提出动态人脸识别策略,揭示现有反人脸识别方法失效原因并设计更优防护方案。
DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy
- 构建动态更新画廊的追踪模型DynTracker,模拟真实攻击者行为
- 实验显示现有反人脸识别方法在动态策略下全部失效
- 提出多样性增强的DivTrackee,提升防护图像的对抗鲁棒性
面部识别(FR)模型的广泛应用引发了对其滥用的担忧,推动了保护用户面部隐私的反面部识别(AFR)技术发展。本文指出,以往研究普遍采用静态FR策略评估AFR有效性,无法真实反映有目标追踪者的能力。为此,我们提出DynTracker——一种动态FR策略,通过迭代将新识别的目标图像加入画廊数据库。出乎意料的是,这种简单方法使所有现有AFR防护手段失效。为应对该威胁,我们主张在AFR保护图像中显式促进多样性,认为多样性不足是现有方法失败的根本原因。具体地,我们提出DivTrackee,基于文本引导生成框架与多样性增强对抗损失,生成具有高多样性的防护图像。在多个图像基准和特征提取器上的综合实验表明,DynTracker能有效突破现有AFR方法,而DivTrackee在抵御动态FR策略方面表现更优。我们认为本工作为应对有目标追踪者的隐私威胁提供了重要起点。
原文摘要 · Abstract (English)
The widespread adoption of facial recognition (FR) models raises serious concerns about their potential misuse, motivating the development of anti-facial recognition (AFR) to protect user facial privacy. In this paper, we argue that the static FR strategy, predominantly adopted in prior literature for evaluating AFR efficacy, cannot faithfully characterize the actual capabilities of determined trackers who aim to track a specific target identity. In particular, we introduce DynTracker, a dynamic FR strategy where the model's gallery database is iteratively updated with newly recognized target identity images. Surprisingly, such a simple approach renders all the existing AFR protections ineffective. To mitigate the privacy threats posed by DynTracker, we advocate for explicitly promoting diversity in the AFR-protected images. We hypothesize that the lack of diversity is the primary cause of the failure of existing AFR methods. Specifically, we develop DivTrackee, a novel method for crafting diverse AFR protections that builds upon a text-guided image generation framework and diversity-promoting adversarial losses. Through comprehensive experiments on various image benchmarks and feature extractors, we demonstrate DynTracker's strength in breaking existing AFR methods and the superiority of DivTrackee in preventing user facial images from being identified by dynamic FR strategies. We believe our work can act as an important initial step towards developing more effective AFR methods for protecting user facial privacy against determined trackers.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。