Conceptio › Archive › arXiv CS
arXiv CSopen access

A Deeper Dive into the Irreversibility of PolyProtect: Making Protected Face Templates Harder to Invert

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

1

A Deeper Dive into the Irreversibility of PolyProtect: Making Protected Face Templates Harder to Invert

arXiv:2605.03857v1 [cs.CV] 5 May 2026

Vedrana Krivokuća Hahn, Jérémy Maceiras, Sébastien Marcel, Senior Member, IEEE

Abstract—This work presents a deeper analysis of the “irreversibility” property of PolyProtect, a biometric template protection method initially proposed for securing face embeddings. PolyProtect transforms embeddings into protected templates via multivariate polynomials, whose coefficients and exponents are distinct for each subject enrolled in the face recognition system. A polynomial is applied to consecutive sets of elements from a given embedding, where the amount of overlap between the sets is a tunable parameter. We begin our irreversibility analysis by demonstrating that PolyProtected templates are easier to invert using a numerical solver based on cosine distance, as opposed to Euclidean distance (used in the earlier PolyProtect work). To make this inversion more difficult, we then propose a “key selection algorithm”, which tries to choose “keys” (coefficients and exponents of the PolyProtect polynomial) that enhance the irreversibility of PolyProtected templates, compared to when the keys are purely random. Our experiments show that this algorithm is effective at generating PolyProtected templates that are significantly more difficult to invert, and that it approximately equalises the irreversibility of PolyProtected templates generated using different “overlap” parameters. This allows for better control of the irreversibility versus accuracy trade-off, known to exist across different overlaps. We also show that accuracy in the PolyProtected domain can be affected by the range in which the embedding elements lie, but that this can be improved by normalizing the embeddings prior to applying PolyProtect. This work is reproducible using our open-source code1 . Index Terms—biometrics, face, face recognition, biometric template protection, PolyProtect, irreversibility, non-invertibility.

I. I NTRODUCTION UR faces are becoming indispensable tools for proving our identities in various applications (e.g., unlocking smartphones, accessing bank accounts, verifying passports at electronic gates). The convenience of this form of authentication is evident, as is the heightened security and identity assurance offered by the uniqueness of our faces. There is, however, a hidden cost: our privacy. As more and more organisations collect our face data for such purposes, concerns arise around how this data is being stored and whether (and with whom) it is being shared. The problem is that, the more our face data gets distributed, the more likely it is to be misused; e.g., by creating presentation attacks or deepfakes to impersonate us and potentially gain unlawful access to protected resources, or by tracking us (for profiling or stalking purposes) across different applications in which the same data is enrolled. So, it is crucial that face data never be stored in the clear: it should always be protected, such that, if the databases of the underlying face recognition systems are jeopardised, the

O

All authors are with Idiap Research Institute in Martigny, Switzerland. 1 Link will be provided upon paper acceptance.

original, irreplaceable face information remains inaccessible. This is the realm of Biometric Template Protection (BTP). The aim of BTP is to convert a biometric feature vector, or “template”, into a protected template, from which it is impossible to recover the original one. In this paper, we are interested in the application of BTP to face templates. Modern face recognition systems are based on deep learning architectures that are trained to map face images to fixedlength numerical representations called “embeddings”. It has been shown that face embeddings are invertible [1], in that they can be used to recover an approximation of the underlying face image [2]–[5], and that certain soft biometric attributes (e.g., sex, race, age, hair colour) can be extracted from these representations [6], [7]. These findings underline the need to protect embeddings in order to prevent recovery of the original face information, thereby protecting the privacy of the face recognition system users. This is where BTP comes into play. A recent survey of face BTP methods [8], as well as Part II of the new Handbook of Biometric Template Protection [9], revealed two broad approaches: applying handcrafted (humandesigned) BTP methods to learned face embeddings, and using neural networks to learn the BTP algorithms. Handcrafted BTP methods include: feature transformations [10], which involve transforming a biometric template from its original feature space to a new, protected space (e.g., [11], [12]); biometric cryptosystems [13], which most commonly involve binding an external key with the biometric template (e.g., [14], [15]); and homomorphic encryption [16], which allows us to compare reference and probe templates in encrypted form (e.g., [17]–[19]). Learned BTP methods [20] include: training a neural network to learn the mapping from a biometric template to a pre-defined random code (e.g., [21], [22]); or training a neural network to learn its own representation of a protected template (e.g., [23]–[25]). While learned BTP methods may allow for higher complexity and thus potentially the generation of more secure protected templates, handcrafted methods have two chief advantages that make them easier to adopt in practice: (i) they can more readily be integrated into existing biometric systems (e.g., as a module after the feature extractor), and (ii) they tend to be easier to evaluate, since the algorithms are designed by humans (i.e., not learned by neural networks) so their properties are more explicit. For these reasons, in our work we adopt a handcrafted BTP method. The context for this work is defined by a project that aims to use BTP to develop a privacy-preserving face identification system for humanitarian aid distribution. This is similar to the context in [26], except that the end goal of our project is different. Nevertheless, as the global target in both cases is a humanitarian use-case, the criteria for selecting a suitable BTP

2

method were similar. In particular, for our work, the chosen BTP method should possess the following characteristics: easy and lightweight to implement, modular (can be integrated into an existing face recognition system), satisfies the main BTP criteria (recognition accuracy, irreversibility, unlinkability), and ideally comes with open-source code. So, similarly to the reasoning outlined in [26], these requirements narrowed our selection to handcrafted, as opposed to learned, BTP methods. Then, within this category, biometric cryptosystems were eliminated due to known accuracy issues and envisaged implementation difficulties in our use-case, and homomorphic encryption was deemed unsuitable due to its computational complexity and the need to safely store the decryption key (which cannot be guaranteed in a volatile humanitarian setting). So, we settled on the feature transformations category, in which the PolyProtect method [12] was found to most closely align with our project requirements. PolyProtect transforms face embeddings into protected templates via multivariate polynomials, whose parameters (coefficients, C, and exponents, E) are unique for each subject enrolled in the face recognition system. A polynomial is applied to consecutive sets of elements from a given embedding, where the amount of overlap between the sets is a tunable parameter. PolyProtect has already been shown [12], [26] to satisfy the three crucial BTP criteria: recognition accuracy, irreversibility, and unlinkability. Our goal is to build on this evaluation, with a deeper dive into the “irreversibility” criterion. Our ultimate aim is to make PolyProtected templates more difficult to invert, by selecting the C and E parameters in a smarter (i.e., not purely random) way. This focus is illustrated in Fig. 1.

Fig. 1. The focus of this work (highlighted in yellow) is on enhancing the irreversibility of PolyProtected templates generated from face embeddings, by selecting the polynomial coefficients, C, and exponents, E, such that it is more difficult (ideally impossible) to invert a PolyProtected template to recover the unprotected embedding. (Source of face image: SOTERIA [27].)

Concretely, our contributions are the following: • Firstly, we evaluate the recognition accuracy attainable by the protected templates when PolyProtect is applied to face embeddings generated by two different face recognition models: iResNet100 and EdgeFace. We show that,

although the two sets of embeddings have comparable accuracy in the unprotected domain, the iResNet100 embeddings result in significantly worse accuracy in the protected domain. We attribute this to the larger range in which the iResNet100 embedding elements lie, which causes greater intra-class variance when the PolyProtect transform is applied to these embeddings (compared to those generated by the EdgeFace model). We then propose a simple fix: normalizing the embeddings prior to applying the PolyProtect transform. This considerably improves the accuracy of the protected templates, making PolyProtect applicable to embeddings in any range. • Secondly, we launch into our analysis of the irreversibility of PolyProtect by challenging the definition of the worstcase attacker from the original work [12]. Specifically, we investigate an alternative numerical solver for recovering a face embedding from its PolyProtected template: one based on cosine distance, as opposed to the original solver based on Euclidean distance. We show that the cosine-based solver is the more effective inversion tool, so it should replace the Euclidean-based solver in our definition of the capabilities of the worst-case attacker. • Thirdly, we propose a promising method for significantly improving the irreversibility of PolyProtect against our new, more powerful worst-case attacker. The method tries to select “keys” (i.e., coefficients and exponents of the PolyProtect polynomial) that are more likely (than random keys) to generate “irreversible” protected templates. Use of this method results in an important additional effect: the irreversibility of PolyProtected templates generated using different “overlap” parameters is approximately equalised. This gives us more control over the irreversibility versus accuracy trade-off, known to exist across different overlaps [12], [26], by allowing us to tune the overlap to obtain acceptable recognition accuracy while achieving a high (and approximately equal) degree of irreversibility regardless of the selected overlap. The remainder of this paper is structured as follows. Section II details our experimental set-up, including a description of the PolyProtect BTP method, and the face recognition models and datasets used for the PolyProtect evaluation. Section III evaluates PolyProtect’s recognition accuracy, which is an important first step for assessing its practical utility. Section IV then dives into the irreversibility analysis, which focuses on establishing the feasibility of recovering a face embedding from its PolyProtected template using two different numerical solvers. Section V builds on the analysis from Section IV by presenting a new key selection algorithm that significantly improves the irreversibility of PolyProtect and helps to effectively balance the known irreversibility versus accuracy trade-off. Finally, Section VI concludes this work and presents potential future directions. II. E XPERIMENTAL S ET- UP This section starts with a brief description of PolyProtect, the BTP method being studied in this work, in Section II-A. Section II-B then details the face recognition models selected

3

for the generation of face embeddings, to which PolyProtect will be applied, and the face datasets that will serve as the image sources for these embeddings.

were randomly generated, unique integers in the range [1, 5]. Regarding the choice of values for C, we used the [-50, 50] range as in [12], so all sets of Cs consisted of 5 randomly generated, unique, non-zero integers in this range.

A. PolyProtect: The selected BTP method PolyProtect, proposed in [12] as a BTP method for face embeddings, works as follows. Let V = [v1 , v2 , ..., vn ] denote an n-dimensional face embedding. PolyProtect transforms V into another, lower-dimensional feature vector, P = [p1 , p2 , ..., pk ] (where k < n), which is the protected version of V . This is achieved by mapping sets of m (where m << n) consecutive elements from V to single elements in P via multivariate polynomials defined by m subject-specific (i.e., distinct for each subject enrolled in the face recognition system) coefficients, C = [c1 , c2 , ..., cm ], and exponents, E = [e1 , e2 , ..., em ]. The first m elements in V (i.e., v1 , v2 , ..., vm ) are transformed into the first element in P (i.e., p1 ) via Eq. (1): em p1 = c1 v1e1 + c2 v2e2 + ... + cm vm

(1)

The elements of V used to generate p2 depend on the chosen amount of overlap between successive sets of elements. The minimum overlap is 0, in which case the elements of V in each set would be unique, and the maximum is m − 1, in which case successive sets would share m − 1 elements. Eqs. (2) and (3) define the mapping from V to p2 for overlaps of 0 and m − 1, respectively: e1 e2 em p2 = c1 vm+1 + c2 vm+2 + ... + cm vm+m

(2)

em p2 = c1 v2e1 + c2 v3e2 + ... + cm vm+1

(3)

The remaining elements in P (i.e., p3 , ..., pk ) are generated in a similar manner, until all the elements in V have been used up. If the last set of elements is incomplete because the dimensionality of V is not divisible by the required number of sets (defined by m and the amount of overlap), V is padded by a sufficient number of zeros to complete the last set. Since the analysis presented in this paper will be based on 512-dimensional face embeddings (see Section II-B), Fig. 2 illustrates the transformation from a 512-dimensional V to P , for overlaps 0 – 4, when m = 5. It is evident that the dimensionality of P is influenced by the amount of overlap used in the V → P mapping, i.e., larger overlap → larger P . This has been shown to have an effect on the recognition accuracy and irreversibility properties of PolyProtect [12], [26], which will be further investigated in this paper. For the PolyProtect evaluations presented in the next sections, we chose m = 5, as in [12], meaning that each element in P was generated using 5 consecutive elements from V , as illustrated for different overlaps in Fig. 2. As explained in [12], this setting was inspired by the Abel-Ruffini theorem, which states that there is no closed-form algebraic expression for solving polynomials of degree 5 or higher with arbitrary coefficients. Furthermore, as in [12], we also chose not to set m > 5, since this would require using exponents larger than 5 in the PolyProtect transform, which may obliterate small embedding elements. Consequently, the exponents, E,

B. Selected face recognition models and datasets Recall that the aim of this paper is to dig deeper into the irreversibility of PolyProtect, and the context is a project focusing on the protection of face templates. So, in order to perform this analysis, the first step was to generate the face templates to which PolyProtect would be applied. Since modern face recognition systems employ neural-network-based models for the extraction of face templates (“embeddings”), these were the types of feature extractors we were interested in. To select the best face recognition model(s) for our study, we evaluated five state-of-the-art models to which we have open-source access: iResNet50 and iResNet1002 [28], [29], EdgeFace and EdgeFace-XS3 [30], and FaceNet4 [31]. All five models generate 512-dimensional face embeddings. These models were applied to three different face datasets, to extract the face embeddings from the underlying face images. The three face datasets used in this study were selected to represent three different image acquisition scenarios. They include: 5 • Multi-PIE [32]: Contains face images of 337 subjects. The images were captured in a very controlled environment, using multiple cameras fixed at different angles. We randomly selected 10 images per subject across the 3 frontal cameras (14 0, 05 1, and 05 0), which resulted in a total of 3,370 face images. 6 • SOTERIA [27]: Contains face videos of 70 subjects. The (bona-fide) videos were captured in a less controlled environment than Multi-PIE, using the frontal (“selfie”) and main (back) cameras of five different mobile phones (Apple iPhones 6s and 12, Xiaomi Redmi 6 Pro and 9A, and Samsung Galaxy S9), under various lighting conditions. We randomly selected 10 frontal frames per subject across the five phones, which resulted in a total of 700 face images. 7 • iCarB-Face [33]: Contains face videos of 198 subjects. The videos were captured inside a car, using a nearinfrared camera, while the subjects were seated in the driver’s seat. We selected 4 video frames per subject, when the subject wore a neutral facial expression and no accessories: 2 when the car was parked indoors and the other 2 when it was parked outdoors, with the subject’s eyes being open in one image and closed in the other. This resulted in a total of 792 face images. To select the best face recognition model(s) for our study, the verification accuracy for each of the five sets of extracted face embeddings was computed on each of our three datasets. 2 From https://github.com/deepinsight/insightface/tree/master/model zoo, converted to PyTorch via https://github.com/nizhib/pytorch-insightface 3 https://github.com/otroshi/edgeface 4 https://github.com/timesler/facenet-pytorch 5 https://www.cs.cmu.edu/afs/cs/project/PIE/MultiPie 6 https://www.idiap.ch/en/scientific-research/data/soteria 7 https://www.idiap.ch/en/scientific-research/data/icarb-face

4

Fig. 2. Mapping 512-dimensional V to P via PolyProtect, using C = [c1 , c2 , ..., c5 ] and E = [e1 , e2 , ..., e5 ], for different amounts of overlap.

Within each set of embeddings, all possible pairs were compared in terms of cosine distance, which resulted in: 3,150 genuine and 241,500 impostor scores for Multi-PIE; 15,165 genuine and 5,661,600 impostor scores for SOTERIA; and 1,194 genuine and 312,042 impostor scores for iCarB-Face. Fig. 3 compares the resulting verification accuracy of the five face recognition models on our three datasets, in terms of the False Non-Match Rate (FNMR) and False Match Rate (FMR).

Fig. 3. Detection Error Trade-off (DET) plots comparing the verification accuracy across face embeddings (unprotected face templates) generated using five different face recognition models, on three face datasets.

From Fig. 3, we see that, overall, iResNet100 achieves the highest accuracy, closely followed by EdgeFace. So, both iResNet100 and EdgeFace were selected as our baseline face recognition models, whose face embeddings would be used in the first step of the PolyProtect evaluation: recognition accuracy in the protected domain, covered in Section III.

The first step was to apply PolyProtect to our iResNet100 and EdgeFace face embeddings (from Section II-B), in order to transform them into protected templates. This transformation was performed using the PolyProtect parameters specified in Section II-A, separately for each “overlap” in the range [0, 4]. This means that we ended up with a separate set of protected face templates for each of our two sets of face embeddings (iResNet100 and EdgeFace), from each of our three datasets (Multi-PIE, SOTERIA, and iCarB-Face), and for each of the five aforementioned PolyProtect overlaps. Then, within each of these 30 sets of protected face templates, we computed the cosine distance (comparison score) between every possible pair of templates. Finally, the resulting scores were used to calculate the verification accuracy in the protected domain, in terms of FMR and FNMR. Fig. 4 presents the verification accuracy in our different evaluation scenarios, in terms of DET plots. Each plot compares the accuracy of the unprotected face templates from a particular model and dataset, against the accuracy of the corresponding PolyProtected templates when different amounts of overlap are used for the transform.

III. P OLY P ROTECT E VALUATION : ACCURACY Although the main aim of this paper is to dig deeper into the irreversibility of PolyProtect, it is important to first demonstrate that this BTP method allows for acceptable recognition accuracy in the protected domain. This is because, when a BTP method is integrated into a face recognition system in practice, we must ensure that the ability of that system to perform facial recognition is not adversely affected as a result – otherwise, the irreversibility of the BTP method is of little importance. So, we begin our analysis of PolyProtect with an evaluation of its recognition accuracy.

Fig. 4. Detection Error Trade-off (DET) plots comparing verification accuracy across PolyProtected templates generated from iResNet100 and EdgeFace face embeddings using different overlaps (o).

5

There are two important observations from Fig. 4. The first one is that, across all evaluation scenarios, the general trend is that accuracy increases as the amount of overlap increases. The same trend was already observed in the original PolyProtect work [12] and later confirmed in [26], and it was attributed to the higher dimensionality of PolyProtected templates (and thus more information about the original face embedding being retained) when a larger overlap is used; so, this was expected. The second important finding from Fig. 4, which has not previously been reported, is that accuracy in the PolyProtected domain seems to depend on the model used to generate the underlying face embeddings. Specifically, although the iResNet100 and EdgeFace embeddings were found to have similar accuracy in the unprotected domain (Fig. 3), in the protected domain the accuracy of the iResNet100 PolyProtected templates is significantly worse (Fig. 4). We believe this is because the iResNet100 face embeddings lie in a larger range compared to the EdgeFace embeddings. So, when the PolyProtect transform is applied, the iResNet100 embeddings are more distorted, leading to greater intra-class variance among the iResNet100 protected templates and thus lower accuracy in the protected domain. To validate this theory, Fig. 5 compares the range of the iResNet100 versus EdgeFace template (embedding) elements before and after PolyProtect is applied. Fig. 6 then presents t-SNE plots to illustrate the differences in the class (identity) clustering and intra-class variance of the unprotected versus protected iResNet100 and EdgeFace templates. Due to space constraints, these plots show the results for only the SOTERIA dataset, and only for PolyProtected templates generated using an overlap of 3; however, the same observations can be made for the other datasets and overlaps (i.e., same range regardless of the dataset and overlap, and similar identity clustering behaviour).

Fig. 5. Range of iResNet100 and EdgeFace template elements before and after PolyProtect (overlap = 3), on the SOTERIA dataset. Approximately the same ranges are observed on the Multi-PIE and iCarB-Face datasets, as well as across the other PolyProtect overlaps (0, 1, 2, 4).

From Fig. 5, we see that the unprotected EdgeFace templates lie in the range of approximately [−0.7, 0.7], while the unprotected iResNet100 templates lie in the larger range of about [−4, 4]. Once these embeddings are transformed via PolyProtect, the range of protected iResNet100 templates explodes to roughly [−20000, 20000], which is ten times larger

Fig. 6. Class (identity) separation provided by iResNet100 and EdgeFace face templates before and after PolyProtect (overlap = 3), on SOTERIA. Similar observations can be made on the Multi-PIE and iCarB-Face datasets, as well as for the other PolyProtect overlaps (0, 1, 2, 4).

than the protected EdgeFace range of about [−20, 20]. So, it makes sense to postulate that any intra-class variance present in the face embeddings prior to the PolyProtect transformation would be more exaggerated in the iResNet100 protected templates than in the EdgeFace protected templates. The tSNE plots in Fig. 6 show that this indeed seems to be the case: while the clustering of the classes (identities) is approximately the same among the unprotected and PolyProtected EdgeFace templates, as well as the unprotected iResNet100 templates, the classes in the PolyProtected iResNet100 domain are more dispersed. So, the same identities become more difficult to distinguish (separate) when represented using PolyProtected iResNet100 templates. This can be used to explain why the accuracy in the iResNet100 protected domain is worse than the accuracy in both the iResNet100 unprotected domain and the EdgeFace protected domain (Fig. 4). At this stage, we may be tempted to conclude that PolyProtect is not a suitable BTP method for face embeddings generated using the iResNet100 model (or other models that produce embeddings lying in a relatively large range). However, we found a very simple fix for this issue: normalize the embeddings prior to applying PolyProtect. This way, regardless of the model used, all face embeddings end up lying in the same range, which prevents exaggerated intra-class variance for any one model in the protected domain. Fig. 7 shows the same DET plots from Fig. 4, except this time the unprotected face embeddings are normalized prior to applying PolyProtect. To facilitate the “unnormalized” versus “normalized” accuracy comparison, Table I quantifies the results in terms of the FNMR at the commonly used 0.1% FMR threshold. Comparing Fig. 7 to Fig. 4, and based on the results in Table I, it is clear that normalization is indeed an effective fix to the issue of poor accuracy in the iResNet100 protected

6

IV. P OLY P ROTECT E VALUATION : I RREVERSIBILITY

Fig. 7. Detection Error Trade-off (DET) plots comparing verification accuracy across PolyProtected templates generated from normalized iResNet100 and EdgeFace face embeddings using different overlaps (o). TABLE I V ERIFICATION ACCURACY FOR UNNORMALIZED (U) VS NORMALIZED (N) I R ES N ET 100 AND E DGE FACE FACE EMBEDDINGS , WHEN THEY ARE P OLY P ROTECTED USING DIFFERENT OVERLAPS (o).

Model

iResNet100

EdgeFace

Templates Unprotected o=0 o=1 o=2 o=3 o=4 Unprotected o=0 o=1 o=2 o=3 o=4

FNMR (%) @ 0.1% FMR Multi-PIE SOTERIA iCarB-Face U N U N U N 0.1 0.1 0.3 0.3 1.4 1.4 53.3 0.3 49.3 0.3 50.6 1.8 48.2 0.1 40.9 0.3 42.0 1.3 36.6 0.1 29.0 0.3 36.0 1.0 24.2 0.1 16.7 0.3 29.5 1.1 10.7 0.1 7.9 0.3 16.8 0.8 0.1 0.1 0.3 0.3 2.0 2.0 1.1 0.4 0.6 0.4 4.1 3.3 0.6 0.2 0.4 0.3 2.4 2.1 0.4 0.2 0.4 0.3 4.3 1.3 0.2 0.1 0.3 0.3 2.0 1.1 0.1 0.1 0.3 0.3 1.7 1.0

domain. Now, regardless of the face recognition model, the accuracy in the PolyProtected domain remains relatively close to the corresponding baseline (unprotected) accuracy (with higher PolyProtect overlaps resulting in better accuracy, as before). Even for EdgeFace, normalization results in slightly better accuracy in the protected domain, compared to when the embeddings are not normalized. So, we may conclude that, in order to ensure the best possible accuracy in the PolyProtected domain, it is a good idea to normalize the face embeddings prior to applying the PolyProtect transform. We are now ready to dig into the irreversibility of PolyProtect. Based on the findings in our accuracy analysis, the irreversibility evaluation will be conducted on protected templates generated from normalized face embeddings only. Furthermore, due to space constraints, we will report irreversibility results on iResNet100 only, since the accuracy of normalized iResNet100 templates in the protected domain was found to be slightly better than that of EdgeFace (see Table I). However, the observations and conclusions drawn from this analysis are comparable to the results obtained for EdgeFace, which can be reproduced using our open-source code.

When evaluating the irreversibility of PolyProtect, we are trying to answer the following question: Is it possible to invert the V → P transform (i.e., perform the inverse transform, P → V ) to recover a face embedding, V , from its protected template, P ? In the original work [12], the irreversibility of PolyProtect was evaluated in two ways: theoretically and empirically. The theoretical analysis showed that the inverse transform is defined by an underdetermined system of equations and, therefore, technically does not exist. This is because there are (theoretically) infinitely many solutions for the elements in V that could produce P , so there is no unique solution. So, it was concluded that, in theory, the PolyProtect transform is irreversible (non-invertible). Since this conclusion is mathematically sound, there is no reason for us to investigate the theoretical irreversibility further. The only difference is that our face embeddings are 512-dimensional, whereas those in [12] were 128-dimensional, so the number of equations considered in our theoretical analysis would differ. Table II shows the forward (V → P ) and inverse (P → V ) transforms when PolyProtect is applied to our 512-dimensional face embeddings. The dimensionality of P indicates the number of equations involved; e.g., when overlap = 0, the V → P transform is defined by 103 equations in 512 variables (unknowns), resulting in a 103-dimensional PolyProtected template, P . So, the inverse transform, P → V , cannot be uniquely defined, due to the 512−103 = 409 degrees of freedom. In other words, it is mathematically impossible to invert the 103-dimensional P to recover the 512-dimensional V . The same may be concluded for the other overlaps, albeit with differing degrees of freedom. TABLE II V → P AND P → V TRANSFORMS FOR DIFFERENT OVERLAPS . Overlap

V→P

P→V

0

R512 → R103

R103 → R512

1

R512 → R128

R128 → R512

2

R512 → R170

R170 → R512

3

R512 → R255

R255 → R512

4

R512 → R508

R508 → R512

The second type of irreversibility analysis in [12] involved using a numerical solver to try to approximate a solution for V from P , even if a unique solution technically does not exist. This inversion attack was simulated using an open-source numerical solver: Python’s scipy.optimize.root function with the lm method. This method adopts the Levenberg-Marquardt algorithm, which approximates a solution to a non-linear system of equations using a damped least-squares approach. So, this solver essentially tries to find some set of n elements representing the n-dimensional face embedding, V , such that when we apply PolyProtect to those n elements the Euclidean distance between the resulting protected template and the true protected template, P , is as small as possible. In [12], the success of this inversion attack was quantified as follows. If, for a particular P , the solver converges to a solution, V ∗ , calculate the comparison score (i.e., cosine distance) between V ∗ and the true embedding, V . The idea

7

is to determine whether V ∗ is a close enough approximation to V , such that V ∗ could be used to impersonate the identity represented by V in a face recognition system that stores the unprotected V as a reference face embedding. If the resulting cosine distance is smaller than a pre-defined threshold, the inversion attack is deemed successful; otherwise, the PolyProtected template is considered “irreversible” at this threshold. Since the success rate of an inversion attack in [12] was based on cosine distance, we asked ourselves the following question: Would the inversion attack be more successful if we were to use a numerical solver that tries to minimise the cosine distance between P and the protected version of V ∗ , as opposed to Euclidean distance? To answer this question, we performed two inversion attacks: one based on Python’s scipy.optimize.root function with the lm method, as in [12], and the other one based on Python’s scipy.optimize.minimize function with the BFGS method, which was set up to minimise the cosine distance between the PolyProtected version of the solution, V ∗ , and P . The two solvers were applied to the PolyProtected templates generated from our 512-dimensional, normalized iResNet100 embeddings, which originated from the three datasets mentioned in Section II-B. For each dataset, we selected only one face image, and thus face embedding, per identity (to represent reference embeddings), meaning that we ended up with one PolyProtected template per identity. In total, this amounted to 337 protected templates from the Multi-PIE dataset, 70 from SOTERIA, and 198 from iCarB-Face. As in [12], our irreversibility evaluation was based on the worst-case scenario of a fully-informed attacker, corresponding to the full disclosure threat model defined in ISO/IEC 303168 (i.e., the PolyProtect algorithm and all parameters are known by the attacker). The only difference was that, in our work, the initial guesses for the solvers were drawn from probability distributions estimated on the same face embeddings on which the inversion attacks were performed, whereas in [12] the distributions were estimated on a different set of face embeddings. So, ours represents an even more informed attacker than that assumed in [12], which should not be encountered in practice but is useful for estimating the worst-case irreversibility of PolyProtect. Fig. 8 shows histograms representing the inversion scores (i.e., cosine distances9 ) between the inverted templates (i.e., solutions for V found by each solver, V ∗ ), and the true V s from which the corresponding P s (i.e., the templates being inverted) were created. These histograms were generated by launching an inversion attack on each protected template 10 times, using 10 different initial guesses for the solvers, and concatenating the resulting inversion scores. Each inversion score indicates how close, in terms of cosine distance, the inverted template is to the original face embedding. The figures also include histograms for the genuine and impostor scores (also cosine distances) computed on the unprotected face embeddings. Ideally, the inversion scores should lie as close as possible to the impostor distribution, which would indicate that the inverted templates are as different from their corresponding 8 https://www.iso.org/standard/53256.html 9 Multiplied by -1 to turn them into similarity scores.

face embeddings as are embeddings from different identities. From Fig. 8, it is clear that, in general, the numerical solver based on cosine distance results in higher inversion scores than the solver from [12], which is based on Euclidean distance. In other words, the templates inverted using the cosine solver tend to be more similar (lower cosine distance) to their corresponding face embeddings. This is good for the attacker, since it would allow them to more easily use the inverted template to impersonate the underlying identity in the unprotected face recognition system. On the other hand, this is bad for PolyProtect, because its irreversibility is lower with this new solver than with the Euclidean solver employed in [12]. Having said that, it is important to note that the solver based on Euclidean distance actually represents a “truer” picture of irreversibility, since this type of solver tries to recover both the magnitude and direction of the underlying n-dimensional embedding, whereas the cosine solver attempts to recover only the direction of the embedding. However, since the success of an inversion attack is judged in terms of cosine distance, technically the direction of the embedding is all we need to recover. So, it makes sense that, for this particular definition of a successful inversion, the worst-case irreversibility evaluation should be based on the cosine solver. Fig. 8 also shows that inversion scores increase as the amount of overlap (used in the PolyProtect transform) increases (i.e., the inversion score histograms shift to the right). This means that PolyProtected templates generated using larger overlaps are easier to invert than those generated using smaller overlaps. This trend was already observed in the earlier PolyProtect work [12], [26], and is due to the same reason as that used to explain why larger overlaps lead to better accuracy in the protected domain (Section III), i.e., because larger overlaps result in more information about the original embedding being retained in the PolyProtected template, which, in the context of irreversibility, makes it easier to recover the embedding from its protected template. So, we confirm the observation from [12], [26], that there is a trade-off between the irreversibility and accuracy of PolyProtected templates depending on the amount of overlap applied in the transform, i.e., a larger overlap results in higher recognition accuracy but lower irreversibility, and vice-versa. In Section V, we will demonstrate that this trade-off can be effectively mitigated using our new key selection algorithm, which also serves to significantly improve the irreversibility of PolyProtected templates even in the worst-case scenario where a numerical solver based on cosine distance is used for the inversion attack. V. I MPROVING THE I RREVERSIBILITY OF P OLY P ROTECT: K EY S ELECTION A LGORITHM In the PolyProtect evaluations presented thus far, the coefficients, C, and exponents, E, used to parameterise the PolyProtect polynomials, were randomly generated for each subject (identity). In this section, we propose an alternative method for selecting these subject-specific “keys”, with the aim of generating PolyProtected templates that are more difficult to invert. In particular, we propose a key selection algorithm, which works as follows. Assume we have a database of

8

Fig. 8. Inversion scores for PolyProtected templates generated from normalized iResNet100 face embeddings using different amounts of overlap, when the inversion is performed using two different numerical solvers: one based on Euclidean distance, and the other one based on cosine distance. The closer the inversion scores are to the unprotected template genuine distribution, the more effective the inversion attack.

reference templates (embeddings) that we wish to protect. The goal of the key selection algorithm is to choose C and E for those templates, such that their PolyProtected versions are irreversible under a numerical solver. We assume that the

cosine-distance-based solver from Section IV is used, since this represents the worst-case scenario. So, for a particular subject’s reference template, our algorithm begins by generating C and E randomly, as before. These parameters are used

9

to transform the template to its PolyProtected counterpart, and an inversion attack using the cosine solver is launched. If the inversion is successful, new C and E parameters are generated, and the process is repeated until the inversion fails. The threshold used to define a successful inversion is set to a value well beyond anything likely to be used in a practical face recognition system – in our case, the threshold was set at 20% FMR – because this way, if the inversion fails for such a loose threshold, we may expect it to fail for all stricter (more practical) thresholds (e.g., at 0.1% or 0.01% FMR). Fig. 9 shows the histograms of inversion scores, based on the cosine solver, when the keys (C and E) are selected randomly, as in Section IV, versus when our key selection algorithm is used. Note that, in these plots, the genuine (green) and impostor (red) histograms are the same as in Fig. 8, as is the histogram of inversion scores resulting from using random keys (purple). The only new histogram is the one corresponding to inversion scores obtained when our key selection algorithm is used to generate the PolyProtected templates (blue). To produce this histogram, 10 different (random) initial guesses for the solver were used to launch the inversion attack on the PolyProtected templates, and the resulting 10 sets of inversion scores were concatenated. This was done because we cannot guarantee that the initial guesses used during the inversion step in the key selection algorithm (to select the C and E parameters) would be the same initial guesses used by an attacker attempting to invert the final, PolyProtected templates generated using the selected keys. In Fig. 9, we observe that, for all PolyProtect overlaps and all face datasets, the blue histogram is located further to the left than the purple histogram. In other words, the blue histogram boasts lower inversion scores, and it overlaps quite significantly with the unprotected template impostor score distribution. This tells us that our key selection algorithm is very effective at improving the irreversibility of PolyProtect, i.e., when the C and E parameters are chosen more carefully, using our key selection algorithm, the resulting PolyProtected templates are more difficult to invert compared to when these keys are simply generated randomly. Moreover, while random key generation results in varying degrees of irreversibility depending on the amount of overlap used in the PolyProtect transform (i.e., the purple histogram shifts to the right as the overlap increases), when our key selection algorithm is employed the irreversibility is approximately the same regardless of the overlap. This suggests that our key selection algorithm may also be able to mitigate the irreversibility versus accuracy trade-off across different overlaps (discussed later), which was mentioned in Section IV. Note that results for overlap = 4 are not shown, because the key selection algorithm did not manage to find suitable keys for all templates from the MultiPIE and iCarB-Face datasets. This suggests that an overlap of 4 should be avoided, as already recommended in [12], since the resulting PolyProtected templates seem fairly easy to invert using a numerical solver (see Fig. 8) and our key selection algorithm cannot be guaranteed to fix that. Table III compares the inversion success rate (ISR) of PolyProtected templates generated using random keys (C and E) versus keys chosen by our key selection algorithm. As

in [12], the ISR was computed in terms of the proportion of PolyProtected templates whose inversion score (cosine distance) is below a pre-defined threshold, in which case the inversion attack would be considered successful. Due to space constraints, we present results at only two of the three thresholds illustrated in Fig. 9: at 0.1% FMR and at 0.01% FMR, computed on the unprotected face recognition system (genuine and impostor scores). However, from Fig. 9 it is clear that the ISR would be higher at larger thresholds (e.g., ≥ 1% FMR) and lower at stricter thresholds (e.g., < 0.01% FMR). TABLE III I NVERSION SUCCESS RATE (ISR) AT TWO FMR THRESHOLDS , FOR NORMALIZED I R ES N ET 100 EMBEDDINGS PROTECTED VIA P OLY P ROTECT WITH DIFFERENT OVERLAPS , WHEN THE KEYS (C, E) ARE GENERATED RANDOMLY (R) VS USING OUR KEY SELECTION ALGORITHM (KS). T HE IMPROVEMENT IN ISR DUE TO KS IS REPRESENTED BY ↓.

Dataset

Multi-PIE

SOTERIA

iCarB-Face

Overlap 0 1 2 3 0 1 2 3 0 1 2 3

ISR (%) @ 0.1% FMR @ 0.01% FMR R KS ↓ R KS ↓ 85.6 0.0 85.6 29.9 0.0 29.9 95.9 0.1 95.8 80.7 0.0 80.7 96.7 0.2 96.5 94.0 0.0 94.0 98.3 0.5 97.8 97.6 0.0 97.6 96.3 0.1 96.2 74.6 0.0 74.6 95.9 0.6 95.3 92.3 0.0 92.3 98.9 0.1 98.8 98.4 0.0 98.4 99.6 0.9 98.7 98.7 0.0 98.7 68.3 0.2 68.1 15.2 0.0 15.2 92.8 0.0 92.8 63.2 0.0 63.2 95.6 0.1 95.5 92.7 0.0 92.7 99.2 0.4 98.8 98.6 0.1 98.5

From Table III, it is evident that our key selection algorithm drastically reduces the ISR to less than 1% for all overlaps, at both thresholds, and for all three datasets. At the less strict threshold (0.1% FMR), this represents an improvement of 85.6 – 97.8% for Multi-PIE, 95.3 – 98.8% for SOTERIA, and 68.1 – 98.8% for iCarB-Face, depending on the amount of overlap used in the PolyProtect transform. At the stricter threshold (0.01% FMR) the improvement is, overall, a bit smaller, since the initial ISR (when random keys are used) is lower (as it is harder to find a match between the inverted template and the original embedding at this threshold); however, the improvement in ISR thanks to our key selection algorithm is still significant, especially considering that the ISR is now reduced to ≈ 0% in all evaluation scenarios (i.e., the PolyProtected templates would be considered practically irreversible at this threshold, regardless of the overlap). These findings indicate that our key selection algorithm should definitely be used to select the C and E parameters of the PolyProtect polynomials, in order to ensure a high degree of irreversibility (low ISR) for the worst-case scenario of an inversion attack based on the cosine numerical solver. Selecting these parameters in a purely random fashion is not recommended. Our key selection algorithm is clearly effective at improving the irreversibility of PolyProtect, which was the aim of the work presented in this paper. However, we know from earlier work [12], [26] that PolyProtect incurs a trade-off between the irreversibility and accuracy of protected templates depending

10

Fig. 9. Inversion scores for PolyProtected templates generated from normalized iResNet100 face embeddings using different overlaps, when the keys (C and E parameters) are generated randomly versus using our key selection algorithm. The inversion was performed using the cosine-based numerical solver. The three vertical black lines represent different thresholds at which the inversion success rate (ISR) could be computed (e.g., Table III).

on the amount of overlap used in the transform. Indeed, we also observed this in the accuracy analysis in Section III and the irreversibility analysis (based on random keys) in Section IV, i.e., as the overlap increases, the accuracy increases but the irreversibility decreases, and vice-versa. So now the following question arises: Since our key selection algorithm is able to drastically improve, and approximately equalise, the irreversibility across all overlaps, what effect does this have on the recognition accuracy of the resulting PolyProtected templates? Fig. 10 compares the verification accuracy obtained in the protected domain when PolyProtect’s C and E parameters are generated using our key selection algorithm versus when they are generated randomly. From Fig. 10, we may conclude that our key selection

algorithm degrades, to some extent, the recognition accuracy in the PolyProtected domain, compared to when the PolyProtected templates are generated using purely random C and E parameters. Table IV quantifies this accuracy degradation for the same two thresholds used to compute the ISR in Table III. If we compare Table IV to Table III, we see that the amount by which the accuracy decreases as a result of using our key selection algorithm is much less significant than the amount by which the ISR improves; e.g., at the less strict threshold (0.1% FMR), the accuracy degradation is 1.3 – 8.0% for Multi-PIE, 0.6 – 5.6% for SOTERIA, and 4.9 – 14.2% for iCarB-Face, depending on the amount of overlap used in the PolyProtect transform, whereas the corresponding improvements in irreversibility are 85.6 – 97.8% for Multi-

11

Fig. 10. Detection Error Trade-off (DET) plots comparing verification accuracy for PolyProtected templates generated from normalized iResNet100 face embeddings using different overlaps, when the keys (C and E parameters) are chosen randomly versus using our key selection algorithm.

to result in poor irreversibility against the worst-case inversion attack based on a cosine-distance numerical solver. Another observation from comparing Tables III and IV is that our key selection algorithm is able to effectively mitigate, and in some cases (e.g., at the 0.01% FMR threhold) practically eliminate, the accuracy versus irreversibility trade-off, which is known to exist across PolyProtected templates generated using different overlaps. In particular, since the key selection algorithm allows us to almost equalise the irreversibility (in terms of ISR) across different overlaps (Table III), and the largest overlap results in the best accuracy (Table IV), this suggests that, to ensure the best accuracy versus irreversibility trade-off, we should select the largest (sensible) overlap. For example, in our experimental set-up, this would correspond to an overlap of 3 (since an overlap of 4 was discouraged), which resulted in the best accuracy (Table IV) while still maintaining a high degree of irreversibility comparable to the lower overlaps (Table III). This may be interpreted as a general recommendation for choosing the most appropriate overlap when employing our key selection algorithm; however, in practice the accuracy versus irreversibility trade-off should be evaluated separately for each application context, and the overlap should be carefully tuned based on the requirements of the target PolyProtected system. VI. C ONCLUSIONS AND F UTURE W ORK

TABLE IV V ERIFICATION ACCURACY (FNMR) AT TWO FMR THRESHOLDS , FOR NORMALIZED I R ES N ET 100 EMBEDDINGS PROTECTED VIA P OLY P ROTECT WITH DIFFERENT OVERLAPS , WHEN THE KEYS (C, E) ARE GENERATED RANDOMLY (R) VS USING OUR KEY SELECTION ALGORITHM (KS). T HE ACCURACY DEGRADATION DUE TO KS IS REPRESENTED BY ↓.

Dataset

Multi-PIE

SOTERIA

iCarB-Face

Overlap 0 1 2 3 0 1 2 3 0 1 2 3

FNMR (%) @ 0.1% FMR @ 0.01% FMR R KS ↓ R KS ↓ 0.3 8.3 8.0 0.8 16.3 15.5 0.1 5.0 4.9 0.5 11.2 10.7 0.1 3.1 3.0 0.4 6.7 6.3 0.1 1.4 1.3 0.1 3.0 2.9 0.3 5.9 5.6 0.4 13.8 13.4 0.3 3.6 3.3 0.4 7.9 7.5 0.3 2.2 1.9 0.3 5.7 5.4 0.3 0.9 0.6 0.3 1.5 1.2 1.8 16.0 14.2 3.4 23.2 19.8 1.3 10.0 8.7 3.1 20.6 17.5 1.0 6.7 5.7 2.5 16.4 13.9 1.1 6.0 4.9 1.9 10.6 8.7

PIE, 95.3 – 98.8% for SOTERIA, and 68.1 – 98.8% for iCarBFace. At the stricter threshold (0.01% FMR), the accuracy drop is larger, but the improvement in ISR is still much more drastic in comparison. So, even though our key selection algorithm seems to have a negative effect on the accuracy attainable by the resulting PolyProtected templates, the increase in the irreversibility of those templates is significantly higher than this drop in accuracy. Therefore, we would still recommend using the key selection algorithm over simply generating the C and E parameters randomly, since the latter scenario is likely

The main aim of this work was to improve the irreversibility of protected face templates (embeddings), generated using the PolyProtect BTP method. This was motivated by our finding that PolyProtected templates are easier to invert using a numerical solver based on cosine distance, compared to using a solver based on Euclidean distance (when the definition of a successful inversion is likewise based on cosine distance). To make PolyProtected templates harder to invert with this new solver, we proposed a key selection algorithm, which tries to choose “keys” (i.e., coefficients and exponents of the PolyProtect polynomial) that are more likely to generate “irreversible” protected templates, compared to when these keys are selected purely randomly. Our experiments showed that this algorithm can significantly improve the irreversibility of PolyProtected templates, and moreover that it is able to approximately equalise the irreversibility of PolyProtected templates generated using different “overlap” parameters. This allows for more effective control of the irreversibility versus accuracy trade-off, known to exist across different overlaps. To ensure that accuracy in the PolyProtected domain is as high as possible, we also suggested normalizing the face embeddings prior to transforming them using PolyProtect, so as to avoid potentially high intra-class variance caused by the (large) range in which the embedding elements initially lie. There are two main ideas for next steps. Firstly, we aim to investigate the “suitable key” space of our key selection algorithm, to see if there are any patterns in the C and E parameters that are selected versus those that are rejected. This would help us estimate the number of possible suitable keys, which would give us an idea of how many different PolyProtected templates it is possible to generate when our

12

key selection algorithm is used (related to the renewability/unlinkability criterion of BTP methods). Secondly, we plan to improve our key selection algorithm to increase accuracy in the protected domain. One idea is to incorporate an accuracy check into the selection procedure – at the moment, we select keys that produce “irreversible” PolyProtected templates, based on a threshold that determines a successful inversion, so we could imagine adding a similar check for accuracy. This would help ensure an even better balance between the accuracy and irreversibility of PolyProtected templates. ACKNOWLEDGMENTS This work was funded by the Innosuisse project “PRiMEAiD: Privacy-pReserving bioMetric idEntification for humAnitarian aid Distribution” (Number: 116.346 IP-ICT). R EFERENCES [1] C. Busch, M. Gomez-Barrero, and H. Otroshi Shahreza, “Biometric Template Protection: Why and How,” in Handbook of Biometric Template Protection: Motivation, Methods and Metrics, V. Krivokuća Hahn, M. Gomez-Barrero, A. Ross, and S. Marcel, Eds. Springer, 2026, pp. 3–29. [2] A. Zhmoginov and M. Sandler, “Inverting face embeddings with convolutional neural networks,” arXiv preprint arXiv:1606.04189, 2016. [3] F. Cole, D. Belanger, D. Krishnan, A. Sarna, I. Mosseri, and W. T. Freeman, “Synthesizing Normalized Faces from Facial Identity Features,” in 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2017, pp. 3386–3395. [4] G. Mai, K. Cao, P. C. Yuen, and A. K. Jain, “On the Reconstruction of Face Images from Deep Face Templates,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 41, no. 5, pp. 1188–1202, 2019. [5] H. Otroshi Shahreza, V. Krivokuća Hahn, and S. Marcel, “Face Reconstruction from Deep Facial Embeddings using a Convolutional Neural Network,” in 2022 IEEE International Conference on Image Processing (ICIP). IEEE, 2022, pp. 1211–1215. [6] I. Fábián and G. G. Gulyás, “De-anonymizing Facial Recognition Embeddings,” Infocommunications Journal, vol. 12, no. 2, pp. 50–56, 2020. [7] P. Terhörst, D. Fährmann, N. Damer, F. Kirchbuchner, and A. Kuijper, “Beyond Identity: What Information Is Stored in Biometric Face Templates?” arXiv preprint arXiv:2009.09918, 2020. [8] V. Krivokuća Hahn and S. Marcel, “Biometric Template Protection for Neural-Network-Based Face Recognition Systems: A Survey of Methods and Evaluation Techniques,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 639–666, 2022. [9] V. Krivokuća Hahn, M. Gomez-Barrero, A. Ross, and S. Marcel, Eds., Handbook of Biometric Template Protection: Motivation, Methods and Metrics. Springer, 2026. [10] X. Dong and A. B. J. Teoh, “Feature Transformation-Based Biometrics Template Protection,” in Handbook of Biometric Template Protection: Motivation, Methods and Metrics, V. Krivokuća Hahn, M. GomezBarrero, A. Ross, and S. Marcel, Eds. Springer, 2026, pp. 79–106. [11] X. Dong, K. Wong, Z. Jin, and J. L. Dugelay, “A Cancellable Face Template Scheme Based on Nonlinear Multi-Dimension Spectral Hashing,” in 2019 7th International Workshop on Biometrics and Forensics (IWBF), 2019, pp. 1–6. [12] V. Krivokuća Hahn and S. Marcel, “Towards Protecting Face Embeddings in Mobile Face Verification Scenarios,” IEEE Transactions on Biometrics, Behavior, and Identity Science, vol. 4, no. 1, pp. 117–134, 2022. [13] C. Rathgeb, V. Fohr, and B. Tams, “Biometric Cryptosystems,” in Handbook of Biometric Template Protection: Motivation, Methods and Metrics, V. Krivokuća Hahn, M. Gomez-Barrero, A. Ross, and S. Marcel, Eds. Springer, 2026, pp. 107–132. [14] B. P. Gilkalaye, A. Rattani, and R. Derakhshani, “Euclidean-Distance Based Fuzzy Commitment Scheme for Biometric Template Security,” in 2019 7th International Workshop on Biometrics and Forensics (IWBF), 2019, pp. 1–6. [15] C. Rathgeb, J. Merkle, J. Scholz, B. Tams, and V. Nesterowicz, “Deep face fuzzy vault: Implementation and performance,” Computers & Security, vol. 113, p. 102539, 2022.

[16] V. N. Boddeti, “Homomorphic Encryption for Biometric Template Protection,” in Handbook of Biometric Template Protection: Motivation, Methods and Metrics, V. Krivokuća Hahn, M. Gomez-Barrero, A. Ross, and S. Marcel, Eds. Springer, 2026, pp. 133–170. [17] Y. Ma, L. Wu, X. Gu, J. He, and Z. Yang, “A Secure Face-Verification Scheme Based on Homomorphic Encryption and Deep Neural Networks,” IEEE Access, vol. 5, pp. 16 532–16 538, 2017. [18] V. N. Boddeti, “Secure Face Matching Using Fully Homomorphic Encryption,” in 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS), 2018, pp. 1–10. [19] J. J. Engelsma, A. K. Jain, and V. N. Boddeti, “HERS: Homomorphically Encrypted Representation Search,” IEEE Transactions on Biometrics, Behavior, and Identity Science, vol. 4, no. 3, pp. 349–360, 2022. [20] V. Krivokuća Hahn, M. Valenti, V. Talreja, N. Nasrabadi, T. S. Ng, and A. B. J. Teoh, “Using Neural Networks to Learn Biometric Template Protection,” in Handbook of Biometric Template Protection: Motivation, Methods and Metrics, V. Krivokuća Hahn, M. Gomez-Barrero, A. Ross, and S. Marcel, Eds. Springer, 2026, pp. 171–201. [21] R. K. Pandey, Y. Zhou, B. U. Kota, and V. Govindaraju, “Deep Secure Encoding for Face Template Protection,” in 2016 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), 2016, pp. 77–83. [22] A. K. Jindal, S. Chalamala, and S. K. Jami, “Face Template Protection Using Deep Convolutional Neural Network,” in 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), 2018, pp. 575–5758. [23] V. Talreja, M. C. Valenti, and N. M. Nasrabadi, “Zero-Shot Deep Hashing and Neural Network Based Error Correction for Face Template Protection,” in 2019 IEEE 10th International Conference on Biometrics Theory, Applications and Systems (BTAS), 2019, pp. 1–10. [24] J. R. Pinto, M. V. Correia, and J. S. Cardoso, “Secure Triplet Loss: Achieving Cancelability and Non-Linkability in End-to-End Deep Biometrics,” IEEE Transactions on Biometrics, Behavior, and Identity Science, vol. 3, no. 2, pp. 180–189, 2021. [25] G. Mai, K. Cao, X. Lan, and P. C. Yuen, “SecureFace: Face Template Protection,” IEEE Transactions on Information Forensics and Security, vol. 16, pp. 262–277, 2021. [26] G. Stragapede, S. Merrick, V. Krivokuća Hahn, J. Sukaitis, and V. Graf Narbel, “Securing Face and Fingerprint Templates in Humanitarian Biometric Systems,” in 2025 IEEE International Joint Conference on Biometrics (IJCB). IEEE, 2025, pp. 1–10. [27] N. Ramoly, A. Komaty, V. K. Hahn, L. Younes, A.-M. Awal, and S. Marcel, “A Novel and Responsible Dataset for Face Presentation Attack Detection on Mobile Devices,” in 2024 IEEE International Joint Conference on Biometrics (IJCB). IEEE, 2024, pp. 1–9. [28] K. He, X. Zhang, S. Ren, and J. Sun, “Deep Residual Learning for Image Recognition,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 770–778. [29] J. Deng, J. Guo, N. Xue, and S. Zafeiriou, “ArcFace: Additive Angular Margin Loss for Deep Face Recognition,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2019, pp. 4690–4699. [30] A. George, C. Ecabert, H. O. Shahreza, K. Kotwal, and S. Marcel, “Edgeface: Efficient face recognition model for edge devices,” IEEE Transactions on Biometrics, Behavior, and Identity Science, vol. 6, no. 2, pp. 158–168, 2024. [31] F. Schroff, D. Kalenichenko, and J. Philbin, “FaceNet: A Unified Embedding for Face Recognition and Clustering,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2015, pp. 815–823. [32] R. Gross, I. Matthews, J. Cohn, T. Kanade, and S. Baker, “Multi-PIE,” Image and Vision Computing, vol. 28, no. 5, pp. 807–813, 2010. [33] V. Krivokuća Hahn, J. Maceiras, A. Komaty, P. Abbet, and S. Marcel, “in-Car Biometrics (iCarB) Datasets for Driver Recognition: Face, Fingerprint, and Voice,” arXiv preprint arXiv:2411.17305, 2024.

Record · ID 157294 · SHA-256 9e8df210919ca356
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.