用扩散模型生成逼真又可迁移的对抗人脸,保护隐私
Diffusion-based Adversarial Identity Manipulation for Facial Privacy Protection
- 在扩散模型低维隐空间迭代注入对抗引导,操控人脸身份
- 黑盒攻击迁移率更强,视觉自然度优于现有方法
- 适合需隐私保护的社交平台和商业人脸识别系统
面部识别(FR)系统的成功引发了未经授权监控和用户追踪的严重隐私问题。现有隐私增强方法难以生成既自然又能有效防护的面部图像。本文提出基于扩散模型的对抗身份操纵方法(DiffAIM),生成自然且高度可迁移的对抗性人脸以抵御恶意FR系统。具体而言,在扩散模型的低维隐空间中操纵面部身份,通过在反向扩散过程中迭代注入基于梯度的对抗身份引导,逐步引导生成目标对抗人脸。该引导优化了身份向目标收敛的同时促进语义上与源图像发散,实现有效伪装并保持视觉自然性。进一步引入结构保持正则化,确保操纵过程中的面部结构一致性。在人脸验证与识别任务上的大量实验表明,相比当前最优方法,DiffAIM在保持更优视觉质量的同时实现了更强的黑盒攻击迁移能力。此外,我们还验证了该方法在商业FR API(如Face++和Aliyun)上的有效性。
原文摘要 · Abstract (English)
The success of face recognition (FR) systems has led to serious privacy concerns due to potential unauthorized surveillance and user tracking on social networks. Existing methods for enhancing privacy fail to generate natural face images that can protect facial privacy. In this paper, we propose diffusion-based adversarial identity manipulation (DiffAIM) to generate natural and highly transferable adversarial faces against malicious FR systems. To be specific, we manipulate facial identity within the low-dimensional latent space of a diffusion model. This involves iteratively injecting gradient-based adversarial identity guidance during the reverse diffusion process, progressively steering the generation toward the desired adversarial faces. The guidance is optimized for identity convergence towards a target while promoting semantic divergence from the source, facilitating effective impersonation while maintaining visual naturalness. We further incorporate structure-preserving regularization to preserve facial structure consistency during manipulation. Extensive experiments on both face verification and identification tasks demonstrate that compared with the state-of-the-art, DiffAIM achieves stronger black-box attack transferability while maintaining superior visual quality. We also demonstrate the effectiveness of the proposed approach for commercial FR APIs, including Face++ and Aliyun.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。