发表机构
Indian Institute of Technology Madras(印度理工学院马德拉斯分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过模拟攻击审计无镜头近眼传感的身份泄露,发现编码测量虽视觉不可读,但学习型对手仍可高精度恢复身份,表明默认隐私假设不成立。
AI 中文摘要
无镜头近眼传感常被描述为隐私友好型,因为其编码测量在视觉上难以理解。然而,视觉上的不可理解反映的是人类的解读,而非学习型对手能够恢复的内容。因此,我们将身份隐私视为披露表面的系统属性:跨越传感、存储、计算和输出边界的表示。我们在一个36名受试者的封闭集识别协议下,使用固定的已知PSF模拟无镜头注视管道,并采用固定的已知PSF。隐私来自未知或变化的PSF不在我们的研究范围内。报告的成功率是在匹配的线性MLP探针下的经验攻击成功率,并不对更强的对手设定上限。模拟的无镜头测量在匹配的原始眼部裁剪上实现了96.7%的top-1识别率,而MAE嵌入保留了97.7%。仅压缩提供的保护有限:8维PCA和8维瓶颈分别保留了93.2%和91.8%的信息。相比之下,经过单独训练的8维GSPL瓶颈在三个随机种子上平均将单帧恢复率降至77.5%。在源帧不相交的协议下,连续输出的token在38.1%的帧上实现了恢复,而62.1%和72.6%的token分别暴露了身份信息。这些比率反映了所有受试者的信息,包括采集和行为线索,而非内在的眼部生物特征。我们的结果表明,无镜头传感的隐私声明必须在披露边界上进行测试,而不是从原始测量中推断。
英文摘要
Lensless near-eye sensing is often described as privacy-friendly because its coded measurements are visually unintelligible. Yet visual unintelligibility reflects human interpretation, not what a learned adversary can recover. We therefore treat identity privacy as a systems property of disclosure surfaces: representations crossing sensing, storage, computation, and output boundaries. We audit a simulated lensless gaze pipeline under a 36-subject known-gallery closed-set identification protocol with a fixed, known PSF; privacy from an unknown or varying optical key is outside our scope. Reported accuracies are empirical attack success rates under matched linear and MLP probes and do not upper-bound stronger adversaries. Simulated lensless measurements yield 96.7% top-1 identification versus 97.7% for matched original eye crops, while an MAE embedding retains 94.3%. Compression alone offers little protection: 8-D PCA and a matched 8-D bottleneck retain 93.2% and 91.8%, whereas separately trained 8-D GSPL bottlenecks yield 77.5% mean recovery across three seeds. A released 128-way gaze token lowers single-frame recovery to 38.1%, while its residual and continuous gaze output expose 62.1% and 72.6%, respectively. Under a source-frame-disjoint tiled protocol, token summaries reach 39.9% at T=25, showing that repeated-output risk depends on representation and aggregation. These rates reflect all subject-correlated information in the evaluated dataset, including acquisition and behavioral cues, rather than isolating intrinsic ocular biometrics. Ordinary least squares residualization against a six-dimensional crop geometry and intensity summary still leaves lensless recovery at 95.1%. Our results show that privacy claims for lensless sensing must be tested at disclosure boundaries rather than inferred from appearance.
Comments16 pages, 5 figures. Code available at https://github.com/xoxo121/Lensless-Gaze-Is-Not-Private-by-Default