arXiv:2609.27115v1 Announce Type: new Abstract: A face recognition model links two images of a person recorded on separate occasions when their embedding similarity exceeds an operating threshold. We consider making chosen identities unlinkable across separate occasions while the model remains in service for the rest of the population. Deleting their images and retraining does not achieve this, since the model recognises identities never observed in training. Therefore, the embedding space must be altered against these identities, the process of which we call open-set adversarial forgetting. We propose three loss functions, one that disperses an identity's embeddings from their centroid, and two that map each image onto its own near-orthogonal target, learnt with the classifier head or fixed in advance as an almost-orthonormal frame. Each is fine-tuned alongside the classification objective on a subset of each identity's images. We evaluate them against four methods from prior work in verification and identification, at two forget scales and three backbones. Every loss acting on the embedding geometry makes the forget identities nearly unidentifiable. The orthonormal frame alone achieves strong forgetting, which holds wherever an image of that subset enters the comparison and leaves distinct forget identities unlinkable. It also surpasses a concurrent unsupervised method at a higher retain rate.
Damnatio Memoriae: Adversarially and Selectively Forgetting Identities in the Embedding Space of Face Recognition Models
Researchers posting to arXiv (2609.27115v1) propose three loss functions for "open-set adversarial forgetting" that alter a face recognition model's embedding space so chosen identities become nearly unidentifiable and unlinkable across separate occasions while the model stays in service for the rest of the population. The methods, fine-tuned alongside the classification objective on a subset of each identity's images, were evaluated against four prior-work methods in verification and identification at two forget scales and three backbones. The authors report that an almost-orthonormal fixed frame alone achieves strong forgetting and surpasses a concurrent unsupervised method at a higher retain rate.
Run your AI side-project on zahid.host
EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.