Fantômas: Understanding Face Anonymization Reversibility

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Todt, Julian, Hanisch, Simon, Strufe, Thorsten
Format: Preprint
Veröffentlicht: 2022
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916237196394496
author Todt, Julian
Hanisch, Simon
Strufe, Thorsten
author_facet Todt, Julian
Hanisch, Simon
Strufe, Thorsten
contents Face images are a rich source of information that can be used to identify individuals and infer private information about them. To mitigate this privacy risk, anonymizations employ transformations on clear images to obfuscate sensitive information, all while retaining some utility. Albeit published with impressive claims, they sometimes are not evaluated with convincing methodology. Reversing anonymized images to resemble their real input -- and even be identified by face recognition approaches -- represents the strongest indicator for flawed anonymization. Some recent results indeed indicate that this is possible for some approaches. It is, however, not well understood, which approaches are reversible, and why. In this paper, we provide an exhaustive investigation in the phenomenon of face anonymization reversibility. Among other things, we find that 11 out of 15 tested face anonymizations are at least partially reversible and highlight how both reconstruction and inversion are the underlying processes that make reversal possible.
format Preprint
id arxiv_https___arxiv_org_abs_2210_10651
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Fantômas: Understanding Face Anonymization Reversibility
Todt, Julian
Hanisch, Simon
Strufe, Thorsten
Cryptography and Security
Machine Learning
Face images are a rich source of information that can be used to identify individuals and infer private information about them. To mitigate this privacy risk, anonymizations employ transformations on clear images to obfuscate sensitive information, all while retaining some utility. Albeit published with impressive claims, they sometimes are not evaluated with convincing methodology. Reversing anonymized images to resemble their real input -- and even be identified by face recognition approaches -- represents the strongest indicator for flawed anonymization. Some recent results indeed indicate that this is possible for some approaches. It is, however, not well understood, which approaches are reversible, and why. In this paper, we provide an exhaustive investigation in the phenomenon of face anonymization reversibility. Among other things, we find that 11 out of 15 tested face anonymizations are at least partially reversible and highlight how both reconstruction and inversion are the underlying processes that make reversal possible.
title Fantômas: Understanding Face Anonymization Reversibility
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2210.10651