用扩散模型生成防识别人脸,提升隐私保护成功率。
Enhancing Facial Privacy Protection via Weakening Diffusion Purification
- 学习无条件嵌入增强对抗修改能力,削弱扩散净化效应。
- 在CelebA-HQ和LADN数据集上,保护成功率显著提升。
- 保留身份特征,人眼可辨认但系统难识别,适合实用部署。
社交媒体中个人肖像图像的广泛传播带来了严重的隐私风险,因自动人脸识别(AFR)系统具备大规模监控能力。为应对这一问题,现有方法利用扩散模型生成对抗性人脸图像以保护隐私,但受限于扩散净化效应,保护成功率较低。本文首次提出学习无条件嵌入,提升对抗修改的学习能力,并以此引导对抗潜在码的修改,从而削弱扩散净化效应。同时引入身份保持结构,确保生成图像与原图在结构上保持一致,使人类观察者仍能识别其身份。在两个公开数据集CelebA-HQ和LADN上的大量实验表明,本方法生成的受保护人脸在可迁移性和自然外观方面均优于现有方法。
原文摘要 · Abstract (English)
The rapid growth of social media has led to the widespread sharing of individual portrait images, which pose serious privacy risks due to the capabilities of automatic face recognition (AFR) systems for mass surveillance. Hence, protecting facial privacy against unauthorized AFR systems is essential. Inspired by the generation capability of the emerging diffusion models, recent methods employ diffusion models to generate adversarial face images for privacy protection. However, they suffer from the diffusion purification effect, leading to a low protection success rate (PSR). In this paper, we first propose learning unconditional embeddings to increase the learning capacity for adversarial modifications and then use them to guide the modification of the adversarial latent code to weaken the diffusion purification effect. Moreover, we integrate an identity-preserving structure to maintain structural consistency between the original and generated images, allowing human observers to recognize the generated image as having the same identity as the original. Extensive experiments conducted on two public datasets, i.e., CelebA-HQ and LADN, demonstrate the superiority of our approach. The protected faces generated by our method outperform those produced by existing facial privacy protection approaches in terms of transferability and natural appearance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。