See Me If You Can: A Multi-Layer Protocol for Bystander Privacy with Consent-Based Restoration
Authors
Paper Title
See Me If You Can: A Multi-Layer Protocol for Bystander Privacy with Consent-Based Restoration
Publication Info
- Topic area: Privacy-enhancing technologies for wearable camera glasses.
- Keywords: Camera glasses, privacy-by-default, consent restoration, synthetic face replacement, obfuscation, bystander privacy, wearable technology, user study, context-aware PETs, social dynamics.
Background and Problem
- Problem / challenge: Wearable camera glasses raise privacy concerns for bystanders, particularly regarding unauthorized recording. Existing privacy-enhancing technologies (PETs) rely on opt-out models, placing the burden on bystanders and offering limited enforceable protections or restoration mechanisms.
- Significance: Addressing these privacy concerns is critical to balancing the usability of wearable devices with ethical considerations, ensuring adoption without compromising individual rights.
- Motivation and related work: Prior research has explored opt-out mechanisms, face blurring, and privacy indicators, but these approaches fail to provide robust privacy guarantees or practical usability. Context-aware, opt-in privacy-by-default mechanisms remain underexplored, motivating the need for solutions that mediate wearers' and bystanders' needs.
Solution
- Proposed approach: A three-tier opt-in privacy-by-default protocol for camera glasses, featuring mandatory on-device blurring, optional synthetic face replacement, and consent-based restoration mediated by a Trusted Third Party (TTP).
- Novelty:
- Mandatory on-device blurring as a default privacy measure.
- AI-based synthetic face replacement to preserve video quality while anonymizing identities.
- Consent-based restoration mechanism allowing selective recovery of original faces upon bystander approval.
- Procedure and key techniques:
- Tier 1: On-device blurring of faces with encrypted embeddings and symmetric keys stored securely.
- Tier 2: Synthetic face replacement using AI-generated faces aligned with facial landmarks.
- Tier 3: Consent-based restoration via a TTP, which identifies bystanders and facilitates consent requests without sharing raw media.
Results
- Concrete findings:
- Privacy protection metrics (Tier 1): Average Precision (AP) = 0.942, Average Recall (AR) = 0.953.
- Visual utility metrics (Tier 2): Fréchet Inception Distance (FID) = 63.70 ± 27.8, Structural Similarity Index (SSIM) = 0.61 ± 0.07.
- System costs: Energy consumption = 67.04 J (privacy-only) and 112.05 J (privacy + synthetic replacement); latency = 13.69 s (privacy-only) and 22.88 s (privacy + synthetic replacement).
- Advantage over baselines: The protocol achieved comparable privacy protection to state-of-the-art (SOTA) methods like EgoBlur while introducing synthetic face replacement for enhanced visual fidelity. It maintained manageable computational overheads on resource-constrained hardware.
- Experiments / evaluation:
- Implementation tested on Raspberry Pi 4 hardware to simulate wearable-class devices.
- Evaluation conducted on custom datasets recorded with Meta Ray-Ban Stories glasses, assessing privacy, visual fidelity, and system costs.
- Qualitative user study (N = 18) explored wearer and bystander perceptions through semi-structured interviews.
- Limitations and future work:
- Lack of audio obfuscation mechanisms.
- Potential risks from unencrypted facial landmarks and temporary storage of encrypted face regions.
- Cultural and demographic specificity of the study sample limits generalizability.
- Future work should explore landmark-free approaches, longitudinal studies, and decentralized architectures.
Summary
This paper introduces a three-tier opt-in privacy-by-default protocol for wearable camera glasses, addressing bystander privacy concerns through mandatory blurring, synthetic face replacement, and consent-based restoration. Quantitative evaluations demonstrate technical feasibility, while qualitative studies reveal wearers' and bystanders' differing priorities: wearers seek context-dependent flexibility, and bystanders advocate for robust mandatory protections. The findings highlight the need for context-aware PETs that reconcile usability and privacy, offering design directives for future systems and implications for camera glass manufacturers.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 86%
Investigating How Types of Data Associated With Smart Home Devices Influence Privacy Concerns and Perceived Benefits
CHI '26· Smart Home Privacy & Security +2
- 63%
IoTBeholder: A Privacy Snooping Attack on User Habitual Behaviors from Smart Home Wi-Fi Traffic
UbiComp '23· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)