A RE-EVALUATION OF FACIAL PRIVACYUBC / RESEARCH / 2026

YOUR FACE.STILLTHERE.

A protected image can still carry an identity. FaceLinkGen shows how simple distillation recovers the signal that facial privacy systems leave behind.

FIG. 01 / IDENTITY PERSISTS
01 / ORIGINAL[ x ]
02 / REGENERATED[ OUTPUT ]
IDENTITY
RECOVERED
Different image.
Recognizable identity.
SIMPLE DISTILLATION. SHARED IDENTITY SIGNAL.
A PAPER BY

Wenqi Guo / Mohamed S. Shehata / Shan Du

University of British Columbia
Kelowna, Canada

01 / THE FINDINGA SHARED STRUCTURAL WEAKNESS

TWO GOALS.
ONE LEAK.

Facial privacy systems preserve useful information. That same information can give an adaptive attacker a path back to identity.

01.A / PRIVACY-PRESERVING FACE RECOGNITION

Hide the appearance.
Keep recognition.

Keyless PPFR preserves machine-readable identity so a server can verify a person. FaceLinkGen learns to extract that signal and regenerate a recognizable face.

MINUSFACE / PARTIALFACE / DECOYFACE
01.B / PERCEPTION-PRESERVING DE-IDENTIFICATION

Keep the appearance.
Block recognition.

Perception-preserving De-ID retains a face's human recognizability. FaceLinkGen adapts the recognizer to recover identity linkage from those remaining cues.

TIP-IM / WDP / PERCEPTFACE / PROTEGO
02 / THE METHODINTENTIONALLY SIMPLE

TEACH. DISTILL.
RE-LINK.

One frozen teacher. One trainable student. Paired original and protected images.

The student learns to map protected inputs into the teacher's identity embedding space. For PPFR, Arc2Face turns those embeddings into faces. For De-ID, the adapted model links identities across images.

THE DE-ID ADDITION /

Cross-image identity distillation strengthens linkage across photos. An original-domain-preserving loss maintains recognition of unprotected faces.

03 / THE EVIDENCEREPORTED IN THE PAPER

THE NUMBERS
LOOK BACK.

7

PROTECTION
METHODS TESTED

Regenerated faces pass identity verification.

FACELINKGEN U-NET (ADAMW + IN)

READ THE CONTEXT /

Face++ and Amazon are independent verifiers, not attack targets. Direct U-Net reconstruction succeeds on MinusFace and PartialFace; distillation also recovers identity from DecoyFace.

04 / SEE FOR YOURSELFQUALITATIVE RESULTS

THE FACE
COMES THROUGH.

Direct reconstruction can recover a decoy. Distillation follows the retained identity signal.

SAME SOURCE FACE / THREE OUTPUTS
01 / ORIGINALx
02 / U-NETDECOY IDENTITY
03 / FACELINKGENDISTILLATION

DecoyFace: U-Net reconstructs a different identity. The distillation attack regenerates a face resembling the original identity.

LESS DATA. STILL LINKABLE.

The attack also learns
from limited pairs.

The few-sample experiments use 256-8,192 identities for PPFR and 32-1,024 for De-ID, with two images per identity. Effectiveness varies by protection method and sample count.

05 / TAKE A CLOSER LOOKFACELINKGEN

PRIVACY NEEDS
AN ADAPTIVE TEST

FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation

READ THE FULL PAPER (PDF, opens in a new tab)
CITE THIS WORKBIBTEX
@unpublished{guo2026facelinkgen,
  title = {FaceLinkGen: A Re-evaluation of Identity Leakage in Privacy-Preserving Face Recognition and Face Anonymization Systems Using Simple Distillation},
  author = {Guo, Wenqi and Shehata, Mohamed S. and Du, Shan},
  year = {2026},
  note = {Research manuscript, University of British Columbia}
}

DecoyFace: more comparisons

DecoyFace comparisons from the paper

Within each group of three columns: original, U-Net reconstruction, and distillation output.