arXiv:2506.09777cs.CVcs.AI2025-06被引 1

仅用相似度分数就能逆推人脸图像,突破黑箱识别系统隐私防线。

Inverting Black-Box Face Recognition Systems via Zero-Order Optimization in Eigenface Space

  • 在主成分分析的特征空间中进行零阶优化,无需嵌入向量
  • 在LFW、AgeDB-30等数据集上实现顶尖的识别准确率
  • 适用于研究模型隐私漏洞或对抗攻击的学者

从黑箱人脸识别模型中重构面部图像构成重大隐私威胁。尽管许多方法依赖于嵌入向量,本文针对更困难的仅使用相似度分数的场景提出DarkerBB。该方法在由PCA生成的特征空间中执行零阶优化,重建彩色人脸图像。即使信息极度受限,实验表明DarkerBB在LFW、AgeDB-30和CFP-FP基准测试中均达到相似度仅设置下的最先进验证准确率,并具备良好的查询效率。

原文摘要 · Abstract (English)

Reconstructing facial images from black-box recognition models poses a significant privacy threat. While many methods require access to embeddings, we address the more challenging scenario of model inversion using only similarity scores. This paper introduces DarkerBB, a novel approach that reconstructs color faces by performing zero-order optimization within a PCA-derived eigenface space. Despite this highly limited information, experiments on LFW, AgeDB-30, and CFP-FP benchmarks demonstrate that DarkerBB achieves state-of-the-art verification accuracies in the similarity-only setting, with competitive query efficiency.

隐私安全模型逆向黑箱攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。