TY - JOUR
T1 - A Security Analysis of an Outsourcing Scheme for Generalized Eigenvalue Decomposition
AU - Tong, Xiaofei
AU - Bi, Jingguo
AU - Zhang, Ran
AU - Wang, Licheng
AU - Li, Lixiang
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2026
Y1 - 2026
N2 - Face recognition has been widely adopted in Internet of Things (IoT) applications. However, its core process of high-dimensional feature dimensionality reduction usually incurs high computational complexity. To enable efficient processing on resource-constrained terminal devices, such computation-intensive tasks are often outsourced to cloud servers, thereby significantly reducing the local computational burden. Recently, Ding et al. [1] proposed a face recognition outsourcing scheme based on Laplacian Eigenmaps (LE), in which the generalized eigenvalue decomposition (GED) is delegated to a cloud server. By outsourcing the GED procedure, the computational complexity on the client side is substantially reduced, making the scheme more suitable for resource-limited devices. In this paper, we identify potential security risks in the GED outsourcing scheme. Specifically, by analyzing the algebraic and spectral properties of the encrypted matrices observable to the cloud server, we propose a heuristic numerical-analysis-based approach that can effectively recover secret information concealed during the encryption procedure. Experimental results further demonstrate the feasibility of the proposed attack, thereby exposing numerical-level security weaknesses in the existing GED outsourcing scheme. Moreover, in light of the identified vulnerabilities, this paper preliminarily explores optimization directions for GED secure outsourcing mechanisms, providing methodological insights for the design of secure outsourcing computation schemes for IoT-based face recognition.
AB - Face recognition has been widely adopted in Internet of Things (IoT) applications. However, its core process of high-dimensional feature dimensionality reduction usually incurs high computational complexity. To enable efficient processing on resource-constrained terminal devices, such computation-intensive tasks are often outsourced to cloud servers, thereby significantly reducing the local computational burden. Recently, Ding et al. [1] proposed a face recognition outsourcing scheme based on Laplacian Eigenmaps (LE), in which the generalized eigenvalue decomposition (GED) is delegated to a cloud server. By outsourcing the GED procedure, the computational complexity on the client side is substantially reduced, making the scheme more suitable for resource-limited devices. In this paper, we identify potential security risks in the GED outsourcing scheme. Specifically, by analyzing the algebraic and spectral properties of the encrypted matrices observable to the cloud server, we propose a heuristic numerical-analysis-based approach that can effectively recover secret information concealed during the encryption procedure. Experimental results further demonstrate the feasibility of the proposed attack, thereby exposing numerical-level security weaknesses in the existing GED outsourcing scheme. Moreover, in light of the identified vulnerabilities, this paper preliminarily explores optimization directions for GED secure outsourcing mechanisms, providing methodological insights for the design of secure outsourcing computation schemes for IoT-based face recognition.
KW - Generalized eigenvalue decomposition
KW - numerical analysis
KW - secure outsourcing computation
UR - https://www.scopus.com/pages/publications/105044346975
U2 - 10.1109/JIOT.2026.3710254
DO - 10.1109/JIOT.2026.3710254
M3 - Article
AN - SCOPUS:105044346975
SN - 2327-4662
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
ER -