Pith. sign in

REVIEW

Assessing Privacy Risks from Feature Vector Reconstruction Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2202.05760 v1 pith:QOSVMKA2 submitted 2022-02-11 cs.CR cs.CV

classification cs.CRcs.CV
keywords facefeatureprivacyattackscaptureend-to-endfacialimages
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In deep neural networks for facial recognition, feature vectors are numerical representations that capture the unique features of a given face. While it is known that a version of the original face can be recovered via "feature reconstruction," we lack an understanding of the end-to-end privacy risks produced by these attacks. In this work, we address this shortcoming by developing metrics that meaningfully capture the threat of reconstructed face images. Using end-to-end experiments and user studies, we show that reconstructed face images enable re-identification by both commercial facial recognition systems and humans, at a rate that is at worst, a factor of four times higher than randomized baselines. Our results confirm that feature vectors should be recognized as Personal Identifiable Information (PII) in order to protect user privacy.

Discussion (0). Sign in to comment.

Pith tools