arXiv:2601.22744cs.CVcs.CR2026-01被引 1

用方向性属性编辑实现隐蔽对抗扰动,防御扩散模型人脸替换

Beauty and the Beast: Imperceptible Perturbations Against Diffusion-Based Face Swapping via Directional Attribute Editing

  • 通过定向人脸属性编辑修复扰动带来的失真
  • 在保持视觉不可察觉的同时显著提升防御效果
  • 适合关注隐私保护与恶意换脸防御的研究者

基于扩散模型的人脸替换已达到顶尖性能,但也加剧了恶意换脸对肖像权或个人声誉的潜在危害。这推动了主动防御方法的发展。然而,现有方法面临核心矛盾:大扰动会扭曲面部结构,小扰动则削弱防护效果。为此,我们提出FaceDefense,一种增强的主动防御框架。该方法引入新型扩散损失以强化对抗样本的防御能力,并采用定向人脸属性编辑恢复扰动引起的失真,从而提升视觉不可察觉性。设计了两阶段交替优化策略生成最终的扰动人脸图像。大量实验表明,FaceDefense在不可察觉性和防御有效性方面均显著优于现有方法,实现了更优的平衡。

原文摘要 · Abstract (English)

Diffusion-based face swapping achieves state-of-the-art performance, yet it also exacerbates the potential harm of malicious face swapping to violate portraiture right or undermine personal reputation. This has spurred the development of proactive defense methods. However, existing approaches face a core trade-off: large perturbations distort facial structures, while small ones weaken protection effectiveness. To address these issues, we propose FaceDefense, an enhanced proactive defense framework against diffusion-based face swapping. Our method introduces a new diffusion loss to strengthen the defensive efficacy of adversarial examples, and employs a directional facial attribute editing to restore perturbation-induced distortions, thereby enhancing visual imperceptibility. A two-phase alternating optimization strategy is designed to generate final perturbed face images. Extensive experiments show that FaceDefense significantly outperforms existing methods in both imperceptibility and defense effectiveness, achieving a superior trade-off.

人脸替换扩散模型对抗防御隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。