A new analysis of seven face-swapping tools found that none fully hid the identity of the person whose face was being altered. In comparisons against unrelated non-member identities, target-versus-non-member AUCs ranged from 0.729 for E4S to 0.993 for DiffSwap. In ordinary terms, every tool left target-specific signal that an embedding-based test could distinguish from unrelated identities.
The work, posted as an arXiv preprint, asks why a swapped image can retain traces of the target identity and whether a model in identity-embedding space can predict that leakage. It is version 1, dated 26 Aug 2026.
Low false-alarm tests still found the target
One test used a deliberately low false-alarm setting. At a false-positive rate of no more than 1%, a threshold attack correctly flagged 61% of BlendFace targets, 52% of CanonSwap targets, 30% of FaceFusion targets and 12.4% of E4S targets. FaceFusion still reached a 15% true-positive rate when the false-positive rate was capped at 0.1%.
The signal was not limited to a broad ranking effect. In a closed-set gallery of 948 candidate identities, BlendFace put the correct target first in 34% of swaps and among the top ten in 63%. The gallery test shows that residual signal could help elevate a target above many unrelated candidates when the system had to choose from a fixed list.
Donor transfer did not mean target erasure
The results separate two ideas that are easy to conflate: transferring the donor's identity and erasing the target's identity. Five tools were donor-dominated in more than 93% of pairs. But under the paper's working definition of successful anonymization, the other two were treated as failures: DiffSwap was closer to the target in 86% of pairs, while FaceShifter's similarities were 0.198 for the target and 0.226 for the donor.
For the single-swap benchmark, the researchers used VGGFace2-HQ, with 8,624 identities and roughly 1.16 million images. They sampled three disjoint groups of 1,000 donor, target and non-member identities. After failed tool runs were removed, 947 complete pairs with valid swaps from all seven tools remained for identical-input comparisons.
A model explains the fast drop and slow tail
To look beyond a single swap, the authors fitted an affine stochastic model, a compact rule that maps one identity embedding to the next while allowing for random variation. The fits used identity-disjoint triplets, with 57,048 training and 10,667 held-out triplets for FaceFusion, 56,848 and 10,397 for BlendFace, and 16,849 and 7,239 for CanonSwap. Ridge regression was checked with five-fold cross-validation.
On held-out data, the model fit FaceFusion best, with a cosine similarity of 0.769 and an R-squared value of 0.585, a measure of the share of variation captured by the model. BlendFace scored 0.647 and 0.399 on those measures, while CanonSwap scored 0.599 and 0.338. The unexplained residual fractions were 0.414, 0.600 and 0.662, respectively.
For FaceFusion, the fitted operator had a mean Rayleigh gain of about 0.183, a spectral radius of 0.894 and a largest singular value of 10.1. The model predicts strong first-pass attenuation followed by a slower spectral tail, giving the researchers an interpretable way to describe how target signal fades across repeated swaps.
Most of the gain came in the first swap
The cascade results fit that picture. In a five-pass FaceFusion chain, the first swap removed 0.525 of absolute gallery similarity, compared with 0.044 across the next four passes combined, a 12-to-1 asymmetry. Most of the measured reduction therefore came at the beginning, with later swaps producing smaller gains.
Leakage did not simply disappear after that first drop. FaceFusion's excess-leakage ratio rose from 0.139 to 0.893 as the cascade moved toward the non-member level, whose median score was 0.006. The floor was not reached within the five tested swaps, and a membership-inference attack still had an AUC of 0.709 after the fifth.
The model was better at describing the shape of the decline than its exact height. A Monte Carlo rollout predicted pass-1 leakage of 0.168, versus 0.091 measured, and pass-5 leakage of 0.018, versus 0.047 measured. The paper links the mismatch to cascade inputs drifting away from the range of natural images used to fit the rule.
A warning about the tested setting
A comparison across three tools gave the model some broader predictive value. The fitted spectra ranked BlendFace as the slowest late-decay tool, with a spectral radius of 0.920; FaceFusion was intermediate; and CanonSwap was fastest, at 0.854. Observed tails by pass three were approximately 0.88 for BlendFace and 0.79 for CanonSwap, although the shallow tests were not enough to establish exact long-run ratios.
The result is a warning about the tested setting, not a universal scorecard for every face-swapping system. The data came from VGGFace2-HQ, and the operator analysis covered only FaceFusion, BlendFace and CanonSwap; five-pass results were reported only for FaceFusion. The supplied analysis describes the threshold and ranking attacks as lower bounds for stronger, tool-aware or multi-image adversaries, and it measured identity leakage rather than attribute inference. No confidence intervals are reported for the headline AUC and low-false-positive estimates.
The authors present spectral radius as a possible design or certification target, but the affine model is a first-order approximation and its absolute cascade levels were off as inputs moved outside the fitted image range. Further work is needed to determine whether deeper repeated swapping reaches the non-member floor, how the privacy-utility tradeoff changes, and whether the pattern holds on clinical, surveillance or more diverse images.
The practical lesson for privacy audits is that visual quality or donor similarity alone may miss residual target signal. Comparisons with unrelated non-members, low-false-positive identity attacks and, where repeated swapping is proposed, cascade testing can reveal whether the remaining signal is actually approaching the non-member baseline.
Paper data and sources
Original title: Toward Interpretable Privacy Guarantees in Face-Swapping Anonymization
Authors: Vishnu Bondalakunta, Arman Zareian Jahromi, Shuangqing Wei, George Amariucai
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-26
DOI: Not available
Original paper · Full text