Fantômas: Understanding Face Anonymization Reversibility

Todt, Julian 1; Hanisch, Simon 2; Strufe, Thorsten ORCID iD icon 1
1 Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL), Karlsruher Institut für Technologie (KIT)
2 Technische Universität Dresden (TU Dresden)


Face images are a rich source of information that can be used to identify individuals and infer private information about them. To mitigate this privacy risk, anonymizations employ transformations on clear images to obfuscate sensitive information, all while retaining some utility. Albeit published with impressive claims, they sometimes are not evaluated with convincing methodology.

Reversing anonymized images to resemble their real input --- and even be identified by face recognition approaches --- represents the strongest indicator for flawed anonymization. Some recent results indeed indicate that this is possible for some approaches. It is, however, not well understood, which approaches are reversible, and why. In this paper, we provide an exhaustive investigation in the phenomenon of face anonymization reversibility. Among other things, we find that 11 out of 15 tested face anonymizations are at least partially reversible and highlight how both reconstruction and inversion are the underlying processes that make reversal possible.

Zugehörige Institution(en) am KIT Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsjahr 2024
Sprache Englisch
Identifikator ISSN: 2299-0984
KITopen-ID: 1000172319
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Proceedings on Privacy Enhancing Technologies
Verlag De Gruyter
Band 2024
Heft 4
Seiten 24–43
Schlagwörter anonymization, evaluation methodology, reversibility
Nachgewiesen in Dimensions
Verlagsausgabe §
DOI: 10.5445/IR/1000172319
Veröffentlicht am 09.07.2024
DOI: 10.56553/popets-2024-0105
Zitationen: 2
Seitenaufrufe: 64
seit 09.07.2024
Downloads: 13
seit 26.08.2024
