arXiv:2412.09692cs.CV2024-12被引 1

提出新型抗检索扰动方法,有效抵御社交网络中的图像隐私泄露。

Three-in-One: Robust Enhanced Universal Transferable Anti-Facial Retrieval in Online Social Networks

  • 构建压缩生成器模拟真实后处理,增强扰动鲁棒性。
  • 通过元学习与迭代优化,实现通用迁移下的高抗干扰能力。
  • 在主流社交平台表现优异,适合保护真实场景下的面部隐私。

基于深度哈希的检索技术广泛用于人脸识别系统以提升匹配效率,但也带来隐私泄露风险。现有对抗样本方法虽具通用性和可迁移性,但在在线社交网络(OSNs)中缺乏鲁棒性研究,导致经后处理后防检索失效。本文首次深入探讨通用可迁移反人脸识别中的鲁棒性问题,提出Three-in-One对抗扰动(TOAP)方法。具体地,设计局部与全局压缩生成器(CG)模拟复杂后处理场景;基于模型分布变化模式发现,构建鲁棒优化目标,并结合元学习生成对抗样本;通过交替生成对抗样本与微调CG,实现扰动性能与缓解能力的平衡。大量实验表明,相比当前最优方法,TOAP在多个鲁棒性指标上显著提升,通用性与可迁移性提高5%至28%,在多种模拟后处理及主流OSNs中实现约33%的性能增益,验证了其在真实场景中有效防护私密图像免遭恶意检索的能力。

原文摘要 · Abstract (English)

Deep hash-based retrieval techniques are widely used in facial retrieval systems to improve the efficiency of facial matching. However, it also carries the danger of exposing private information. Deep hash models are easily influenced by adversarial examples, which can be leveraged to protect private images from malicious retrieval. The existing adversarial example methods against deep hash models focus on universality and transferability, lacking the research on its robustness in online social networks (OSNs), which leads to their failure in anti-retrieval after post-processing. Therefore, we provide the first in-depth discussion on robustness adversarial perturbation in universal transferable anti-facial retrieval and propose Three-in-One Adversarial Perturbation (TOAP). Specifically, we construct a local and global Compression Generator (CG) to simulate complex post-processing scenarios, which can be used to mitigate perturbation. Then, we propose robust optimization objectives based on the discovery of the variation patterns of model's distribution after post-processing, and generate adversarial examples using these objectives and meta-learning. Finally, we iteratively optimize perturbation by alternately generating adversarial examples and fine-tuning the CG, balancing the performance of perturbation while enhancing CG's ability to mitigate them. Numerous experiments demonstrate that, in addition to its advantages in universality and transferability, TOAP significantly outperforms current state-of-the-art methods in multiple robustness metrics. It further improves universality and transferability by 5% to 28%, and achieves up to about 33% significant improvement in several simulated post-processing scenarios as well as mainstream OSNs, demonstrating that TOAP can effectively protect private images from malicious retrieval in real-world scenarios.

隐私保护对抗样本人脸识别社交网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。