arXiv:2510.01031cs.CVcs.LG2025-10被引 1

用扩散模型实现可逆且安全的人脸匿名,仅授权者能还原身份。

Secure and reversible face anonymization with diffusion models

  • 通过密钥条件控制扩散过程,实现安全匿名与可控恢复。
  • 在CelebA-HQ和LFW上优于现有方法,支持精确身份重建。
  • 防止非法解匿名,适合需要隐私保护的实操场景。

人脸匿名旨在保留视觉真实性和下游任务可用性的同时,保护敏感身份信息。现有方法难以同时保证高图像质量、强安全性和可控可逆性。近期基于扩散模型的方法提升了匿名人脸的生成质量,但缺乏对解匿名权限的限制,影响实际应用。本文提出首个基于扩散模型的、通过密钥条件实现的安全可逆人脸匿名框架。该方法将密钥直接注入扩散过程,实现匿名化与授权方的身份重建,同时阻止未经授权的解匿名。确定性的前向与反向扩散步骤确保在正确密钥下可完全恢复原始身份。在CelebA-HQ和LFW数据集上的实验表明,本方法在匿名化与解匿名性能上均优于现有工作。此外,方法对错误或对抗性密钥具有鲁棒性。代码将公开。

原文摘要 · Abstract (English)

Face anonymization aims to protect sensitive identity information by altering faces while preserving visual realism and utility for downstream computer vision tasks. Current methods struggle to simultaneously ensure high image quality, strong security guarantees, and controlled reversibility for authorized identity recovery at a later time. To improve the image quality of generated anonymized faces, recent methods have adopted diffusion models. However, these new diffusion-based anonymization methods do not provide a mechanism to restrict de-anonymization to trusted parties, limiting their real-world applicability. In this paper, we present the first diffusion-based framework for secure, reversible face anonymization via secret-key conditioning. Our method injects the secret key directly into the diffusion process, enabling anonymization and authorized face reconstruction while preventing unauthorized de-anonymization. The use of deterministic forward and reverse diffusion steps guarantees exact identity recovery when the correct secret key is available. Experiments on CelebA-HQ and LFW demonstrate that our approach achieves better anonymization and de-anonymization capabilities than prior work. We also show that our method remains robust to incorrect or adversarial key de-anonymization. Our code will be made publicly available.

人脸匿名扩散模型可逆隐私密钥保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。