arXiv · 2607.29144
Have I Seen You? Embedding Behavior Signals Synthetic Face Dataset Membership
Abstract
Synthetic face datasets are increasingly used to reduce privacy exposure and data access constraints in biometric recognition. Yet the generators that produce these datasets are trained on real faces, so synthetic data may still reveal their real source data. We study this risk through a dataset-level membership inference attack that first identifies the synthetic dataset used to train a face recognizer and then infers the real dataset used to train the generator. Across 11 face recognition models, 11 synthetic datasets, and 7 real datasets, the attack recovers the synthetic training dataset in 100% of cases and identifies the generator's source dataset in 54.5% of cases. These results show that synthetic data can retain dataset-level traces of real training data and that privacy-preserving deployment requires stronger leakage mitigation.
Explore related subjects
Keep this discovery
Paweł Borsukiewicz, Daniele Lunghi, Wendkûuni C. Ouédraogo, Jacques Klein, Tegawendé F. Bissyandé. 2026-07-31. Have I Seen You? Embedding Behavior Signals Synthetic Face Dataset Membership. https://arxiv.org/abs/2607.29144
Cite the original work for its findings. Save a collection to share your selection of sources.