arXiv:2503.08731cs.CVcs.LG2025-03被引 1

首个系统评估人脸模糊方法公平性与抗攻击能力的框架。

FairDeFace: Evaluating the Fairness and Adversarial Robustness of Face Obfuscation Methods

  • 构建多模块评估框架,统一测试标准。
  • 7种方法在500+实验中表现不一,部分对特定群体效果差。
  • 可视化分析揭示模糊与攻击焦点差异,定位缺陷原因。

缺乏统一的平台和基准数据集,导致人脸模糊方法的评估依赖于任意实验、数据集和指标。尽管已有研究显示人脸识别系统对某些人口群体存在偏见,但关于人脸模糊方法公平性的理解仍严重不足。提供公平的人脸模糊方法可确保不同群体获得平等隐私保护,尤其对弱势群体至关重要。为此,本文提出综合性框架FairDeFace,用于评估人脸模糊方法的对抗鲁棒性和公平性。该框架包含数据基准、人脸检测与识别算法、对抗模型、效用检测模型及公平性度量等模块。用户可将任意模糊方法接入平台,进行严格测试与对比。当前实现包含6种攻击方式及多项隐私、效用与公平性指标。通过超过500次实验,我们评估并比较了7种主流人脸模糊方法的对抗鲁棒性,发现现有方法在鲁棒性及对性别或种族群体的偏见方面存在显著差异。FairDeFace还通过可视化模糊区域与验证攻击聚焦区,揭示不同群体在模糊过程中被修改的重点区域及其失败原因。

原文摘要 · Abstract (English)

The lack of a common platform and benchmark datasets for evaluating face obfuscation methods has been a challenge, with every method being tested using arbitrary experiments, datasets, and metrics. While prior work has demonstrated that face recognition systems exhibit bias against some demographic groups, there exists a substantial gap in our understanding regarding the fairness of face obfuscation methods. Providing fair face obfuscation methods can ensure equitable protection across diverse demographic groups, especially since they can be used to preserve the privacy of vulnerable populations. To address these gaps, this paper introduces a comprehensive framework, named FairDeFace, designed to assess the adversarial robustness and fairness of face obfuscation methods. The framework introduces a set of modules encompassing data benchmarks, face detection and recognition algorithms, adversarial models, utility detection models, and fairness metrics. FairDeFace serves as a versatile platform where any face obfuscation method can be integrated, allowing for rigorous testing and comparison with other state-of-the-art methods. In its current implementation, FairDeFace incorporates 6 attacks, and several privacy, utility and fairness metrics. Using FairDeFace, and by conducting more than 500 experiments, we evaluated and compared the adversarial robustness of seven face obfuscation methods. This extensive analysis led to many interesting findings both in terms of the degree of robustness of existing methods and their biases against some gender or racial groups. FairDeFace also uses visualization of focused areas for both obfuscation and verification attacks to show not only which areas are mostly changed in the obfuscation process for some demographics, but also why they failed through focus area comparison of obfuscation and verification.

人脸隐私公平性评估对抗鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。