REVIEW 4 major objections 3 minor 1 cited by
Privacy Enhancement for Gaze Data Using a Noise-Infused Autoencoder
T0 review · 4 major / 3 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read A latent-noise autoencoder can strip gaze data of its biometric identity while preserving its usefulness for benign prediction tasks.
desk verdict A plausible gaze-privacy mechanism that I cannot evaluate because the supplied full text is unreadable; the abstract overclaims 'prevents' where the evidence can only support 'reduces.' read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is a noise-infused autoencoder, a neural network that maps gaze traces into a low-dimensional latent code, perturbs that code with random noise, and reconstructs a gaze signal from the perturbed code. The latent noise is the privacy mechanism: it disrupts the identity-specific regularities that biometric identification exploits while leaving intact the broader gaze statistics that benign prediction tasks depend on. The evaluation sets the two sides of the trade-off as biometric identification accuracy and gaze prediction accuracy, with the physiological plausibility of outputs as the factor that keeps the two sides in balance.
What would settle it
Train a re-identification model on the privacy-transformed gaze traces themselves and run it across sessions with a large gallery and a realistic time gap; if identification accuracy returns to a level close to the original, the claimed privacy protection does not survive a determined attacker.
Extended reading notes
Core claim
On the paper's own terms, the discovery is that the latent space of an autoencoder is the right place to inject privacy noise for gaze signals. An encoder compresses a gaze trace into a compact code, random noise is added to that code, and a decoder produces a modified trace that no longer carries the identity-specific structure that biometric identification relies on. The paper reports a significant drop in biometric identifiability across play sessions together with minimal degradation on gaze prediction, and it attributes the favorable trade-off to the physiological plausibility of the reconstructed traces. The intended consequence is a practical privacy mechanism: gaze data can be transformed once and then used for benign purposes without enabling re-identification.
Load-bearing premise
The load-bearing premise is that the evaluation protocol measures the real threat: the biometric identification task must reflect the re-identification risk an attacker actually faces across play sessions, and the gaze prediction task must reflect the benign uses that actually matter.
Editorial extensions
If this is right
- Gaze-data holders could release transformed traces that resist cross-session re-identification while still supporting benign gaze-prediction tasks.
- The latent noise level becomes a tunable dial, letting a system choose where it sits on the privacy-utility frontier.
- Because outputs remain physiologically plausible, benign downstream models are less likely to be disrupted by reconstruction artifacts than by input-level perturbations.
- The approach can be applied at the point of collection, so raw identifiable gaze never leaves the device.
- Privacy becomes a transformation problem rather than a suppression problem: the data can stay useful without exposing the person.
Reading between the lines
- The paper's threat model assumes an attacker who runs the same kind of identification benchmark; a stronger adversary who trains an identifier on the transformed traces could partially undo the privacy gain, and that scenario is not settled by the reported numbers.
- The same latent-noise design should transfer to other continuous biometric signals, such as ECG, EEG, or gait, wherever an autoencoder can separate identity-specific from task-relevant variation.
- A natural follow-up is to calibrate the latent noise to a formal privacy definition such as differential privacy, which would turn the empirical trade-off into a provable bound.
- A quantitative metric for physiological plausibility would let future work test directly whether realism is what preserves utility, rather than treating it as a stated property.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a privacy-enhancing mechanism for gaze signals based on a latent-noise autoencoder. The abstract claims that injecting noise into the latent space of an autoencoder prevents users from being re-identified across play sessions without their consent, while preserving the utility of the data for benign tasks. The authors report evaluating privacy-utility trade-offs across biometric identification and gaze prediction tasks, asserting a significant reduction in biometric identifiability with minimal utility degradation, and further claim that the framework retains physiologically plausible gaze patterns. Because the supplied full text is unreadable mojibake, no equations, datasets, baselines, results, or ablations are accessible in the submission, leaving the central empirical claim entirely unverifiable from the available material.
Significance. If the claimed results are correct, the paper would make a valuable contribution to privacy in gaze-based systems by demonstrating that a latent-noise autoencoder can serve as a practical, tunable privacy mechanism with a favorable privacy-utility trade-off. The problem is well motivated and the method is plausible. However, the significance cannot currently be assessed from the submission: the full text is corrupted, and the abstract provides no quantitative evidence, no dataset names, no baseline comparisons, and no description of the evaluation protocol. The paper does not, in the available material, ship reproducible code or machine-checked proofs, so the central claim rests entirely on the unreadable full text.
major comments (4)
- [Full text (as supplied)] The full text supplied to the referee is corrupted mojibake; no equations, tables, figures, dataset names, or numerical results are legible. The central claim that the proposed autoencoder significantly reduces biometric identifiability with minimal utility degradation is therefore unverifiable from this submission. The authors must resubmit a readable version with the complete methodology and all empirical results before the manuscript can be reviewed.
- [Abstract, first sentence] The abstract states that the mechanism "prevents users from being re-identified," but the evaluation described in the abstract can at most support a reduction in identifiability. This wording overstates the likely result and should be corrected, since the paper has not demonstrated a complete absence of re-identification risk.
- [Abstract, evaluation description] The abstract reports no datasets, baseline methods, identification accuracy, false-acceptance rates, utility metrics, or noise-level settings. The claimed privacy-utility trade-off is the central result, and without specifying the biometric identification protocol (identification model, gallery size, session gap, operating point) and the gaze prediction task, the claim is not reproducible and its real-world validity cannot be assessed. A concrete test is to report the privacy-utility curve over noise levels under a cross-session identification protocol.
- [Abstract, physiologically plausible gaze patterns] The claim that the framework retains physiologically plausible gaze patterns is not supported by any visible evaluation criterion. The authors should specify the plausibility measure (e.g., comparison with known saccade and fixation statistics, perceptual evaluation, or a quantitative plausibility metric) and report the corresponding results, since this claim is presented as an advantage over prior methods.
minor comments (3)
- [Abstract] The phrase "usable and effective mechanism" is vague; consider specifying the exact privacy guarantee provided (e.g., reduction to chance-level identification or a concrete upper bound on re-identification accuracy).
- [Abstract, 'without their consent'] The phrase "without their consent" is ambiguous: is the privacy mechanism applied by the data processor, by the user's client, or by the platform? Clarifying the trust model would help position the contribution.
- [Footer (arXiv:2508.10919)] The extracted footer shows an arXiv identifier different from the manuscript ID (2508.10918); please check whether this is an artifact of extraction or a genuine mismatch in the submission metadata.
Assumptions & free parameters
free parameters (2)
- latent noise magnitude
- autoencoder architecture and training hyperparameters
assumptions (3)
- domain assumption Identity-discriminative information in gaze is separable from task-relevant information, so latent noise can remove the former while preserving the latter.
- domain assumption Biometric identification accuracy on the evaluation protocol is a valid estimate of cross-session re-identification risk.
- standard math Standard autoencoder training with stochastic noise converges to a useful reconstruction of gaze signals.
Cite this review
Pith. "Pith review of Privacy Enhancement for Gaze Data Using a Noise-Infused Autoencoder." pith.science (2026). https://pith.science/paper/HMA6ZXSB
@misc{pith2026250810918,
author = {Pith},
title = {Pith review of: Privacy Enhancement for Gaze Data Using a Noise-Infused Autoencoder},
year = {2026},
howpublished = {\url{https://pith.science/paper/HMA6ZXSB}},
note = {Machine review of arXiv:2508.10918}
}
read the original abstract
We present a privacy-enhancing mechanism for gaze signals using a latent-noise autoencoder that prevents users from being re-identified across play sessions without their consent, while retaining the usability of the data for benign tasks. We evaluate privacy-utility trade-offs across biometric identification and gaze prediction tasks, showing that our approach significantly reduces biometric identifiability with minimal utility degradation. Unlike prior methods in this direction, our framework retains physiologically plausible gaze patterns suitable for downstream use, which produces favorable privacy-utility trade-off. This work advances privacy in gaze-based systems by providing a usable and effective mechanism for protecting sensitive gaze data.
Forward citations
Cited by 1 Pith paper
-
Privatization of Synthetic Gaze: Attenuating State Signatures in Diffusion-Generated Eye Movements
Diffusion-generated synthetic gaze shows weaker, less stable correlations with self-reported fatigue and difficulty than real gaze, suggesting partial state-level privatization.
Reference graph
Works this paper leans on
-
[1]
Practical perception-based evaluation of gaze prediction for gaze contingent rendering
Samantha Aziz, Dillon J Lohr, Razvan Stefanescu, and Oleg Komogortsev. Practical perception-based evaluation of gaze prediction for gaze contingent rendering. Proceedings of the ACM on Human-Computer Interaction , 7(ETRA):1--17, 2023
work page 2023
- [2]
-
[3]
Joint attention simulation using eye-tracking and virtual humans
Matthieu Courgeon, Gilles Rautureau, Jean-Claude Martin, and Ouriel Grynszpan. Joint attention simulation using eye-tracking and virtual humans. IEEE Transactions on Affective Computing , 5(3):238--250, 2014
work page 2014
-
[4]
Soft- DTW : a differentiable loss function for time-series
Marco Cuturi and Mathieu Blondel. Soft- DTW : a differentiable loss function for time-series. In Doina Precup and Yee Whye Teh, editors, Proceedings of the 34th International Conference on Machine Learning , volume 70 of Proceedings of Machine Learning Research , pages 894--903. PMLR, 06--11 Aug 2017
work page 2017
-
[5]
A privacy-preserving approach to streaming eye-tracking data
Brendan David-John, Diane Hosfelt, Kevin Butler, and Eakta Jain. A privacy-preserving approach to streaming eye-tracking data. IEEE Transactions on Visualization and Computer Graphics , PP:1--1, 03 2021
work page 2021
-
[6]
Differentially private recommender framework with dual semi-autoencoder
Yang Deng, Wang Zhou, Amin Ul Haq, Sultan Ahmad, and Alia Tabassum. Differentially private recommender framework with dual semi-autoencoder. Expert Syst. Appl. , 260(C), February 2025
work page 2025
-
[7]
Reinforcement learning for the privacy preservation and manipulation of eye tracking data
Wolfgang Fuhl, Efe Bozkir, and Enkelejda Kasneci. Reinforcement learning for the privacy preservation and manipulation of eye tracking data. In Igor Farka s , Paolo Masulli, Sebastian Otte, and Stefan Wermter, editors, Artificial Neural Networks and Machine Learning -- ICANN 2021 , pages 595--607, Cham, 2021. Springer International Publishing
work page 2021
-
[8]
Goodfellow, Jonathon Shlens, and Christian Szegedy
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples, 2015
2015
Show all 30 references
-
[9]
Gazebase, a large-scale, multi-stimulus, longitudinal eye movement dataset
Henry Griffith, Dillon Lohr, Evgeny Abdulin, and Oleg Komogortsev. Gazebase, a large-scale, multi-stimulus, longitudinal eye movement dataset. Scientific Data , 8(1):184, Jul 2021
2021
-
[10]
Otus: A gaze model-based privacy control framework for eye tracking applications
Miao Hu, Zhenxiao Luo, Yipeng Zhou, Xuezheng Liu, and Di Wu. Otus: A gaze model-based privacy control framework for eye tracking applications. In IEEE INFOCOM 2022 - IEEE Conference on Computer Communications , pages 560--569, 2022
2022
-
[11]
An eye-tracking assistive device improves the quality of life for als patients and reduces the caregivers’ burden
Chi-Shin Hwang, Ho-Hsiu Weng, Li-Fen Wang, Chon-Haw Tsai, and Hao-Teng Chang. An eye-tracking assistive device improves the quality of life for als patients and reduces the caregivers’ burden. Journal of motor behavior , 46(4):233--238, 2014
2014
-
[12]
Jamshidi, Hadi Veisi, Mohammad M
Mohammad A. Jamshidi, Hadi Veisi, Mohammad M. Mojahedian, and Mohammad R. Aref. Adjustable privacy using autoencoder-based learning structure. Neurocomputing , 566:127043, 2024
2024
-
[13]
Eye tracking cognitive load using pupil diameter and microsaccades with fixed gaze
Krzysztof Krejtz, Andrew T Duchowski, Anna Niedzielska, Cezary Biele, and Izabela Krejtz. Eye tracking cognitive load using pupil diameter and microsaccades with fixed gaze. PloS one , 13(9):e0203629, 2018
2018
-
[14]
o ger, Otto Hans-Martin Lutz, and Florian M \
Jacob Leon Kr \"o ger, Otto Hans-Martin Lutz, and Florian M \"u ller. What does your gaze reveal about you? on the privacy implications of eye tracking. In IFIP International Summer School on Privacy and Identity Management , pages 226--241. Springer, 2020
2020
-
[15]
Differences in eye movement range based on age and gaze direction
Won June Lee, Ji Hong Kim, Yong Un Shin, Sunjin Hwang, and Han Woong Lim. Differences in eye movement range based on age and gaze direction. Eye , 33(7):1145--1151, 2019
2019
-
[16]
Kaleido : Real-Time privacy control for Eye-Tracking systems
Jingjie Li, Amrita Roy Chowdhury, Kassem Fawaz, and Younghyun Kim. Kaleido : Real-Time privacy control for Eye-Tracking systems. In 30th USENIX Security Symposium (USENIX Security 21) , pages 1793--1810. USENIX Association, August 2021
-
[17]
Differential privacy for eye-tracking data
Ao Liu, Lirong Xia, Andrew Duchowski, Reynold Bailey, Kenneth Holmqvist, and Eakta Jain. Differential privacy for eye-tracking data. In Proceedings of the 11th ACM Symposium on Eye Tracking Research & Applications , ETRA '19, New York, NY, USA, 2019. Association for Computing ...
2019
-
[18]
Enhanced embedded autoencoders: An attribute-preserving face de-identification framework
Jianqi Liu, Zhiwei Zhao, Pan Li, Geyong Min, and Huiyong Li. Enhanced embedded autoencoders: An attribute-preserving face de-identification framework. IEEE Internet of Things Journal , 10(11):9438--9452, 2023
2023
-
[19]
Differentially private recommender system with autoencoders
Xiaoqian Liu, Qianmu Li, Zhen Ni, and Jun Hou. Differentially private recommender system with autoencoders. In 2019 International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CP...
2019
-
[20]
Komogortsev
Dillon Lohr and Oleg V. Komogortsev. Eye know you too: Toward viable end-to-end eye movement biometrics for user authentication. IEEE Transactions on Information Forensics and Security , 17:3151--3164, 2022
2022
-
[21]
Establishing a baseline for gaze-driven authentication performance in vr: A breadth-first investigation on a very large dataset
Dillon Lohr, Michael J Proulx, and Oleg Komogortsev. Establishing a baseline for gaze-driven authentication performance in vr: A breadth-first investigation on a very large dataset. In 2024 IEEE International Joint Conference on Biometrics (IJCB) , pages 1--10. IEEE, 2024
2024
-
[22]
Uncertainty-autoencoder-based privacy and utility preserving data type conscious transformation
Bishwas Mandal, George Amariucai, and Shuangqing Wei. Uncertainty-autoencoder-based privacy and utility preserving data type conscious transformation. In 2022 International Joint Conference on Neural Networks (IJCNN) , pages 1--8, 2022
2022
-
[23]
Raschka, Anoop M
Vahid Mirjalili, S. Raschka, Anoop M. Namboodiri, and Arun Ross. Semi-adversarial networks: Convolutional autoencoders for imparting privacy to face images. 2018 International Conference on Biometrics (ICB) , pages 82--89, 2017
2018
-
[24]
Towards foveated rendering for gaze-tracked virtual reality
Anjul Patney, Marco Salvi, Joohwan Kim, Anton Kaplanyan, Chris Wyman, Nir Benty, David Luebke, and Aaron Lefohn. Towards foveated rendering for gaze-tracked virtual reality. ACM Trans. Graph. , 35(6), dec 2016
2016
-
[25]
Perero-Codosero, Fernando M
Juan M. Perero-Codosero, Fernando M. Espinoza-Cuadros, and Luis A. Hernández-Gómez. X-vector anonymization using autoencoders and adversarial training for preserving speech privacy. Computer Speech & Language , 74:101351, 2022
2022
-
[26]
The eye in extended reality: A survey on gaze interaction and eye tracking in head-worn extended reality
Alexander Plopski, Teresa Hirzle, Nahal Norouzi, Long Qian, Gerd Bruder, and Tobias Langlotz. The eye in extended reality: A survey on gaze interaction and eye tracking in head-worn extended reality. ACM Computing Surveys (CSUR) , 55(3):1--39, 2022
2022
-
[27]
J\" a ger
Paul Prasse, David Robert Reich, Silvia Makowski, Seoyoung Ahn, Tobias Scheffer, and Lena A. J\" a ger. Sp-eyegan: Generating synthetic eye movement data with generative adversarial networks. In Proceedings of the 2023 Symposium on Eye Tracking Research and Applications , ETRA...
2023
-
[28]
Recommender systems based on autoencoder and differential privacy
Jiahui Ren, Xian Xu, Zhihuan Yao, and Huiqun Yu. Recommender systems based on autoencoder and differential privacy. In 2019 IEEE 43rd Annual Computer Software and Applications Conference (COMPSAC) , volume 1, pages 358--363, 2019
2019
-
[29]
Privacy-aware eye tracking using differential privacy
Julian Steil, Inken Hagestedt, Michael Xuelin Huang, and Andreas Bulling. Privacy-aware eye tracking using differential privacy. In Proceedings of the 11th ACM Symposium on Eye Tracking Research & Applications , ETRA '19, New York, NY, USA, 2019. Association for Computing Machinery
2019
-
[30]
Proulx, Sai Deep Tetali, Kevin Butler, and Eakta Jain
Ethan Wilson, Azim Ibragimov, Michael J. Proulx, Sai Deep Tetali, Kevin Butler, and Eakta Jain. Privacy-preserving gaze data streaming in immersive interactive virtual reality: Robustness and user experience, 2024
2024
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.