Generalization of identity extraction to PPFR methods without frequency-domain obfuscation
Determine whether the identity-extraction vulnerability demonstrated by FaceLinkGen under a minimal-knowledge attack setting extends to privacy-preserving face recognition systems whose template generation does not rely on frequency-domain obfuscation (i.e., systems that do not primarily preserve high-frequency information while obfuscating low-frequency content).
References
Whether this generalizes to future methods that do not rely on frequency-domain obfuscation remains an open question.
— FaceLinkGen: Rethinking Identity Leakage in Privacy-Preserving Face Recognition with Identity Extraction
(2602.02914 - Guo et al., 2 Feb 2026) in Section 6: What If the Attacker Knows Almost Nothing?