Search papers, labs, and topics across Lattice.
This paper investigates the privacy implications of face-swapping techniques, which are designed to anonymize individuals by replacing their facial features with those of a donor. Despite the initial promise of these methods, empirical evaluations reveal that they still allow for significant identity leakage, prompting an exploration of the underlying mechanisms of this leakage. The authors introduce a linear stochastic model that interprets face-swapping as transformations on identity embeddings, enabling a principled analysis of privacy guarantees and facilitating the derivation of testable predictions regarding leakage.
Face-swapping may not be as secure as it seems, with significant identity leakage that can be quantitatively analyzed and predicted.
Face-swapping has emerged as a promising approach to facial privacy protection, replacing a target individual's appearance with that of a donor while preserving non-facial context. The resulting images visually resemble the donor, and face recognition systems tend to suppress the target's match scores -- ostensibly satisfying privacy requirements. Empirical evaluation across a range of face-swapping models, however, reveals that significant target identity leakage still occurs. This raises a deeper question: why does leakage occur, and can it be predicted? We propose a linear stochastic model that treats face-swappers as transformations on the space of identity embeddings, providing an interpretable account of the leakage mechanism. The model is fit to empirical observations and used to derive testable predictions. The aim is to ground privacy assessments in principled, interpretable analysis, thus making formal privacy guarantees explainable -- and perfectible -- rather than purely observational.