Compositional Non-Face Re-Identification Pressure under Cumulative Vision Releases
Abstract
Most privacy evaluations in computer vision treat datasets and models as isolated, static disclosures, failing to account for how risk accumulates in practice. We formalize Compositional Non-Face ReIdentification Risk, where identities remain linkable through non-face cues, such as clothing, gait, and scene context that aggregate across sequential releases of data expansions, model checkpoints, and metadata. We introduce the Vision Re-Identification Pressure Index (vRPI ), a foundational, information-theoretic measure derived from α Arimoto conditional Rényi entropy that quantifies the systemic erosion of anonymity. We prove that vRPI is monotone under cu- α mulative releases, establish an exact bridge to Bayes-optimal guessing probability, and derive additive decompositions under conditionalindependence benchmarks. Through the NFLeak protocol, we provide illustrative experiments on Market-1501-Tau and a CUHK03- Tau closed-world replication using a structured Attacker Ladder, together with masking-level, dependence-overlap, temperature-calibration, and non-uniform-prior diagnostics, demonstrating that vRPI accurately α tracks realized re-identification success even after explicit face removal. Our framework enables principled auditing of the “leaky bucket” effect in vision benchmarks, shifting the focus from single-release compliance to ecosystem-level privacy hygiene.