arXiv:2503.08269cs.CVcs.AI2025-03CVPR被引 35

用对抗攻击保护生成肖像的隐私,防止被人脸识别系统追踪。

Adv-CPG: A Customized Portrait Generation Framework with Facial Adversarial Attacks

  • 通过双层加密机制,注入目标身份并增强隐私保护。
  • 攻击成功率比现有方法高2.86%以上,有效干扰人脸识别。
  • 适合关注数字肖像隐私与安全生成的开发者与研究者。

近期的定制化肖像生成(CPG)方法虽能生成高保真肖像,但难以防止其被恶意人脸识别系统追踪和滥用。为此,本文提出一种引入面部对抗攻击的定制化肖像生成框架(Adv-CPG)。为实现面部隐私保护,设计轻量级局部身份加密器与加密增强器,通过直接注入目标身份并添加额外身份引导,实现渐进式双层加密防护。同时,开发多模态图像定制器,以控制生成细粒度人脸特征。据我们所知,Adv-CPG是首个将面部对抗攻击引入CPG的研究。大量实验表明其优越性:相比最先进的基于噪声的攻击方法和无约束攻击方法,平均攻击成功率分别高出28.1%和2.86%。

原文摘要 · Abstract (English)

Recent Customized Portrait Generation (CPG) methods, taking a facial image and a textual prompt as inputs, have attracted substantial attention. Although these methods generate high-fidelity portraits, they fail to prevent the generated portraits from being tracked and misused by malicious face recognition systems. To address this, this paper proposes a Customized Portrait Generation framework with facial Adversarial attacks (Adv-CPG). Specifically, to achieve facial privacy protection, we devise a lightweight local ID encryptor and an encryption enhancer. They implement progressive double-layer encryption protection by directly injecting the target identity and adding additional identity guidance, respectively. Furthermore, to accomplish fine-grained and personalized portrait generation, we develop a multi-modal image customizer capable of generating controlled fine-grained facial features. To the best of our knowledge, Adv-CPG is the first study that introduces facial adversarial attacks into CPG. Extensive experiments demonstrate the superiority of Adv-CPG, e.g., the average attack success rate of the proposed Adv-CPG is 28.1% and 2.86% higher compared to the SOTA noise-based attack methods and unconstrained attack methods, respectively.

肖像生成隐私保护对抗攻击人脸识别

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。