arXiv:2411.18165cs.CV2024-11被引 6

用KAN网络从人脸嵌入还原图像,揭示隐私保护人脸识别的漏洞

KAN See Your Face

  • 提出FEM-KAN模型,用KAN网络学习嵌入到人脸的非线性映射
  • 在多个SOTA系统上成功还原出高保真人脸图像,重建质量优于MLP
  • 首次系统评估了嵌入泄露风险,适合关注人脸识别安全的研究者

随着人脸重建(FR)技术的发展,隐私保护人脸识别(PPFR)因其安全性、隐私保护能力及对各类攻击的鲁棒性而受到关注。现有方法通过将嵌入映射到安全空间来保护面部嵌入。然而,尚缺乏对从这些系统嵌入中恢复人脸图像可能性的研究,尤其针对PPFR。本文首次提出利用柯尔莫哥洛夫-阿诺德网络(KAN)进行嵌入到人脸的攻击,设计了面部嵌入映射(FEM)模型,学习初始域与目标域嵌入间的分布映射关系。相比多层感知机(MLP),我们提出FEM-KAN和FEM-MLP两种变体,实现高效非线性嵌入到嵌入的映射,从而从对应嵌入重建真实人脸图像。通过在多种PPFR和FR模型上开展广泛实验,并使用不同指标评估重建图像质量,结果表明FEM在准确嵌入映射与人脸重建方面均有效。

原文摘要 · Abstract (English)

With the advancement of face reconstruction (FR) systems, privacy-preserving face recognition (PPFR) has gained popularity for its secure face recognition, enhanced facial privacy protection, and robustness to various attacks. Besides, specific models and algorithms are proposed for face embedding protection by mapping embeddings to a secure space. However, there is a lack of studies on investigating and evaluating the possibility of extracting face images from embeddings of those systems, especially for PPFR. In this work, we introduce the first approach to exploit Kolmogorov-Arnold Network (KAN) for conducting embedding-to-face attacks against state-of-the-art (SOTA) FR and PPFR systems. Face embedding mapping (FEM) models are proposed to learn the distribution mapping relation between the embeddings from the initial domain and target domain. In comparison with Multi-Layer Perceptrons (MLP), we provide two variants, FEM-KAN and FEM-MLP, for efficient non-linear embedding-to-embedding mapping in order to reconstruct realistic face images from the corresponding face embedding. To verify our methods, we conduct extensive experiments with various PPFR and FR models. We also measure reconstructed face images with different metrics to evaluate the image quality. Through comprehensive experiments, we demonstrate the effectiveness of FEMs in accurate embedding mapping and face reconstruction.

人脸识别隐私保护嵌入还原KAN网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。