通过强化局部特征实现黑盒人脸识别的隐私保护
Local Features Meet Stochastic Anonymization: Revolutionizing Privacy-Preserving Face Recognition for Black-Box Models
- 利用局部特征增强与全局特征破坏提升识别性能
- 在黑盒模型上实现94.21%平均识别准确率
- 随机不可逆注入防止图像重建,适合高隐私需求场景
当前隐私保护人脸识别(PPFR)面临两大挑战:(1)现有方法通常仅适用于特定人脸识别模型,难以泛化至黑盒模型;(2)当前方法采用数据驱动的可逆表示编码,易受对抗学习和原始图像重建。我们观察到人脸识别模型主要依赖局部特征(如面部轮廓、皮肤纹理等)进行识别。因此,通过破坏全局特征并增强局部特征,可在黑盒环境中实现有效识别。此外,为防止对抗模型学习并逆向匿名化过程,我们采用基于对抗学习的不可逆随机注入方法,确保匿名化过程的随机性。实验结果表明,该方法在黑盒模型上的平均识别准确率达94.21%,在隐私保护与抗重建能力上均优于现有方法。
原文摘要 · Abstract (English)
The task of privacy-preserving face recognition (PPFR) currently faces two major unsolved challenges: (1) existing methods are typically effective only on specific face recognition models and struggle to generalize to black-box face recognition models; (2) current methods employ data-driven reversible representation encoding for privacy protection, making them susceptible to adversarial learning and reconstruction of the original image. We observe that face recognition models primarily rely on local features ({e.g., face contour, skin texture, and so on) for identification. Thus, by disrupting global features while enhancing local features, we achieve effective recognition even in black-box environments. Additionally, to prevent adversarial models from learning and reversing the anonymization process, we adopt an adversarial learning-based approach with irreversible stochastic injection to ensure the stochastic nature of the anonymization. Experimental results demonstrate that our method achieves an average recognition accuracy of 94.21\% on black-box models, outperforming existing methods in both privacy protection and anti-reconstruction capabilities.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。