通过破坏图像美学特征,隐蔽人脸身份以防范定制化生成模型滥用。
Anti-Aesthetics: Protecting Facial Privacy against Customized Text-to-Image Synthesis
- 构建分层反美学框架,从全局与局部两方面干扰生成质量。
- 在多个数据集上实现显著的人脸身份消除效果,优于现有最优方法。
- 适合关注隐私保护与生成内容安全的开发者及研究人员使用。
定制化扩散模型的兴起推动了个性化视觉内容创作的发展,但也带来了恶意滥用的风险,严重威胁个人隐私与版权保护。已有研究指出图像美学特性与人类对图像质量的感知高度正相关。受此启发,本文提出一种新颖的分层反美学(HAA)框架,通过降低生成内容的整体与局部美学质量,从而有效隐藏人脸身份。该框架包含两个关键分支:1)全局反美学机制,通过全局反美学奖励和损失函数,降低整体生成图像的美学水平;2)局部反美学机制,设计局部反美学奖励与损失,引导对抗扰动破坏人脸局部特征。两者协同工作,实现了从全局到局部的反美学干扰。大量实验表明,HAA在人脸身份移除任务中显著优于现有最先进方法,为面部隐私与版权保护提供了有力工具。
原文摘要 · Abstract (English)
The rise of customized diffusion models has spurred a boom in personalized visual content creation, but also poses risks of malicious misuse, severely threatening personal privacy and copyright protection. Some studies show that the aesthetic properties of images are highly positively correlated with human perception of image quality. Inspired by this, we approach the problem from a novel and intriguing aesthetic perspective to degrade the generation quality of maliciously customized models, thereby achieving better protection of facial identity. Specifically, we propose a Hierarchical Anti-Aesthetic (HAA) framework to fully explore aesthetic cues, which consists of two key branches: 1) Global Anti-Aesthetics: By establishing a global anti-aesthetic reward mechanism and a global anti-aesthetic loss, it can degrade the overall aesthetics of the generated content; 2) Local Anti-Aesthetics: A local anti-aesthetic reward mechanism and a local anti-aesthetic loss are designed to guide adversarial perturbations to disrupt local facial identity. By seamlessly integrating both branches, our HAA effectively achieves the goal of anti-aesthetics from a global to a local level during customized generation. Extensive experiments show that HAA outperforms existing SOTA methods largely in identity removal, providing a powerful tool for protecting facial privacy and copyright.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。