This work aims to answer the question of whether it is possible to generate irreversible protected templates when the PolyProtect biometric template protection method is applied to face embeddings using system-specific keys (i.e., the same C and E parameters, which define the transform, are applied to all subjects' face embeddings), instead of the traditional subject-specific keys (i.e., each subject has their own C and E parameters). This is important for determining whether we can perform de-duplication of face identities in the PolyProtected domain, which is not possible in the subject-specific key scenario due to the clash with PolyProtect's unlinkability property (i.e., one could generate multiple protected templates belonging to the same identity, using different C and E parameters, such that those templates cannot be linked to each other). We present experiments (reproducible using our open-source code) to prove that there exist at least three ways of systematically selecting system-specific keys that produce irreversible PolyProtected templates: (i) from pre-selected subject-specific keys, (ii) by applying a previously proposed key selection algorithm to random vectors, and (iii) by approximating a "good" C/E pair distribution from which system-specific keys can be constructed. Our findings thus point to the conclusion that it is, indeed, possible to safely operate PolyProtect in the system-specific key scenario without degrading the template protection potential. This opens up the possibility for identity de-duplication in the PolyProtected domain.
Figures & tables
Fig. 1: We investigate the selection of system -specific keys ( C , E ) for the PolyProtect BTP method, such that the protected templates ( P1 , …, PN ), generated from the face embeddings ( E1 , …, EN ) of all identities enrolled in the face recognition system ( I1 , …, IN ) are irreversible , i.e., it is impossible to recover Ei from its corresponding Pi . (Face images from SOTERIA [ 26 ] .)
Fig. 2: Mapping 512-dimensional V to P via PolyProtect, using C=[c1,c2,...,c5] and E=[e1,e2,...,e5] , for different amounts of overlap.
Fig. 3: Verification accuracy across unprotected face templates (embeddings) generated using five different face recognition models on three face datasets.
Fig. 4: Accuracy of template matching in the PolyProtected domain, for protected templates created from EdgeFace and iResNet100 face embeddings in two scenarios: (i) System -specific keys used for PolyProtect (i.e., the same C and E parameters used for all face embeddings across all identities), and (ii) Sample -specific keys used for PolyProtect (i.e., different C and E parameters used for each face embedding, including different embeddings from the same identity). Accuracy for unprotected embeddings is shown as the baseline.
Fig. 5: Inversion scores for PolyProtected templates generated from EdgeFace and iResNet100 face embeddings when the keys ( C , E ) were: system-specific + random (gray histogram), subject-specific + selected using the key selection algorithm from [ 24 ] (cyan histogram), and system-specific + selected at random from the subject-specific keys (blue histogram). Our main focus is the blue histogram. The inversion was performed using the cosine-based numerical solver from [ 24 ] . The two vertical black lines represent different thresholds at which the inversion success rate (ISR) was computed for Table I .
Model
Dataset
ISR (%)
@ 0.1% FMR
@ 0.01% FMR
Sb.
Sy.
R-Sy.
Sb.
Sy.
R-Sy.
EdgeFace
Multi-PIE
0.5
0.8
100
0
0
99.2
SOTERIA
0
0.6
91.3
0
0
90.1
iCarB-Face
1.1
1.3
91.6
0.2
0
89.7
iResNet100
Multi-PIE
0.5
0.5
100
0
0
99.4
TABLE I: Inversion success rate (ISR) for Fig. 5 at the two FMR thresholds, for EdgeFace and iResNet100 face embeddings protected via PolyProtect when the keys ( C , E ) were: subject-specific + selected using the key selection algorithm from [ 24 ] ( Sb. ) VS system-specific + selected from the subject-specific keys ( Sy. ) VS system-specific + random ( R-Sy. ).
Fig. 6: Inversion scores for PolyProtected templates generated from EdgeFace and iResNet100 face embeddings when the keys ( C , E ) were system-specific and: selected by applying the key selection algorithm from [ 24 ] to random vectors (purple histogram) versus chosen at random from subject-specific keys selected by applying the same key selection algorithm to face embeddings (blue histogram, from Fig. 5 ). Our main focus is the purple histogram. The inversion was performed using the numerical solver from [ 24 ] . The two vertical black lines represent different thresholds at which the inversion success rate (ISR) was computed for Table II .
Model
Dataset
ISR (%)
@ 0.1% FMR
@ 0.01% FMR
RV
SK
RV
SK
EdgeFace
Multi-PIE
0.3
0.8
0
0
SOTERIA
0.2
0.6
0
0
iCarB-Face
0.3
1.3
0
0
iResNet100
Multi-PIE
0.1
0.5
0
0
TABLE II: Inversion success rate (ISR) for Fig. 6 at the two FMR thresholds, for EdgeFace and iResNet100 face embeddings protected via PolyProtect when the keys ( C , E ) were: system-specific + selected using the key selection algorithm from [ 24 ] applied to random vectors ( RV ) VS system-specific + chosen from subject-specific keys selected for individual face embeddings ( SK – corresp. to Sy. in Table I ).
Fig. 7: Left column: Distribution of ( Ci , Ei ) pairs from “good” keys selected by the key selection algorithm [ 24 ] , when it was applied to random vectors and when different thresholds (negative cosine distance) were used to define irreversibility. Right column: Spearman’s rank correlation coefficient matrix, showing weak monotonic correlations across the different ( Ci , Ei ) pairs.
Fig. 8: Inversion scores for PolyProtected templates generated from EdgeFace and iResNet100 face embeddings when the keys ( C , E ) were system-specific and based on applying the key selection algorithm from [ 24 ] to random vectors. The sequences of 5 corresponding C and E parameter pairs were: constructed by choosing samples from a “good” ( Ci , Ei ) pair distribution (orange histogram) versus chosen directly from a list of pre-determined sequences (purple histogram, from Fig. 6 ). Our main focus is the orange histogram. The inversion was performed using the numerical solver from [ 24 ] . The two vertical black lines represent different thresholds at which the inversion success rate (ISR) was computed for Table III .
Model
Dataset
ISR (%)
@ 0.1% FMR
@ 0.01% FMR
Dis.
Seq.
Dis.
Seq.
EdgeFace
Multi-PIE
2.1
0.3
0.1
0
SOTERIA
2.6
0.2
0.2
0
iCarB-Face
3.3
0.3
0.2
0
iResNet100
Multi-PIE
3.7
0.1
0.2
0
TABLE III: Inversion success rate (ISR) for Fig. 8 at the two FMR thresholds, for EdgeFace and iResNet100 face embeddings protected via PolyProtect when the keys (based on applying the key selection algorithm [ 24 ] to random vectors) were system-specific and: selected from a “good” ( Ci , Ei ) pair distribution ( Dis. ) VS chosen from a list of pre-selected ( C , E ) sequences ( Seq. – corresp. to RV in Table II ).
Fig. 9: Recognition accuracy for PolyProtected templates when the keys ( C , E ) were generated randomly versus using the key selection algorithm from [ 24 ] . In the latter scenario, the keys were either subject-specific, or system-specific and selected using the three methods from Sections III-C – III-E : from subject-specific keys, from random vectors, or from a C / E distribution. Unprotected template accuracy is shown as a baseline.