression). The central claim is that UP-GAN achieves the best performance among compared methods on both obscuration effectiveness and utility preservation.
Significance. If the empirical claims are substantiated with robust evaluation, the result would be relevant to privacy-preserving computer vision pipelines (e.g., Street View, broadcast media) where simple blurring or pixelation is now known to be insufficient against modern recognizers. The approach directly targets the privacy-utility trade-off via an adversarial formulation rather than post-hoc filtering.
major comments (1)
- [Experimental results / Evaluation protocol] The obscuration claim rests on lowered accuracy of one or more face-recognition networks on the generated images. Because identity and utility attributes (pose, expression) are statistically entangled, any generator that preserves the latter can still leak identity to a recognizer whose feature space was not explicitly penalized. The manuscript reports results only against the recognizer(s) used during training or architecturally similar models; no results are given for independent, stronger, or disjoint recognizers (different backbone or training corpus). This leaves the central claim vulnerable to the concern that measured success does not transfer to an external adversary.
minor comments (2)
- [Abstract] The abstract asserts 'best performance' without any quantitative metrics, baselines, or dataset names; while the full experimental section presumably supplies these, the summary paragraph should at minimum indicate the evaluation protocol and primary numbers.
- [Method] Notation for the utility and identity losses is introduced without an explicit equation reference or table summarizing all loss terms and their weighting coefficients.
Simulated Author's Rebuttal
We thank the referee for the constructive feedback. We address the single major comment below.
read point-by-point responses
-
Referee: [Experimental results / Evaluation protocol] The obscuration claim rests on lowered accuracy of one or more face-recognition networks on the generated images. Because identity and utility attributes (pose, expression) are statistically entangled, any generator that preserves the latter can still leak identity to a recognizer whose feature space was not explicitly penalized. The manuscript reports results only against the recognizer(s) used during training or architecturally similar models; no results are given for independent, stronger, or disjoint recognizers (different backbone or training corpus). This leaves the central claim vulnerable to the concern that measured success does not transfer to an external adversary.
Authors: We agree that the evaluation would be strengthened by results on independent recognizers with different backbones or training corpora. The adversarial objective in UP-GAN is formulated to penalize identity leakage while preserving utility attributes, and the reported experiments already include multiple recognizer architectures. Nevertheless, the referee's concern about generalization is valid. In the revised manuscript we will add quantitative results against at least two additional, disjoint face-recognition models (different backbone and training set) to demonstrate that the measured obscuration transfers beyond the training recognizer. revision: yes
Circularity Check
No significant circularity; empirical evaluation only
full rationale
The paper proposes UP-GAN as an empirical generative model and reports performance on obscuration and utility metrics. No derivation chain, equations, fitted parameters renamed as predictions, or load-bearing self-citations appear in the abstract or described structure. The central claim rests on experimental comparisons rather than any self-definitional reduction or ansatz smuggled via prior work. This is the expected outcome for a standard applied ML paper without theoretical derivations.
Assumptions & free parameters
Cite this review
Pith. "Pith review of A Utility-Preserving GAN for Face Obscuration." pith.science (2026). https://pith.science/paper/2C4DJ3WP
@misc{pith2026190611979,
author = {Pith},
title = {Pith review of: A Utility-Preserving GAN for Face Obscuration},
year = {2026},
howpublished = {\url{https://pith.science/paper/2C4DJ3WP}},
note = {Machine review of arXiv:1906.11979}
}
read the original abstract
From TV news to Google StreetView, face obscuration has been used for privacy protection. Due to recent advances in the field of deep learning, obscuration methods such as Gaussian blurring and pixelation are not guaranteed to conceal identity. In this paper, we propose a utility-preserving generative model, UP-GAN, that is able to provide an effective face obscuration, while preserving facial utility. By utility-preserving we mean preserving facial features that do not reveal identity, such as age, gender, skin tone, pose, and expression. We show that the proposed method achieves the best performance in terms of obscuration and utility preservation.
Figures
Figures from the paper (1 more)
Reference graph
Works this paper leans on
-
[1]
" write newline "" before.all 'output.state := FUNCTION n.dashify 't := "" t empty not t #1 #1 substring "-" = t #1 #2 substring "--" = not "--" * t #2 global.max substring 't := t #1 #1 substring "-" = "-" * t #2 global.max substring 't := while if t #1 #1 substring * t #2 global.max substring 't := if while FUNCTION format.date year duplicate empty "emp...
-
[2]
Face aging with conditional generative adversarial networks
Antipov, G., Baccouche, M., and Dugelay, J.-L. Face aging with conditional generative adversarial networks. Proceedings of the IEEE International Conference on Image Processing, pp.\ 2089--2093, Sep. 2017. URL https://doi.org/10.1109/ICIP.2017.8296650. Beijing, China
-
[3]
Bitouk, D., Kumar, N., Dhillon, S., Belhumeur, P., and Nayar, S. K. Face swapping: Automatically replacing faces in photographs. ACM Transactions on Graphics, 27 0 (3): 0 39:1--39:8, 2008. URL https://doi.org/10.1145/1360612.1360638
-
[4]
Cootes , T. F., Edwards , G. J., and Taylor , C. J. Active appearance models. IEEE Transactions on Pattern Analysis and Machine Intelligence, 23 0 (6): 0 484--498, June 2001. URL https://doi.org/10.1109/34.927467
-
[5]
T., Tatarchenko, M., and Brox, T
Dosovitskiy, A., Springenberg, J. T., Tatarchenko, M., and Brox, T. Learning to generate chairs, tables and cars with convolutional networks. IEEE Transactions on Pattern Analysis and Machine Intelligence, 39 0 (4): 0 692--705, April 2017. URL https://doi.org/10.1109/TPAMI.2016.2567384
-
[6]
Garp-face: Balancing privacy protection and utility preservation in face de-identification
Du, L., Yi, M., Blasch, E., and Ling, H. Garp-face: Balancing privacy protection and utility preservation in face de-identification. Proceedings of the IEEE International Joint Conference on Biometrics, pp.\ 1--8, September 2014. URL https://doi.org/10.1109/BTAS.2014.6996249. Clearwater, FL
-
[7]
Generative Adversarial Networks
Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y. Generative adversarial nets. Advances in Neural Information Processing Systems, pp.\ 2672--2680, December 2014. URL https://arxiv.org/abs/1406.2661. Montr\'eal, Canada
work page Pith review arXiv 2014
-
[8]
Integrating utility into face de-identification
Gross, R., Airoldo, E., Malin, B., and Sweeney, L. Integrating utility into face de-identification. Proceedings of the International Workshop on Privacy Enhancing Technologies, pp.\ 227--242, May 2005. URL https://doi.org/10.1007/11767831_15. Cavtat, Croatia
Show all 27 references
-
[9]
and Delp, E
G\" u era, D. and Delp, E. J. Deepfake video detection using recurrent neural networks. Proceedings of the IEEE International Conference on Advanced Video and Signal Based Surveillance, pp.\ 1--6, Nov. 2018. URL https://doi.org/10.1109/AVSS.2018.8639163. Auckland, New Zealand
2018 doi
-
[10]
Gans trained by a two time-scale update rule converge to a local nash equilibrium
Heusel, M., Ramsauer, H., Unterthiner, T., Nessler, B., and Hochreiter, S. Gans trained by a two time-scale update rule converge to a local nash equilibrium. Advances in Neural Information Processing Systems, pp.\ 6629--6640, 2017. URL http://arxiv.org/abs/1706.08500. Long Beach, CA
2017 arXiv
-
[11]
Perceptual losses for real-time style transfer and super-resolution
Johnson, J., Alahi, A., and Fei-Fei, L. Perceptual losses for real-time style transfer and super-resolution. European Conference on Computer Vision, pp.\ 694--711, 2016. URL https://doi.org/10.1007/978-3-319-46475-6_43. Amsterdam, Netherlands
2016 doi
-
[12]
King, D. E. Dlib-ml: A machine learning toolkit. Journal of Machine Learning Research, 10: 0 1755--1758, December 2009. URL http://dl.acm.org/citation.cfm?id=1577069.1755843
2009
-
[13]
Fast face-swap using convolutional neural networks
Korshunova, I., Shi, W., Dambre, J., and Theis, L. Fast face-swap using convolutional neural networks. Proceedings of the IEEE International Conference on Computer Vision, pp.\ 3697--3705, Oct. 2017. URL https://doi.org/10.1109/ICCV.2017.397. Venice, Italy
2017 doi
-
[14]
Attribute-guided face generation using conditional cyclegan
Lu, Y., Tai, Y.-W., and Tang, C.-K. Attribute-guided face generation using conditional cyclegan. arXiv:1705.09966v2, Nov. 2018. URL https://arxiv.org/abs/1705.09966
2018 arXiv
-
[15]
Defeating image obfuscation with deep learning
McPherson, R., Shokri, R., and Shmatikov, V. Defeating image obfuscation with deep learning. arXiv:1609.00408v2, September 2016. URL https://arxiv.org/abs/1609.00408
2016 arXiv
-
[16]
Emer s i c , S truc, V., and Peer, P
Meden, B., Z . Emer s i c , S truc, V., and Peer, P. k-same-net: k-anonymity with generative deep neural networks for face deidentification. Entropy, 20 0 (1), January 2018. URL https://doi.org/10.3390/e20010060
2018 doi
-
[17]
and Osindero, S
Mirza, M. and Osindero, S. Conditional generative adversarial nets. arXiv:1411.1784v1, November 2014. URL https://arxiv.org/abs/1411.1784
2014 arXiv
-
[18]
M., Sweeney , L., and Malin , B
Newton , E. M., Sweeney , L., and Malin , B. Preserving privacy by de-identifying face images. IEEE Transactions on Knowledge and Data Engineering, pp.\ 232--243, Feburary 2005. URL https://doi.org/10.1109/TKDE.2005.32
2005 doi
-
[19]
and Winkler, S
Ng, H. and Winkler, S. A data-driven approach to cleaning large face datasets. Proceedings of the IEEE International Conference on Image Processing, pp.\ 343--347, October 2014. URL https://doi.org/10.1109/ICIP.2014.7025068. Paris, France
2014 doi
-
[20]
Poisson image editing
P \'e rez, P., Gangnet, M., and Blake, A. Poisson image editing. ACM Transactions on Graphics, 22 0 (3): 0 313--318, July 2003. URL http://doi.acm.org/10.1145/882262.882269
2003 doi
-
[21]
C., and Fei-Fei, L
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L. ImageNet Large Scale Visual Recognition Challenge . International Journal of Computer Vision, 115 0 (3): 0 211--252, 2015. URL ...
2015 doi
-
[22]
and Sweeney, L
Samarati, P. and Sweeney, L. Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression. Technical Report, 1998. Harvard Data Privacy Laboratory
1998
-
[23]
Y., Steinkraus, D., and Platt, J
Simard, P. Y., Steinkraus, D., and Platt, J. C. Best practices for convolutional neural networks applied to visual document analysis. Proceedings of the IEEE International Conference on Document Analysis and Recognition, 2: 0 958--963, August 2003. URL https://doi.org/10.1109/...
2003 doi
-
[24]
and Zisserman, A
Simonyan, K. and Zisserman, A. Very deep convolutional networks for large-scale image recognition. Proceedings of the International Conference on Learning Representations, May 2015. URL http://arxiv.org/abs/1409.1556. San Diego, CA
2015 arXiv
-
[25]
V., Schiele , B., and Fritz , M
Sun , Q., Ma , L., Joon Oh , S., Gool , L. V., Schiele , B., and Fritz , M. Natural and effective obfuscation by head inpainting. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp.\ 5050--5059, June 2018. URL https://doi.org/10.1109/CVPR.2018.00...
2018 doi
-
[26]
Privacy-protective-gan for privacy preserving face de-identification
Wu, Y., Yang, F., Xu, Y., and Ling, H. Privacy-protective-gan for privacy preserving face de-identification. Journal of Computer Science and Technology, pp.\ 47--60, January 2019. URL https://doi.org/10.1007/s11390-019-1898-8. Beijing, China
2019 doi
-
[27]
Age progression/regression by conditional adversarial autoencoder
Zhang, Z., Song, Y., and Qi, H. Age progression/regression by conditional adversarial autoencoder. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp.\ 4352--4360, 2017. URL https://doi.org/10.1109/CVPR.2017.463. Hawaii, HI
2017 doi
Reviewed May 25, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.