arXiv:2501.04390cs.CV2025-01被引 11

用可逆加密技术实现高保真人脸匿名,支持安全还原

iFADIT: Invertible Face Anonymization via Disentangled Identity Transform

  • 分离身份特征与非身份属性,通过密钥控制匿名化
  • 匿名图像可精准还原原图,且保持高清真实细节
  • 适合需要隐私保护又需追溯原始信息的场景

人脸匿名旨在隐藏面部视觉身份以保护个人隐私。传统方法如模糊和像素化虽能去除识别特征,但严重降低图像质量,且易受深度重建攻击。生成模型为保持自然外观提供了新思路,但多数仍存在画质不足、无法恢复原图的问题。本文提出iFADIT(Invertible Face Anonymization via Disentangled Identity Transform),采用解耦架构与基于流的加密模型:前者将身份信息与非身份属性分离,后者在密钥控制下将身份信息转换为匿名版本,过程可逆。匿名图像可通过预训练StyleGAN重建,确保高质量与真实细节。当拥有匹配密钥时,可逆向还原原始人脸。此外,设计专用密钥机制与双阶段训练策略,保障匿名性、可逆性、安全性、多样性与可解释性。定性与定量实验表明,该方法在匿名性、可逆性、安全性、多样性及可解释性方面优于现有方法。

原文摘要 · Abstract (English)

Face anonymization aims to conceal the visual identity of a face to safeguard the individual's privacy. Traditional methods like blurring and pixelation can largely remove identifying features, but these techniques significantly degrade image quality and are vulnerable to deep reconstruction attacks. Generative models have emerged as a promising solution for anonymizing faces while preserving a natural appearance. However, many still face limitations in visual quality and often overlook the potential to recover the original face from the anonymized version, which can be valuable in specific contexts such as image forensics. This paper proposes a novel framework named iFADIT, an acronym for Invertible Face Anonymization via Disentangled Identity Transform. The framework features a disentanglement architecture coupled with a secure flow-based model: the former decouples identity information from non-identifying attributes, while the latter transforms the decoupled identity into an anonymized version in an invertible manner controlled by a secret key. The anonymized face can then be reconstructed based on a pre-trained StyleGAN that ensures high image quality and realistic facial details. Recovery of the original face (aka de-anonymization) is possible upon the availability of the matching secret, by inverting the anonymization process based on the same set of model parameters. Furthermore, a dedicated secret-key mechanism along with a dual-phase training strategy is devised to ensure the desired properties of face anonymization. Qualitative and quantitative experiments demonstrate the superiority of the proposed approach in anonymity, reversibility, security, diversity, and interpretability over competing methods.

人脸匿名可逆生成隐私保护风格迁移

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。