Your Smart Glasses' 'Private' Eye Camera Can Still Identify You
That scrambled eye-tracking image? AI can still figure out exactly who you are.
Smart glasses and next-gen headsets need to know where your eyes are looking. To save space and ease privacy worries, some designs drop the lens entirely, using a lensless camera that captures a coded, blurry pattern instead of a real picture. Because that pattern looks like random noise to a human eye, companies have described it as privacy-friendly — you can't see a face, so what's the harm?
Quite a lot, according to researchers Rahul Vimalkanth and Kaushik Mitra. They ran a simulated lensless eye-tracking system with 36 people and trained AI models to identify who was who from those scrambled measurements. The AI got it right 96.7% of the time — essentially as well as it did with ordinary, full-quality eye photos (97.7%). In other words, if the scrambled data leaves your device, it's not much safer than handing over a photo of your eye.
The team then tested common privacy fixes. Compressing the data down to just 8 numbers still allowed identification 92% of the time. A special "gaze token" design did better, dropping single-frame identification to 38.1% — but the leftover and continuous data streams around it still leaked 62% and 73% respectively. Even after statistically removing obvious clues like eye size and brightness, identification stayed at 95.1%.
The lesson is simple and slightly unsettling: privacy isn't about whether data looks unreadable to you. It's about what a trained AI can pull out of it. The authors argue that any company claiming a sensor is "private by design" should have to prove it at every point where the data could escape — not just point at a fuzzy image and call it safe.
- Scrambled images from lensless eye cameras still let AI identify people 96.7% of the time — barely worse than a normal photo
- Squeezing the data down to a tiny 8-number summary still leaked identity 92% of the time, so compression alone isn't protection
- A newer 'gaze token' format cut leakage to 38%, showing privacy-friendly designs are possible but need careful engineering
Why It Matters
If you wear or buy smart glasses, 'it looks encrypted' may be a false promise about your identity and habits.