Lensless Gaze Is Not Private by Default: Auditing Identity Leakage Across Disclosure Surfaces
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.
Tom: Today's paper: "Lensless Gaze Is Not Private by Default".
Jane: This paper conducts an audit of identity leakage within a simulated lensless gaze sensing pipeline to demonstrate that visual unintelligibility does not equate to privacy by default.
Tom: First, who's behind it and why it matters.
Title and authors: Tom: So, let's talk about who wrote this and what they're calling this work. The paper is "Lensless Gaze Is Not Private by Default: Auditing Identity Leakage Across Disclosure Surfaces," and it was written by Rahul Vimalkanth and Kaushik Mitra from the Indian Institute of Technology Madras.
Jane: It’s interesting that they chose such a specific title, because it immediately sets up the main argument: that lensless sensing isn't private just because the measurements look unintelligible to a human eye.
Lu: The authors are clearly trying to move the conversation away from focusing only on optical encryption and instead treat identity privacy as a property of disclosure surfaces across sensing, storage, computation, and output.
Meng: So they aren't just looking at one part of the pipeline; they’re auditing how information persists across all those different stages. That means we have to look at every interface where data is exposed or processed.
Lalam: If this audit shows that subject-correlated information remains recoverable even when optical encoding is fixed and known, then it suggests that the security focus needs to shift from just the optics to managing data handling across all those boundaries.
The paper's summary: Tom: The core finding they are driving home here in "Lensless Gaze Is Not Private by Default: Auditing Identity Leakage Across Disclosure Surfaces" is that visual unintelligibility doesn't guarantee privacy by default. They audit a simulated pipeline under a common protocol and show that subject-correlated information stays recoverable across different disclosure surfaces.
Jane: What’s striking to me is how they test this across several specific points: original crops, simulated lensless measurements, and even aggregated temporal data, showing leakage rates up to ninety-seven point seven percent for the original crops and ninety-six point seven percent for the simulated lensless measurements under one protocol.
Lu: They also demonstrate that simply residualizing the measurement against acquisition cues—like geometry or illumination summaries—only reduces recovery from ninety-six point seven percent down to ninety-five point one percent, which shows that those cues still contribute heavily to identification even after some cleanup.
Meng: That detail about the six-dimensional sourcecrop geometry and intensity summary reaching ninety-five point five percent is a big practical piece of information for us because it tells us exactly which acquisition details we can't just ignore when trying to protect identity.
Lalam: This suggests that simply masking the visual appearance isn't enough; you have to actively control how stable subject-correlated structures, like positioning and lighting, cross those disclosure boundaries where they are handled by the AI system.
The paper's improvements: Tom: Now let's talk about what the authors suggest we should actually do based on these findings. They propose a major shift in how we approach security in this area, urging us to "Audit the system, not the image" and to treat stable geometry, positioning, illumination, behavior, and learned features crossing trust boundaries as an attack surface.
Jane: So the improvement isn't about making the optical encoding stronger; it’s about designing a holistic audit framework that looks at all those different stages where data is used or released.
Lu: They suggest we need to develop boundary-specific attack models for different parts of the pipeline, such as one for high-resolution crops and another specifically targeting learned embeddings in the internal representations.
Meng: From an engineering standpoint, this means our development process needs to include modeling how an attacker might exploit a specific bottleneck layer or a particular output tokenization strategy, rather than just focusing on overall task accuracy metrics.
Lalam: I think implementing this suggests we need to build layers of defense tailored precisely to the type of leakage identified at each stage, whether it's geometry-based cues or repeated outputs over time.
Conclusion: Tom: So, wrapping up the paper "Lensless Gaze Is Not Private by Default: Auditing Identity Leakage Across Disclosure Surfaces," the authors conclude that visually unintelligible simulated lensless measurements can still be highly subject-predictive under an enrolled attacker, and that privacy should be evaluated as a property of the entire sensing pipeline.
Jane: They emphasize that we need to audit the system rather than just focusing on optical encoding alone, highlighting that stable geometry and learned features crossing trust boundaries are key areas for attack.
Lu: The paper makes it clear that while tokenization might reduce empirical recovery from thirty-eight point one percent in some cases, privacy still hinges on whether the residual or full-precision predictions are exposed elsewhere in the system.
Meng: For us in engineering, this means our design philosophy needs to change to explicitly track those stable features across every layer of computation and storage, treating them as potential leak points.
Lalam: Ultimately, this work gives us a concrete framework for designing systems where we understand that leakage happens at the boundaries between different data handling stages.
Tom: That’s a lot to digest about auditing identity leakage across those surfaces in "Lensless Gaze Is Not Private by Default: Auditing Identity Leakage Across Disclosure Surfaces." What an important piece of research for anyone working with next-generation sensing technology.
Indian Institute of Technology Madras
cs.CV
Submitted: 2026-08-31
Updated: 2026-09-30
Comments: 16 pages, 5 figures. Code available at https://github.com/xoxo121/Lensless-Gaze-Is-Not-Private-by-Default
Code: https://github.com/xoxo121/Lensless-Gaze-Is-Not-Private-by-Default
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 92/100
The gist: This paper conducts an audit of identity leakage within a simulated lensless gaze sensing pipeline to demonstrate that visual unintelligibility does not equate to privacy by default.
Key concepts
- Disclosure Surface Auditing
- This involves evaluating leakage at every stage where data is shared or stored, such as original crops and simulated measurements. The audit demonstrated that even when visual cues are removed or measurements are 'lensless,' identity can still be recovered if the attacker knows the acquisition details.
- Sourcecrop Geometry/Intensity Summary
- This refers to summarizing key physical characteristics of the gaze data, like position and lighting. The study found that these six dimensions strongly contribute to identification, meaning that knowing how and where a gaze was captured is as revealing as the gaze itself.
- Residualization
- This technique involves trying to remove known acquisition cues (like geometry or illumination) from a measurement. The results showed that while this reduces recovery slightly, significant subject-correlated information still persists, proving that removing obvious visual noise isn't enough for privacy.
Terminology
Summary
This paper conducts an audit of identity leakage within a simulated lensless gaze sensing pipeline to demonstrate that visual unintelligibility does not equate to privacy by default. The research treats identity privacy as a systems property across disclosure surfaces—including sensing, storage, computation, and output—showing that subject-correlated information remains recoverable even when optical encoding is fixed and known. This work matters because it shifts the focus of gaze system security from optical encryption to auditing where sensitive information persists across various stages of data handling.
Disclosure Surface Auditing
The authors evaluate measured, stored, represented, retained, released, and temporally aggregated signals under one explicit attacker protocol using a known-gallery closed-set identification protocol. The core finding is that privacy claims for lensless sensing must be tested at disclosure boundaries rather than inferred from appearance.
Specifically:
-
Original crops (L0) yield 97.7% top-1 identification accuracy, and simulated lensless measurements (L1) yield 96.7%.
-
A six-dimensional sourcecrop geometry/intensity summary reaches 95.5%, indicating that
positioning, illumination, crop geometry, and related acquisition cues contribute strongly.
-
Residualizing the flattened lensless measurement against these cues only reduces recovery from 96.7% to 95.1%.
Controlled Simulated-Lensless Audit
The study instantiates this audit in a simulated pipeline derived from the Open Eye Dataset (OpenEDS). The authors intentionally set up a setting where the same optical encoding is used across enrollment and evaluation,
unlike systems like OpEnCam which treat optical elements as a secret key. The audit evaluates leakage using matched linear and multilayer perceptron (MLP) probes on held-out temporal blocks. Key results include:
Original crops and simulated lensless measurements yield 97.7% and 96.7% top-1 identification, while a masked autoencoder (MAE) embedding retains 94.3.
An 8-D principal component analysis (PCA) projection retains 93.2%, and a matched 8-D bottleneck on the same frozen MAE backbone retains 91.8%.
Compression Controls and Representation Leakage
The research investigates whether dimensionality reduction alone guarantees privacy, comparing different compression controls. The findings show that dimensionality alone does not explain leakage reduction.
-
Separately trained 8-D Gaze Semantic Projection Latent (GSPL) bottlenecks yield a mean recovery of 77.5% across three training seeds, demonstrating that representation and training choices materially affect leakage.
-
A matched 8-D bottleneck on the same frozen MAE backbone retains 91.8%, suggesting that
a width-matched same-backbone bottleneck remains highly identifying.
Output and Time-Aware Analysis
The audit examines leakage at the output boundary using the GazeSplit construct, which partitions a continuous gaze estimate into a released quantized token and a locally retained residual.
-
A released 128-way gaze token lowers single-frame recovery to 38.1%.
-
The residual (L5) exposes 62.1%, and the continuous gaze output (L6) exposes 72.6%.
-
Under a source-frame-disjoint tiled protocol, token summaries reach 39.9% at T=25, showing that
repeated-output risk depends on representation and aggregation.
Discussion of Findings
The audit establishes that visually unintelligible simulated lensless measurements can remain highly subject-predictive under an enrolled attacker, including after acquisition-cue residualization and under a full-resolution spatial probe.
The study concludes that privacy should be evaluated as a property of the entire sensing pipeline rather than optical encoding alone, emphasizing the need to Audit the system, not the image
and to Treat stable geometry, positioning, illumination, behavior, and learned features crossing trust boundaries as attack surface.
It notes that while tokenization reduces empirical recovery from 38.1%, privacy still depends on whether residual or full-precision predictions are exposed elsewhere.
What the Audit Does Not Establish
The paper explicitly states what it does not establish to maintain scientific rigor:
The rates are simulation- and protocolspecific, not universal properties of lensless imaging.
They do not isolate intrinsic ocular biometrics from acquisition cues, demonstrate cross-session persistence, evaluate unseen identities, or provide formal privacy guarantees.
The results characterize subject-correlated recoverability under a specified disclosure and threat model,
rather than an intrinsic information-theoretic identity bound.
Design Implications
The authors suggest several design practices:
-
Audit the system, not the image.
-
Treat stable geometry, positioning, illumination, behavior, and learned features crossing trust boundaries as attack surface.
Improvements for AI systems
Here are the specific improvements to AI systems based on the findings of this paper, categorized by where they should be applied:
) Lensless Gaze System Improvements: Disclosure-Surface Auditing Framework
The core improvement is shifting from auditing performance metrics (like accuracy) to auditing privacy risk across defined disclosure boundaries.
- Predictive Privacy Risk Assessment Module:
Identify and map all data flows within an AI pipeline (from sensor input to final output, including intermediate representations like embeddings or bottleneck projections). For each flow, define the trust boundary
where the information is disclosed (e.g., raw pixel data vs. a tokenized output).
- Boundary-Specific Attack Modeling:
Develop tailored adversary models for different boundaries:
-
For high-resolution sensor/original crops (L0): Model attacks based on geometry, illumination, and acquisition cues (positioning/lighting).
-
For learned embeddings (L2): Model attacks exploiting internal representation structure using model inversion or membership inference.
-
For compressed representations (L3', MAE bottleneck): Model attacks exploiting principal component subspaces and bottleneck constraints.
-
For released outputs (L4, L5, L6): Model risks based on token entropy, residual leakage, and temporal aggregation strategies.
- Adversarial Training for Boundary Resilience:
Implement adversarial training that specifically targets the identified leakage surfaces rather than just maximizing task accuracy. For instance:
-
Train the model to maintain high task accuracy (gaze estimation) while minimizing sensitivity to perturbations in the acquisition cues (geometry/intensity summary).
-
Train the latent representation learning process to ensure that stable subject-correlated information (like head pose or persistent gaze patterns) does not persist strongly in downstream bottleneck layers.
- Output Minimization Strategy:
Adopt a multi-stage output strategy based on the audit findings:
-
Instead of releasing a full continuous gaze stream (L6), prioritize releasing only the quantized token (L4) for immediate interaction, while keeping the high-resolution residual (L5) locally retained for calibration or error correction.
-
Implement
Privacy Pruning
layers that explicitly remove or heavily obfuscate known subject-correlated features identified in the audit (e.g., normalizing intensity/geometry summaries before passing data to downstream components).
- Temporal Privacy Control:
For continuous outputs, implement temporal aggregation strategies (like the source-frame-disjoint tiling protocol) that are proven to reduce leakage over time. This involves using token summaries at specific intervals rather than releasing every frame sequentially, as this mitigates the risk associated with repeated releases (L7).
) Specific System Capabilities Enabled by These Improvements:
The improved AI system can achieve the following:
-
Secure Deployment in Sensitive Environments: The system can be deployed in scenarios where data is shared across multiple untrusted components (e.g., edge devices communicating with a cloud service) because it has been audited and hardened against leakage at every interface, not just the final output.
-
Privacy-Aware Model Design: Developers gain a framework to explicitly understand that
visually unintelligible
measurements do not equate toprivate.
The system can be designed specifically to preserve privacy by isolating and protecting stable acquisition cues (geometry/lighting) from the identity-sensitive features (gaze dynamics). -
Robust Compression for Privacy: The system can utilize dimensionality reduction (like PCA or bottleneck layers) not just for efficiency, but as a measurable control against leakage, allowing engineers to choose compression levels that balance utility against a quantifiable privacy risk budget.
-
Intelligent Data Release Protocols: The system can dynamically adjust its data release strategy based on the context (e.g., releasing high-fidelity data for local calibration vs. releasing low-entropy tokens for public interaction), ensuring that the most sensitive information is only exposed when strictly necessary and under controlled conditions.
Abstract
Lensless near-eye sensing is often described as privacy-friendly because its coded measurements are visually unintelligible. Yet visual unintelligibility reflects human interpretation, not what a learned adversary can recover. We therefore treat identity privacy as a systems property of disclosure surfaces: representations crossing sensing, storage, computation, and output boundaries. We audit a simulated lensless gaze pipeline under a 36-subject known-gallery closed-set identification protocol with a fixed, known PSF; privacy from an unknown or varying optical key is outside our scope. Reported accuracies are empirical attack success rates under matched linear and MLP probes and do not upper-bound stronger adversaries. Simulated lensless measurements yield 96.7% top-1 identification versus 97.7% for matched original eye crops, while an MAE embedding retains 94.3%. Compression alone offers little protection: 8-D PCA and a matched 8-D bottleneck retain 93.2% and 91.8%, whereas separately trained 8-D GSPL bottlenecks yield 77.5% mean recovery across three seeds. A released 128-way gaze token lowers single-frame recovery to 38.1%, while its residual and continuous gaze output expose 62.1% and 72.6%, respectively. Under a source-frame-disjoint tiled protocol, token summaries reach 39.9% at T=25, showing that repeated-output risk depends on representation and aggregation. These rates reflect all subject-correlated information in the evaluated dataset, including acquisition and behavioral cues, rather than isolating intrinsic ocular biometrics. Ordinary least squares residualization against a six-dimensional crop geometry and intensity summary still leaves lensless recovery at 95.1%. Our results show that privacy claims for lensless sensing must be tested at disclosure boundaries rather than inferred from appearance.
Related papers
- Loss Knows Best: Detecting Annotation Errors in Videos via Loss Trajectories
- AnchorWeave: World-Consistent Video Generation with Retrieved Local Spatial Memories
- Benchmarking the Robustness of Foundation Models for Mammography under Domain Shift
- MambaX-Net: Dual-Input Mamba-Enhanced Cross-Attention Network for Longitudinal MRI Segmentation
- TeleOCR: Navigating Document Parsing Across Digital and Camera-Captured Documents
- A Survey on Efficient Vision-Language-Action Models