Lensless near-eye sensing is often described as privacy-friendly because its coded measurements are visually unintelligible. Yet visual unintelligibility reflects human interpretation, not what a learned adversary can recover. We therefore treat identity privacy as a systems property of disclosure surfaces: representations crossing sensing, storage, computation, and output boundaries. We audit a simulated lensless gaze pipeline under a 36-subject known-gallery closed-set identification protocol with a fixed, known PSF; privacy from an unknown or varying optical key is outside our scope. Reported accuracies are empirical attack success rates under matched linear and MLP probes and do not upper-bound stronger adversaries. Simulated lensless measurements yield 96.7% top-1 identification versus 97.7% for matched original eye crops, while an MAE embedding retains 94.3%. Compression alone offers little protection: 8-D PCA and a matched 8-D bottleneck retain 93.2% and 91.8%, whereas separately trained 8-D GSPL bottlenecks yield 77.5% mean recovery across three seeds. A released 128-way gaze token lowers single-frame recovery to 38.1%, while its residual and continuous gaze output expose 62.1% and 72.6%, respectively. Under a source-frame-disjoint tiled protocol, token summaries reach 39.9% at T=25, showing that repeated-output risk depends on representation and aggregation. These rates reflect all subject-correlated information in the evaluated dataset, including acquisition and behavioral cues, rather than isolating intrinsic ocular biometrics. Ordinary least squares residualization against a six-dimensional crop geometry and intensity summary still leaves lensless recovery at 95.1%. Our results show that privacy claims for lensless sensing must be tested at disclosure boundaries rather than inferred from appearance.
Figures & tables
Parameter
Assumption / configuration
Gallery
36 known enrolled identities
Enrollment
75 labeled frames/identity ( 2,700 samples)
Evaluation
25 held-out frames/identity ( 900 samples)
Gaze model
Trained on subject-disjoint data
Architecture / weights
Known / not provided to attacker
PSF
Fixed across captures; stored PSF assumed known
Table 1 : Threat-model parameters for the disclosure-surface audit.
ID
Surface
Size / dim.
Exposure boundary
L0
Original eye crop
3072
Reference
L1
Simulated lensless measurement
3072
Sensor / log
L2
MAE CLS embedding
192
Internal
L3
GSPL bottleneck
8
Internal
L3 ′
PCA of L2
8
Internal control
L4
Quantized gaze token
128 -way
Released output
Table 2 : Evaluated disclosure surfaces and deployment boundaries. For categorical L4, 128 -way denotes vocabulary cardinality.
PSF / simulation condition
Accuracy (%)
Stored nominal L1 TIFF
97.2
Matched nominal resimulation
95.3
Alternative phase-mask PSF
96.6
Horizontal shift (2 pixels)
95.7
Additive noise ( 0.01max(Px) )
95.6
Table 3 : Linear identification for stored nominal L1 and matched forward-model resimulations. These test local simulation stability, not generality across hardware.
Disclosure surface / control
Size / dim.
Acc. (%)
Interval
Sensor and representation surfaces
L0: Original eye crop
3072
97.7
[96.7, 98.5]
L1: Simulated lensless measurement
3072
96.7
[95.4, 98.4]
L2: MAE embedding
192
94.3
[92.4, 96.6]
L3: GSPL bottleneck (separate model)
8
78.6
[74.2, 81.9]
L3 ′ : PCA projection of L2
8
93.2
[91.2, 96.2]
Table 4 : Primary grouped-block MLP leakage ladder. Intervals are descriptive percentile-bootstrap intervals over five probe-seed means and exclude encoder-retraining and subject-split uncertainty. 128 denotes categorical vocabulary cardinality.
Surface
T=1
T=25
Quantized gaze token
34.0±1.9
39.9±2.0
Continuous unit gaze
55.7±3.0
41.8±0.6
Local residual
44.9±2.1
36.8±1.9
Table 5 : Identity recovery under source-frame-disjoint tiles; mean ± standard deviation over 20 trials.
RGB camera-based surveillance systems enable human action recognition for public safety and healthcare, yet raise serious privacy concerns. Existing methods rely on post-capture algorithms, which fail to protect privacy during data acquisition. We propose Lens Privacy Sealing (LPS), a simple hardware solution that physically obscures camera lenses with adjustable laminating film, providing pre-sensor privacy protection at minimal cost. Unlike software methods or expensive engineered optics, LPS achieves strong privacy through stochastic multi-layer scattering that is physically irreversible. We introduce the P3AR dataset for privacy-preserving action recognition, featuring both large-scale replay-captured (P3AR-NTU, 114K videos) and real-world collected (P3AR-PKU) subsets with privacy attribute annotations. To handle video degradation from LPS, we propose MSPNet, a single-stage framework incorporating Inter-Frame Noise Suppressor (IFNS) and Cross-Frame Semantic Aggregator (CFSA), enhanced by contrastive language-image pre-training for robust semantic extraction. Extensive experiments demonstrate that MSPNet with IFNS and CFSA nearly doubles action recognition accuracy compared to baseline methods while suppressing identity recognition to low levels. Comprehensive validation shows LPS achieves a superior privacy-utility trade-off compared to state-of-the-art hardware methods, resists reconstruction attacks including PSF inversion and data-driven recovery, and generalizes robustly across optical configurations and challenging environments. Code is available at https://github.com/wangzy01/MSPNet.
Mengyuan Liu, Ziyi Wang, Peiming Li +1
State Key Laboratory of General Artificial Intelligence, Peking University, Shenzhen Graduate School · Department of Computer Science and Engineering, State University of New York at Buffalo
Video recording on smart glasses exposes more than faces. Continuous capture reveals full-body biometric signatures, including gait, posture, and silhouette, that enable person re-identification (ReID) even after conventional face sanitization. We present MIRAGE, a three-tier architecture for privacy-preserving smart glasses that enforces full-body privacy, supports synthetic full-body replacement, and retains encrypted recovery material for consent-based restoration. We implement MIRAGE on a Raspberry Pi~5 (a CPU-only proxy for smart-glasses compute), companion phones, and a cloud generative backend. Compared to prior systems, MIRAGE achieves 0.948 AP and 0.976 AR while accurately detecting the complete visible body. Its bounding box masking reduces learned silhouette-based ReID to essentially random guessing, with 10.86% Rank-1 accuracy compared with an 11.12% measured chance level. Even against an adaptive adversary retrained on MIRAGE's sanitized pose signals, Rank-1 gait identification drops from 90.25% to 26.20%, removing 72.5% of the adversary's identification advantage.
Muhammad Umair, Muhammad Danial Maqbool, Fatima Arshad Cheema +4
Lahore University of Management Sciences (LUMS) Pakistan · Munster Technological University Ireland
Privacy-preserving face recognition (PPFR) and face anonymization have different goals, but both must retain some identity-related information for their intended use. We show that an adaptive attacker can learn this information. We propose FaceLinkGen, a simple distillation-based attack that trains a face recognition model to map protected inputs back to standard face embeddings. FaceLinkGen applies to keyless PPFR systems and perception-preserving face de-identification (De-ID) systems. For PPFR, the recovered embeddings can be used to regenerate faces that match the original person. Across MinusFace, PartialFace, and DecoyFace, the regenerated faces achieve acceptance rates of 81.0--99.4% on Face++ and 74.9--99.6% on Amazon. For De-ID, FaceLinkGen links protected faces to unprotected images of the same person, reaching Recall@1 values of 48.4--89.6% in the one-side-protected setting across the evaluated methods. FaceLinkGen exposes identity leakage across all evaluated methods, including DecoyFace and WDP, whose protection resists the tested U-Net attacks on face recovery and protected-to-unprotected linkage, respectively. The attack also remains effective when trained with limited paired data. Code is available at https://github.com/weathon/FaceLinkGenRelease.
Wenqi Guo, Qingyun Qian, Mohamed Shehata +1
Department of Computer Science, Mathematics, Physics and Statistics University of British Columbia, Kelowna, BC, Canada