arXiv:2503.09306cs.CV2025-03被引 1

用40维特征向量竟能还原人脸图像,揭示了模型隐藏信息泄露风险。

Revealing Unintentional Information Leakage in Low-Dimensional Facial Portrait Representations

  • 通过黑盒访问编码器,用预训练StyleGAN重建人脸
  • 32或40维特征向量可高精度还原原始人脸图像
  • 适合关注隐私安全与模型可解释性的研究人员

我们评估神经网络低维输出中无意泄露的信息,通过从一个仅描述面部肖像抽象属性的40或32维特征向量中重构输入图像。该重构过程仅需黑盒访问生成该特征向量的图像编码器。与以往工作不同,我们利用最新的图像生成和面部相似性知识,提出一种优于当前最先进水平的方法。该方法结合预训练StyleGAN与新型损失函数,通过将肖像映射到FaceNet嵌入的潜在空间来比较感知相似性。此外,我们还提出一种新技巧,通过集成多个输出来刻意生成重建图像的特定方面。

原文摘要 · Abstract (English)

We evaluate the information that can unintentionally leak into the low dimensional output of a neural network, by reconstructing an input image from a 40- or 32-element feature vector that intends to only describe abstract attributes of a facial portrait. The reconstruction uses blackbox-access to the image encoder which generates the feature vector. Other than previous work, we leverage recent knowledge about image generation and facial similarity, implementing a method that outperforms the current state-of-the-art. Our strategy uses a pretrained StyleGAN and a new loss function that compares the perceptual similarity of portraits by mapping them into the latent space of a FaceNet embedding. Additionally, we present a new technique that fuses the output of an ensemble, to deliberately generate specific aspects of the recreated image.

人脸识别信息泄露生成模型隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。