arXiv:2412.17038cs.CVcs.AI2024-12被引 1

提出可擦除的面部隐私保护方法,有效对抗黑箱人脸识别且不永久损伤图像。

ErasableMask: A Robust and Erasable Privacy Protection Scheme against Black-box Face Recognition Models

  • 通过元辅助攻击学习通用特征,提升对黑箱模型的迁移性。
  • 在商业人脸识别系统上平均识别置信度超72%,扰动擦除成功率超90%。
  • 支持隐私保护后图像恢复,适合需取证和认证的场景。

尽管人脸识别(FR)模型在身份验证与识别中带来了显著便利,但也对公众隐私构成重大风险。现有隐私保护方案多采用对抗样本干扰FR模型,但往往对黑箱模型转移能力弱,且永久破坏可识别信息,无法满足取证与认证等授权操作需求。为此,我们提出ErasableMask,一种针对黑箱FR模型的鲁棒且可擦除的隐私保护方案。具体地,通过重新思考代理FR模型之间的内在关系,ErasableMask引入新型元辅助攻击,在稳定平衡的优化策略下学习更具泛化性的特征,显著提升黑箱迁移性;同时提供扰动擦除机制,可在不降低图像质量的前提下移除语义扰动。为进一步提升性能,还采用课程学习策略缓解对抗攻击与扰动擦除间的优化冲突。在CelebA-HQ和FFHQ数据集上的大量实验表明,ErasableMask在迁移性上达到当前最优水平,于商业FR系统上平均识别置信度超过72%;同时扰动擦除成功率超过90%。

原文摘要 · Abstract (English)

While face recognition (FR) models have brought remarkable convenience in face verification and identification, they also pose substantial privacy risks to the public. Existing facial privacy protection schemes usually adopt adversarial examples to disrupt face verification of FR models. However, these schemes often suffer from weak transferability against black-box FR models and permanently damage the identifiable information that cannot fulfill the requirements of authorized operations such as forensics and authentication. To address these limitations, we propose ErasableMask, a robust and erasable privacy protection scheme against black-box FR models. Specifically, via rethinking the inherent relationship between surrogate FR models, ErasableMask introduces a novel meta-auxiliary attack, which boosts black-box transferability by learning more general features in a stable and balancing optimization strategy. It also offers a perturbation erasion mechanism that supports the erasion of semantic perturbations in protected face without degrading image quality. To further improve performance, ErasableMask employs a curriculum learning strategy to mitigate optimization conflicts between adversarial attack and perturbation erasion. Extensive experiments on the CelebA-HQ and FFHQ datasets demonstrate that ErasableMask achieves the state-of-the-art performance in transferability, achieving over 72% confidence on average in commercial FR systems. Moreover, ErasableMask also exhibits outstanding perturbation erasion performance, achieving over 90% erasion success rate.

隐私保护人脸识别对抗攻击可擦除

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。