用对抗扰动保护3D虚拟人脸隐私,不改变外观却让身份无法识别。
AEGIS: Preserving privacy of 3D Facial Avatars with Adversarial Perturbations
- 在3D高斯点云颜色系数上加对抗扰动,保护身份。
- 多视角下身份识别率降为0%,视觉质量仍很高(SSIM=0.9555)。
- 适合需要保护虚拟形象隐私的元宇宙、视频会议等场景。
随着高效3D高斯溅射表示的逼真3D人脸虚拟形象广泛应用,线上身份盗用风险加剧,尤其在依赖生物特征认证的系统中。尽管2D图像的对抗遮蔽方法已成熟,但动态3D虚拟形象的鲁棒且视角一致的身份保护仍存在显著空白。为此,我们提出AEGIS,首个针对3D高斯虚拟形象的隐私保护遮蔽框架,可在不改变几何结构的前提下,保持主体感知特征。该方法通过预训练的人脸验证网络指导对高斯颜色系数施加对抗扰动,实现跨多视角的一致保护,无需重新训练。AEGIS实现完全去标识化,使人脸检索与验证准确率降至0%,同时保持高感知质量(SSIM = 0.9555,PSNR = 35.52 dB),并有效保留年龄、种族、性别和情绪等关键面部属性,展现强隐私保护能力且视觉失真极小。
原文摘要 · Abstract (English)
The growing adoption of photorealistic 3D facial avatars, particularly those utilizing efficient 3D Gaussian Splatting representations, introduces new risks of online identity theft, especially in systems that rely on biometric authentication. While effective adversarial masking methods have been developed for 2D images, a significant gap remains in achieving robust, viewpoint-consistent identity protection for dynamic 3D avatars. To address this, we present AEGIS, the first privacy-preserving identity masking framework for 3D Gaussian Avatars that maintains the subject's perceived characteristics. Our method aims to conceal identity-related facial features while preserving the avatar's perceptual realism and functional integrity. AEGIS applies adversarial perturbations to the Gaussian color coefficients, guided by a pre-trained face verification network, ensuring consistent protection across multiple viewpoints without retraining or modifying the avatar's geometry. AEGIS achieves complete de-identification, reducing face retrieval and verification accuracy to 0%, while maintaining high perceptual quality (SSIM = 0.9555, PSNR = 35.52 dB). It also preserves key facial attributes such as age, race, gender, and emotion, demonstrating strong privacy protection with minimal visual distortion.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。