用对抗扰动破坏人脸生物特征,防止被恶意编辑篡改身份。
Edit Away and My Face Will not Stay: Personal Biometric Defense against Malicious Generative Editing
- 通过优化扰动同时干扰人脸识别与视觉感知,破坏生物特征。
- 在多种编辑攻击下仍保持有效,且能抵御净化处理。
- 适合关注隐私保护的图像编辑用户和安全研究者。
扩散模型的进展使图像生成编辑更易获取,但也带来恶意修改人像的伦理风险,威胁隐私与身份安全。现有防护方法多依赖对抗扰动来消除编辑效果,但对多样编辑请求泛化能力差。我们提出FaceLock,一种新型人脸保护方法,通过优化对抗扰动以破坏或显著改变生物特征信息,使编辑结果在生物特征上无法识别。FaceLock将人脸识别与视觉感知融合至扰动优化中,提升对各类编辑尝试的鲁棒性。实验表明,FaceLock优于基线方法,对净化技术也具有强抵抗力。消融研究验证其稳定性及在扩散模型编辑算法中的广泛适用性。本工作推进了生物特征防护,为图像编辑的隐私保护奠定基础。代码已公开:https://github.com/taco-group/FaceLock。
原文摘要 · Abstract (English)
Recent advancements in diffusion models have made generative image editing more accessible, enabling creative edits but raising ethical concerns, particularly regarding malicious edits to human portraits that threaten privacy and identity security. Existing protection methods primarily rely on adversarial perturbations to nullify edits but often fail against diverse editing requests. We propose FaceLock, a novel approach to portrait protection that optimizes adversarial perturbations to destroy or significantly alter biometric information, rendering edited outputs biometrically unrecognizable. FaceLock integrates facial recognition and visual perception into perturbation optimization to provide robust protection against various editing attempts. We also highlight flaws in commonly used evaluation metrics and reveal how they can be manipulated, emphasizing the need for reliable assessments of protection. Experiments show FaceLock outperforms baselines in defending against malicious edits and is robust against purification techniques. Ablation studies confirm its stability and broad applicability across diffusion-based editing algorithms. Our work advances biometric defense and sets the foundation for privacy-preserving practices in image editing. The code is available at: https://github.com/taco-group/FaceLock.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。