arXiv:2503.10549cs.CVcs.CR2025-03

用文字控制生成干扰妆容,隐蔽保护人脸隐私

Controllable Adversarial Makeup for Privacy via Text-Guided Diffusion

  • 基于扩散模型,根据文字提示生成局部对抗性妆容
  • 在多个平台测试中成功率显著高于现有方法
  • 适配多样化妆提示,保持自然视觉效果

随着人脸识别在政务和商业服务中的普及,其滥用可能严重威胁隐私与公民权利。为应对这一挑战,已有多种反人脸识别技术被提出,通过对抗性扰动人脸图像来保护隐私。其中,基于生成妆容的方法研究最广泛。然而,这些方法主要针对特定目标身份设计,导致避让成功率较低,并增加被针对性滥用的风险。此外,常引入全局视觉伪影或缺乏对多样化妆容提示的适应性,降低用户体验。为此,我们提出MASQUE——一种基于扩散模型的新型框架,可根据用户定义的文字提示生成局部对抗性妆容。该框架基于精确的无文本逆向、带掩码的定制交叉注意力融合,以及使用同一人图像对的成对对抗引导机制,实现无需外部身份信息的鲁棒避让性能。在开源人脸识别模型和商用API上的综合评估表明,MASQUE显著优于所有基线方法,在提升避让成功率的同时,保持更高感知保真度、更强的妆容提示适应性及对图像变换的鲁棒性。

原文摘要 · Abstract (English)

As face recognition becomes more widespread in government and commercial services, its potential misuse raises serious concerns about privacy and civil rights. To counteract this threat, various anti-facial recognition techniques have been proposed, which protect privacy by adversarially perturbing face images. Among these, generative makeup-based approaches are the most widely studied. However, these methods, designed primarily to impersonate specific target identities, can only achieve weak dodging success rates while increasing the risk of targeted abuse. In addition, they often introduce global visual artifacts or a lack of adaptability to accommodate diverse makeup prompts, compromising user satisfaction. To address the above limitations, we develop MASQUE, a novel diffusion-based framework that generates localized adversarial makeups guided by user-defined text prompts. Built upon precise null-text inversion, customized cross-attention fusion with masking, and a pairwise adversarial guidance mechanism using images of the same individual, MASQUE achieves robust dodging performance without requiring any external identity. Comprehensive evaluations on open-source facial recognition models and commercial APIs demonstrate that MASQUE significantly improves dodging success rates over all baselines, along with higher perceptual fidelity preservation, stronger adaptability to various makeup prompts, and robustness to image transformations.

隐私保护扩散模型对抗样本文本生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。