用生成模型逆推高斯模糊人脸,实现高精度复原与身份识别
Restoring Gaussian Blurred Face Images for Deanonymization Attacks
- 基于条件扩散模型与身份检索,实现保身份的去模糊重建
- 在强模糊下仍可达到95.9%重识别准确率,显著优于现有方法
- 揭示高斯模糊不适用于隐私保护,适合安全与隐私研究者参考
高斯模糊常被用于在互联网发布前对敏感照片中的人脸进行匿名化处理。然而,模糊后的人脸在高模糊程度下是否仍可有效复原并用于身份识别尚不明确。本文提出名为Revelio的去模糊方法,利用生成模型的记忆效应,近似高斯模糊的逆函数以恢复人脸。该方法设计为保身份的去模糊流程:先使用条件扩散模型进行初步修复,再通过身份检索模型查找相关图像以提升细节真实性。在多个大型公开人脸数据集上评估显示,Revelio在高模糊条件下仍能有效复原人脸,重识别准确率达95.9%,显著优于现有方案。结果表明,高斯模糊不应作为人脸匿名化的可靠手段。同时,该方法对模糊核大小不匹配具有鲁棒性,并测试了初步反制措施与自适应攻击,为后续研究提供方向。
原文摘要 · Abstract (English)
Gaussian blur is widely used to blur human faces in sensitive photos before the photos are posted on the Internet. However, it is unclear to what extent the blurred faces can be restored and used to re-identify the person, especially under a high-blurring setting. In this paper, we explore this question by developing a deblurring method called Revelio. The key intuition is to leverage a generative model's memorization effect and approximate the inverse function of Gaussian blur for face restoration. Compared with existing methods, we design the deblurring process to be identity-preserving. It uses a conditional Diffusion model for preliminary face restoration and then uses an identity retrieval model to retrieve related images to further enhance fidelity. We evaluate Revelio with large public face image datasets and show that it can effectively restore blurred faces, especially under a high-blurring setting. It has a re-identification accuracy of 95.9%, outperforming existing solutions. The result suggests that Gaussian blur should not be used for face anonymization purposes. We also demonstrate the robustness of this method against mismatched Gaussian kernel sizes and functions, and test preliminary countermeasures and adaptive attacks to inspire future work.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。