This Face Does Not Exist ... But It Might Be Yours! Identity Leakage in Generative Models

Generative adversarial networks (GANs) are able to generate high resolution\nphoto-realistic images of objects that "do not exist." These synthetic images\nare rather difficult to detect as fake. However, the manner in which these\ngenerative models are trained hints at a potential for information leakage from\nthe supplied training data, especially in the context of synthetic faces. This\npaper presents experiments suggesting that identity information in face images\ncan flow from the training corpus into synthetic samples without any\nadversarial actions when building or using the existing model. This raises\nprivacy-related questions, but also stimulates discussions of (a) the face\nmanifold's characteristics in the feature space and (b) how to create\ngenerative models that do not inadvertently reveal identity information of real\nsubjects whose images were used for training. We used five different face\nmatchers (face_recognition, FaceNet, ArcFace, SphereFace and Neurotechnology\nMegaMatcher) and the StyleGAN2 synthesis model, and show that this identity\nleakage does exist for some, but not all methods. So, can we say that these\nsynthetically generated faces truly do not exist? Databases of real and\nsynthetically generated faces are made available with this paper to allow full\nreplicability of the results discussed in this work.\n

Paper

References (31)

Scroll for more · 19 remaining

Similar papers

© 2026 NYSGPT2525 LLC