arXiv · 2602.02914
FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation
Abstract
Privacy-preserving face recognition (PPFR) hides facial appearance while retaining machine recognition, whereas perception-preserving face de-identification (De-ID) retains human recognizability while blocking face recognition models. We show that both designs preserve identity signals that an adaptive attacker can extract. We introduce FaceLinkGen, a unified distillation attack that learns from paired protected and original images. Across MinusFace, PartialFace, and DecoyFace, FaceLinkGen regenerates faces accepted by Face++ at rates of 81.0--99.0\% and by Amazon at rates of 74.9--99.2\%. Against four De-ID methods, it raises mixed-gallery Recall@1 to 55.2--89.6\% and remains effective with limited paired data. These results establish adaptive evaluation as essential for measuring facial privacy and show that resistance to fixed recognition or reconstruction models does not prevent identity leakage.
Explore related subjects
Keep this discovery
Wenqi Guo, Mohamed Shehata, Shan Du. 2026-09-03. FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation. https://arxiv.org/abs/2602.02914
Cite the original work for its findings. Save a collection to share your selection of sources.
Discover connections
Connections use source metadata and explicit phrase matches, not verified experimental comparisons.