See Me If You Can: A Multi-Layer Protocol for Bystander Privacy with Consent-Based Restoration

Privacy by Design & User ControlContext-Aware ComputingSmart Home Privacy & SecuritySoftware Engineers & DevelopersUI/UX DesignersCybersecurity EngineersPrivacy Policy Makers

Paper Title

See Me If You Can: A Multi-Layer Protocol for Bystander Privacy with Consent-Based Restoration

Publication Info

  • Topic area: Privacy-enhancing technologies for wearable camera glasses.
  • Keywords: Camera glasses, privacy-by-default, consent restoration, synthetic face replacement, obfuscation, bystander privacy, wearable technology, user study, context-aware PETs, social dynamics.

Background and Problem

  • Problem / challenge: Wearable camera glasses raise privacy concerns for bystanders, particularly regarding unauthorized recording. Existing privacy-enhancing technologies (PETs) rely on opt-out models, placing the burden on bystanders and offering limited enforceable protections or restoration mechanisms.
  • Significance: Addressing these privacy concerns is critical to balancing the usability of wearable devices with ethical considerations, ensuring adoption without compromising individual rights.
  • Motivation and related work: Prior research has explored opt-out mechanisms, face blurring, and privacy indicators, but these approaches fail to provide robust privacy guarantees or practical usability. Context-aware, opt-in privacy-by-default mechanisms remain underexplored, motivating the need for solutions that mediate wearers' and bystanders' needs.

Solution

  • Proposed approach: A three-tier opt-in privacy-by-default protocol for camera glasses, featuring mandatory on-device blurring, optional synthetic face replacement, and consent-based restoration mediated by a Trusted Third Party (TTP).
  • Novelty:
    1. Mandatory on-device blurring as a default privacy measure.
    2. AI-based synthetic face replacement to preserve video quality while anonymizing identities.
    3. Consent-based restoration mechanism allowing selective recovery of original faces upon bystander approval.
  • Procedure and key techniques:
    • Tier 1: On-device blurring of faces with encrypted embeddings and symmetric keys stored securely.
    • Tier 2: Synthetic face replacement using AI-generated faces aligned with facial landmarks.
    • Tier 3: Consent-based restoration via a TTP, which identifies bystanders and facilitates consent requests without sharing raw media.

Results

  • Concrete findings:
    • Privacy protection metrics (Tier 1): Average Precision (AP) = 0.942, Average Recall (AR) = 0.953.
    • Visual utility metrics (Tier 2): Fréchet Inception Distance (FID) = 63.70 ± 27.8, Structural Similarity Index (SSIM) = 0.61 ± 0.07.
    • System costs: Energy consumption = 67.04 J (privacy-only) and 112.05 J (privacy + synthetic replacement); latency = 13.69 s (privacy-only) and 22.88 s (privacy + synthetic replacement).
  • Advantage over baselines: The protocol achieved comparable privacy protection to state-of-the-art (SOTA) methods like EgoBlur while introducing synthetic face replacement for enhanced visual fidelity. It maintained manageable computational overheads on resource-constrained hardware.
  • Experiments / evaluation:
    • Implementation tested on Raspberry Pi 4 hardware to simulate wearable-class devices.
    • Evaluation conducted on custom datasets recorded with Meta Ray-Ban Stories glasses, assessing privacy, visual fidelity, and system costs.
    • Qualitative user study (N = 18) explored wearer and bystander perceptions through semi-structured interviews.
  • Limitations and future work:
    • Lack of audio obfuscation mechanisms.
    • Potential risks from unencrypted facial landmarks and temporary storage of encrypted face regions.
    • Cultural and demographic specificity of the study sample limits generalizability.
    • Future work should explore landmark-free approaches, longitudinal studies, and decentralized architectures.

Summary

This paper introduces a three-tier opt-in privacy-by-default protocol for wearable camera glasses, addressing bystander privacy concerns through mandatory blurring, synthetic face replacement, and consent-based restoration. Quantitative evaluations demonstrate technical feasibility, while qualitative studies reveal wearers' and bystanders' differing priorities: wearers seek context-dependent flexibility, and bystanders advocate for robust mandatory protections. The findings highlight the need for context-aware PETs that reconcile usability and privacy, offering design directives for future systems and implications for camera glass manufacturers.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/223498/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3790394
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
7 authors
sell
Subtopics
Privacy by Design & User Control, Context-Aware Computing, Smart Home Privacy & Security
work
Professions
Software Engineers & Developers, UI/UX Designers, Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
2 related papers