arXiv:2602.04994cs.CVcs.LG2026-02被引 2

让人脸图像在保护隐私的同时仍可被机器识别,实现视觉匿名化。

SIDeR: Semantic Identity Decoupling for Unrestricted Face Privacy

  • 将人脸分解为身份特征与外观语义,用扩散模型重构匿名脸
  • 黑盒攻击成功率99%,重建质量比基线高41.28% PSNR
  • 支持授权恢复原图,适合金融等高安全场景

随着人脸识别广泛应用于在线银行、身份验证等网络服务,如何在图像存储与传输中有效剥离视觉表征中的身份信息,成为隐私保护的关键挑战。为此,我们提出SIDeR——一种面向无限制人脸隐私保护的语义解耦框架。SIDeR将人脸图像分解为机器可识别的身份特征向量与视觉可感知的语义外观成分。通过利用扩散模型潜在空间中的语义引导重组,生成视觉匿名的对抗性人脸,同时保持机器层面的身份一致性。该框架引入动量驱动的无限制扰动优化与语义-视觉平衡因子,合成多个视觉多样且高度自然的对抗样本。此外,授权用户在提供正确密码时可恢复原始图像。在CelebA-HQ与FFHQ数据集上的大量实验表明,SIDeR在黑盒场景下实现99%攻击成功率,且在基于PSNR的重建质量上优于基线方法41.28%。

原文摘要 · Abstract (English)

With the deep integration of facial recognition into online banking, identity verification, and other networked services, achieving effective decoupling of identity information from visual representations during image storage and transmission has become a critical challenge for privacy protection. To address this issue, we propose SIDeR, a Semantic decoupling-driven framework for unrestricted face privacy protection. SIDeR decomposes a facial image into a machine-recognizable identity feature vector and a visually perceptible semantic appearance component. By leveraging semantic-guided recomposition in the latent space of a diffusion model, it generates visually anonymous adversarial faces while maintaining machine-level identity consistency. The framework incorporates momentum-driven unrestricted perturbation optimization and a semantic-visual balancing factor to synthesize multiple visually diverse, highly natural adversarial samples. Furthermore, for authorized access, the protected image can be restored to its original form when the correct password is provided. Extensive experiments on the CelebA-HQ and FFHQ datasets demonstrate that SIDeR achieves a 99% attack success rate in black-box scenarios and outperforms baseline methods by 41.28% in PSNR-based restoration quality.

隐私保护人脸匿名扩散模型身份解耦

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。