{"id":"b5d327d1-cb21-4960-ad65-6018b4e0630d","arxiv_id":"2412.15228","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A survey that classifies image privacy protection methods into data-level, content-level, and feature-level categories using a new 'privacy-sensitive domain' dimension.","lead":"This survey sorts image privacy protection research by which layer of the image is being protected: raw pixels, visible content, or machine-readable features. It is a map of roughly 140 existing techniques that researchers and engineers can use to locate methods and spot gaps in the field.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Load-bearing concern: the three-level taxonomy is not uniquely defined. Encryption appears as both data-level (§3.2.1) and content-level (§4.2.4), and adversarial perturbation appears at both data-level (§3.4.2) and feature-level (§5.2.1), so 'any solution can find its appropriate classification'…","rationale":"The reader identified corpus representativeness as the weakest assumption. I agree that is a problem, but I think the more load-bearing issue is the construct validity of the taxonomy itself. The exhaustiveness and positioning claims would fail even with a perfectly representative corpus if the three categories are not mutually exclusive and not operational. The paper's own placement of encryption in both §3.2.1 and §4.2.4 is the clearest evidence: the same primitive is assigned to different levels solely by whether its scope is the whole image or a region. The 'privacy-sensitive domain' is therefore not the actual criterion being applied; scope and visual usability are doing the work. Similarly, adversarial perturbation appears in both data-level irreversibility and feature-level protection, underscoring that the same method can straddle levels. Since any image modification is at the pixel level, the domain labels are interpretations rather than intrinsic properties. This concern is about the internal consistency of the framework, not about disagreement with outside consensus, and it directly targets the paper's main claimed contribution. A conditional acceptance with a demand to either make the categories formally disjoint and operational (for example, by defining the primary domain through the adversary model or the protected task) or soften the positioning claim to a multi-label perspective would resolve it. That is why I keep the reader's CONDITIONAL verdict: the survey remains useful as a catalog, but the framing claim needs revision.","tokens_in":32383,"tokens_out":6829,"duration_ms":64757,"concrete_test":"Run an inter-annotator classification test on the paper's own corpus. Strip section labels from 20 representative methods (including [17], [49], [44], [45], [56], and [68]) and give two independent annotators only the §2.1-§2.2 definitions and Fig. 3. Measure agreement and compare with the paper's assignments; if the same method is assigned to different levels by the annotators, or if the annotators cannot reproduce the paper's labels, then the trichotomy is not an operational classification and the positioning claim in §2.2 fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The framework's central claim (§2.2) is that every image privacy protection method has an 'appropriate classification' in the data/content/feature trichotomy. This requires the privacy-sensitive-domain criterion (§2.1) to be a well-defined partition of methods. The paper does not supply such a partition. Encryption is assigned to data-level when it covers the whole image (§3.2.1, examples [17]-[26]) and to content-level when it covers selected regions (§4.2.4, examples [49]-[56]); §4.2.4 states the difference as 'does not involve comprehensively encrypting the entire image... encrypting only select pixels,' i.e., scope and visual usability, not the domain being protected. Likewise, adversarial perturbation is the core feature-level approach (§5.2.1) but also appears in data-level irreversibility (§3.4.2, [43]-[45]). Because every content-level or feature-level operation is ultimately executed on pixels, 'pixel domain,' 'visual content domain,' and 'feature domain' are not intrinsic properties of a mechanism; they are post-hoc interpretations of intent. Face pixelation, for instance, modifies pixels, changes visible content, and suppresses face-recognition features simultaneously. The paper gives no rule for choosing the primary domain in such cases, and its own assignments show inconsistent choices. Consequently, even granting complete corpus coverage, the framework cannot position methods uniquely or deterministically; the exhaustiveness claim in §2.2 is therefore unsupported.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper surveys image privacy protection techniques and organizes them by a proposed 'privacy-sensitive domain' construct, dividing methods into data-level (whole-image pixel treatment), content-level (targeted modification of visually sensitive regions), and feature-level (protection against machine extraction). It claims that this trichotomy yields a comprehensive framework and a positioning system in which any image privacy solution can be classified, and it applies the framework to roughly 140 papers. The survey also discusses design principles and future directions such as dynamic revocable protection and privacy under multimodal learning.","tokens_in":32632,"tokens_out":7058,"duration_ms":59796,"significance":"If the framework's classification were well-defined, the survey would provide a useful cross-scenario view of image privacy protection, complementing existing scenario-specific and objective-specific surveys. The paper's strengths include the breadth of recent literature covered, explicit tabular summaries of methods, and a clear discussion of visual-usability trade-offs. However, the central contribution is a taxonomy, and for a taxonomy the uniqueness and exhaustiveness of the classification is the standard of correctness. The observed inconsistencies make the current version unable to support the 'positioning system' claim.","major_comments":[{"comment":"The central claim (Section 2.2, contribution 3 in Section 1.4) is that every image privacy protection solution can find its appropriate classification in the data/content/feature trichotomy. This requires the privacy-sensitive-domain criterion to be a well-defined, deterministic partition of methods. The paper does not supply such a partition. Encryption is classified as data-level when it covers the whole image (Section 3.2.1, refs [17]-[26]) and as content-level when it covers only selected regions (Section 4.2.4, refs [49]-[56]); the stated difference is 'does not involve comprehensively encrypting the entire image... encrypting only select pixels,' i.e., scope and visual usability, not the domain being protected. Similarly, adversarial perturbation appears as a data-level irreversibility scheme (Section 3.4.2, refs [44]-[45]) and as the core feature-level approach (Section 5.2.1). Face pixelation simultaneously modifies pixels, changes visible content, and suppresses face-recognition features, and no rule is given for choosing a primary domain in such cases. The exhaustiveness/uniqueness claim is therefore unsupported as stated.","section":"§2.2, §3.2.1, §4.2.4"},{"comment":"The survey calls itself systematic (abstract) but provides no search strategy, time window, or inclusion/exclusion criteria for the reviewed corpus. The selection appears strongly skewed toward the authors' own research: the TPE line [66]-[77] is reviewed at length, and the authors' works appear as [40], [68]-[77], [90], [94], [104], [116], [118], [119], among others, while major branches such as differential privacy for image release and image-specific federated learning are absent. Because the framework's universal claim ('any image privacy protection solution') depends on the reviewed corpus being representative, the missing documentation of the selection process is a load-bearing gap.","section":"Abstract; §1.4"},{"comment":"The framework claims to cover various privacy objectives (§2.2), and Section 1.1 defines contextual privacy as one of the three core privacy categories. Yet the taxonomy includes no category for methods that target cross-modal inference, and the only substantive treatment of such threats appears in the challenges section (§6.3). The data-level design principles assert that full encryption prevents contextual correlation (§3.5), but no reviewed method is analyzed from this angle. This gap is distinct from the non-uniqueness problem: even a well-defined trichotomy would not cover the stated objective set.","section":"§1.1, §2.2, §6.3"}],"minor_comments":[{"comment":"The word 'abilitys' is used in Sections 3.1, 4.1, and 5.1; it should read 'abilities'.","section":"§3.1, §4.1, §5.1"},{"comment":"The abstract says the review is 'based on privacy protection goals', but Section 2 uses 'privacy-sensitive domain' as the core classification dimension; these two framings should be reconciled.","section":"Abstract; §2"},{"comment":"The definition of 'privacy-sensitive domain' as 'the privacy region in an image' is narrower than its use as a method-level classification; the relationship between the region and the method should be clarified.","section":"§2.1"},{"comment":"The header claims an ACM format of August 2018 and © 2018, while the manuscript and references are from 2024; the template date should be corrected.","section":"Header"},{"comment":"The notation in Tables 3 and 5-6 ('#', 'G #', blank cells) is difficult to parse; a legend with explicit check marks and clearly defined abbreviations would make the tables usable as evidence.","section":"Tables 3, 5, 6"}],"recommendation":"major_revision","confidential_remarks":"The paper reads like a field survey rather than a focused contribution, which may raise questions about fit with the journal's scope. In addition, the high density of self-citations among the reviewed corpus and the absence of a documented literature search will likely attract scrutiny from referees; the authors should be asked to either provide a representative, documented selection process or soften the universal claims accordingly."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Two things to know. First, this is a survey that actually offers a different way to slice the image-privacy literature: by privacy-sensitive domain (pixel/content/feature) rather than by scenario or objective, with reversibility/robustness as secondary axes. That is a real service, and the open problems section is genuinely forward-looking. Second, the paper's central claim—'any image privacy protection solution can find its appropriate classification'—is not supported by its own material. That needs to be fixed before this can be cited as a positioning framework.\n\nThe strength is the re-framing in Section 1.4/2.1. I haven't seen the domain trichotomy used as the primary organizer in the cited surveys, and it does help compare, say, whole-image encryption with face blurring and adversarial perturbation. The per-category reviews cover a lot of ground and the reversibility/irreversibility split within each level is a useful way to talk about usability.\n\nThe soft spots are real, and I'd put the taxonomy problem closer to the center than the reader's soundness score suggests. The stress-test note is right: encryption appears at data level in §3.2.1 and content level in §4.2.4, and adversarial perturbation appears at data level (§3.4.2) and feature level (§5.2.1). The authors' stated ground for the content-level encryption choice is scope and visual usability, not what domain is protected. Since every method ultimately manipulates pixels, the trichotomy is a post-hoc interpretation of intent, not a well-defined partition. The claim of a comprehensive positioning system therefore overreaches; at best this is a useful heuristic taxonomy.\n\nI also share the reader's concern about corpus fairness. The word 'systematic' appears, but no methodology is given, and the content-level global subsection leans heavily on the authors' own TPE line ([68]–[77]) and related work ([40], [90], [94], [104], [116], [118], [119], [144]). Major strands like differential privacy for images are absent. That does not sink the survey, but it means the exhaustiveness claim is unsubstantiated.\n\nMechanical issues: inconsistent upload statistics in §1.1, a 2018 ACM template on a December 2024 arXiv submission, and several garbled table entries. Minor, but symptomatic.\n\nRecommendation: yes, give it to a serious referee. Researchers looking for a map of this area and its open problems will get value, but revisions should soften the universality claim, add a methodology paragraph, and rebalance the reference list. I wouldn't cite it as-is in my own work.","headline":"A useful re-framing of image privacy protection, but the 'any scheme fits' positioning claim is undercut by the paper's own taxonomy assignments.","tokens_in":33236,"tokens_out":4501,"would_cite":false,"duration_ms":38977,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A survey maps all image privacy methods onto three domains: pixels, visual content, or features.","keywords":["image privacy protection","privacy-sensitive domains","data-level protection","content-level protection","feature-level protection","survey","adversarial perturbation","thumbnail-preserving encryption"],"falsifier":"Exhibit a published image privacy protection scheme whose privacy-sensitive domain is neither pixels, visual content, nor features—for instance a method that protects only image metadata or only the social-graph context around an image—and show that the framework cannot place it without stretching the definition of a domain; alternatively, show a single scheme that the paper itself must assign to two different levels, which would demonstrate the trichotomy is not uniquely defined.","tokens_in":32089,"feed_emoji":"🖼️","tokens_out":3473,"duration_ms":32650,"temperature":0.7,"pith_summary":"This survey tries to establish that the right way to organize the entire field of image privacy protection is by what part of an image is sensitive, rather than by scenario (social networks, surveillance) or by specific target (faces, medical lesions). It defines the privacy-sensitive domain as the region of the image that needs protection and argues that every protection scheme acts on one of three such domains: the pixel domain, the visual content domain, or the feature domain. On this basis it builds a three-level framework—data-level, content-level, and feature-level protection—and claims that any image privacy protection solution can find an appropriate place within it. If the framework holds, researchers and users can compare methods across different scenarios and privacy goals using a single coordinate system.","feed_headline":"Three domains sort every image privacy protection method","feed_subtitle":"A new framework groups protection by what is sensitive: pixels, visual content, or features.","key_machinery":"The central object is the privacy-sensitive domain, defined as the region of an image that needs protection, which the paper splits into the pixel domain, the visual content domain, and the feature domain. This trichotomy does the work of a coordinate system: it claims to jointly determine the protection level (data, content, or feature) and the visual usability of the output (none, general, or high). The framework also assigns each level a secondary division—robustness versus non-robustness for data-level, local versus global objectives for content-level, and significant versus non-significant change for feature-level—so that a given scheme is located by its sensitive domain and then by its reversibility and change characteristics.","core_discovery":"The paper's central claim is that the privacy-sensitive domain is the correct core classification dimension for image privacy protection. The privacy-sensitive domain is defined as the privacy region in an image that needs protection, covering all parts that involve sensitive information, and it is categorized into three types: the pixel domain, the visual content domain, and the feature domain. These map onto three protection levels: data-level protection, which manipulates every pixel value and treats the whole image as one indivisible sensitive entity, giving no visual usability; content-level protection, which modifies selected sensitive areas (faces, license plates, buildings) while keeping the image generally usable; and feature-level protection, which alters high-level features so that machines cannot recognize them while the image stays visually natural for humans. The paper supports the framework by reviewing roughly 140 representative solutions, classifying each into the appropriate level, and stating that the framework encompasses all privacy-sensitive domains so that any image privacy protection scheme can find its classification within it.","pith_inferences":["A testable consequence the paper leaves implicit is that any two schemes classified in the same cell of the framework should be interchangeable in practice for a given privacy objective; one could construct a benchmark that swaps, say, content-level reversible schemes across face, license-plate, and medical-image tasks to see whether the taxonomy predicts transferability.","The framework focuses on the image as the unit of analysis; an extension the paper does not pursue would be to treat the privacy-sensitive domain as a continuous spectrum (e.g., partial-pixel, partial-feature hybrid schemes) rather than three discrete bins, since some modern methods combine encryption and adversarial perturbation in one pipeline.","The classification of encryption under both data-level (Section 3.2.1) and content-level (Section 4.2.4) suggests that the same underlying technique can be aimed at different sensitive domains depending on whether it encrypts all pixels or only selected regions—an ambiguity that a future refinement could resolve by defining the domain as what the scheme actually obscures from a specified adversary","If the framework were combined with a quantitative usability measure, the paper's three-level hierarchy could be turned into a design rule: choose the coarsest domain that still satisfies the adversary model, because moving from data-level to content-level to feature-level monotonically increases visual usability while narrowing the scope of what is protected."],"forward_implications":["If the framework is correct, a reader can take any existing image privacy method, locate which of the three privacy-sensitive domains it acts on, and immediately read off the expected visual usability and the broad class of techniques involved.","Cross-scenario comparison becomes possible: a face-masking method from social-network research and a face-encryption method from surveillance research would both sit in the content-level category, allowing researchers to transfer techniques and evaluation insights between scenarios.","The framework exposes gaps: because the three levels have different usability profiles, a user who needs low visual disturbance must work at the feature level, which imposes the requirement of adversarial-machine resistance.","The paper's own forward-looking challenges—dynamic revocable privacy, user-understandable privacy, and privacy under multimodal learning—follow from the framework's assumption that privacy objectives are fixed, predefined, and image-local rather than user-defined, time-varying, or cross-modal.","The survey's design principles for each level (visual invisibility, general visual usability, high visual usability; adjustable versus fixed sensitive domains; human versus machine adversaries) give new schemes a checklist for what properties they should exhibit in their level."],"supporting_citations":[{"why":"Supplies the three-way privacy taxonomy (contextual, observable, machine privacy) that the paper adapts to motivate its sensitivity-domain levels.","marker":"[8]"},{"why":"Representative scenario-specific review (privacy decision-making in online social networks) that the paper positions its framework against.","marker":"[11]"},{"why":"Representative scenario-specific survey of visual privacy in surveillance systems, used to show existing reviews are bounded by scenario.","marker":"[12]"},{"why":"Representative scenario-specific review of visual sensor network security and privacy, another contrast class for the proposed framework.","marker":"[13]"},{"why":"Representative objective-specific survey of facial identity concealment, used to show existing reviews target single privacy objectives.","marker":"[14]"},{"why":"Representative objective-specific survey of biometric privacy enhancement, supporting the claim that prior reviews focus on one biometric goal.","marker":"[15]"},{"why":"Representative objective-specific review of privacy-preserving AI in medical imaging, completing the contrast set for the framework's motivation.","marker":"[16]"}],"fun_headline_variants":["Three domains classify all image privacy methods","Image privacy: a survey grouped by what is sensitive","From pixels to features: a framework for image privacy","Privacy-sensitive domains: a new lens for image protection","How to protect image privacy: a three-level survey"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The framework's claim to cover any image privacy protection scheme rests on the reviewed corpus fairly representing the whole field, but the paper gives no search strategy, time window, or inclusion/exclusion criteria, and some major branches (for example differential privacy applied to images) do not appear in the review.","fun_headline_variants_meta":{"raw":{"variants":["Three domains classify all image privacy methods","Image privacy: a survey grouped by what is sensitive","From pixels to features: a framework for image privacy","Privacy-sensitive domains: a new lens for image protection","How to protect image privacy: a three-level survey"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000729,"raw_usage":{"total_tokens":3286,"prompt_tokens":988,"completion_tokens":2298,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":604,"completion_tokens_details":{"reasoning_tokens":2225}},"tokens_in":604,"tokens_out":2298,"duration_ms":13945,"temperature":1.0,"reasoning_tokens":2225,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T21:55:25.059414+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Exhibit a published image privacy protection scheme whose privacy-sensitive domain is neither pixels, visual content, nor features—for instance a method that protects only image metadata or only the social-graph context around an image—and show that the framework cannot place it without stretching the definition of a domain; alternatively, show a single scheme that the paper itself must assign to two different levels, which would demonstrate the trichotomy is not uniquely defined.","supporting_citations":[],"review_version":1}