ArXiv

Quantifying Training Membership Information in the Hyperspherical Embedding Geometry of Face Recognition Models

Authors
Ünsal Öztürk, Sébastien Marcel
Categories
cs.CV
arXiv
https://arxiv.org/abs/2607.15084v1
PDF
https://arxiv.org/pdf/2607.15084v1

Brief

The paper quantifies how hyperspherical embedding geometry in face‑recognition models encodes training membership. Using 180 models varying IResNet size, loss head, training duration, and number of identities, and evaluating on nine benchmarks, the authors find training‑identity count drives the strongest member/non‑member separability, same‑domain signals shrink as identities increase, cross‑domain sets inflate signals, and a learned fusion of four geometry statistics improves detection.

Why it matters

Study used a factorial design over IResNet backbone size, loss head, training duration, and number of training identities to train 180 face‑recognition models and quantify cluster-geometry membership signals.

Key details

  • Evaluated on nine benchmarks, the number of training identities produced the largest effect on member/non‑member separability; backbone and loss head contributed far less, and on a same‑domain held‑out reference the geometric membership signal decreased monotonically as more identities were added.
  • Cross‑domain non‑member sets (pose, age, quality, ethnicity) inflate the apparent membership signal, and fusing four cluster‑geometry statistics with a learned classifier reveals additional membership information beyond the best individual statistic.
Source evidence

Abstract

Face recognition models represent each face as an embedding vector on the unit hypersphere by clustering embeddings of the same identity while pushing different identities apart through angular-margin losses. Because these losses act only on training identities, non-member identities may form clusters with different geometric properties. In this paper, we quantify the magnitude of this difference and what training-time factors control it. We compute four statistics based on cluster geometry across 180 face recognition models in a factorial design over IResNet backbone size, loss head, training duration, and the number of training identities, and evaluate each configuration on nine benchmarks. Our results indicate that the number of training identities has the largest effect on member/non-member separability, while backbone and loss head contribute far less, and that, on a same-domain held-out reference, the geometric membership signal decreases monotonically as more identities are added to training. We provide an analysis of cross-domain (pose, age, quality, ethnicity) non-member benchmarks and report that these inflate the apparent membership signal. Finally, we fuse all four statistics with a learned classifier to reveal additional membership information beyond the best individual statistic.

Comment: Accepted at IEEE/IAPR IJCB 2026