arXiv:2602.13168cs.CVcs.LG2026-02AAAI

用扩散模型从人脸嵌入重建真实高分辨率图像,验证隐私泄露风险

Realistic Face Reconstruction from Facial Embeddings via Diffusion Models

  • 基于预训练扩散模型与KAN网络,实现嵌入到人脸的映射攻击
  • 重建图像可成功通过真实人脸识别系统验证,且对部分/保护嵌入仍有效
  • 可用于评估人脸识别系统的隐私安全性,适合安全研究者使用

随着人脸识别(FR)系统的发展,隐私保护型人脸识别(PPFR)系统因其高精度、增强隐私保护及抗多种攻击的能力而受到关注。然而,针对这些系统从嵌入向量中重建真实高分辨率人脸图像的研究仍有限,尤其是对PPFR系统的隐私风险验证。本文提出人脸嵌入映射(FEM)框架,利用预训练的身份保持扩散模型与柯尔莫哥洛夫-阿诺德网络(KAN),对当前最先进(SOTA)的FR与PPFR系统实施嵌入到人脸的攻击。大量实验表明,重建的人脸可成功用于访问真实世界的人脸识别系统;此外,该方法在部分或受保护嵌入下仍具鲁棒性。同时,FEM可作为评估FR与PPFR系统隐私泄露风险的安全工具。本研究所用图像均来自公开数据集。

原文摘要 · Abstract (English)

With the advancement of face recognition (FR) systems, privacy-preserving face recognition (PPFR) systems have gained popularity for their accurate recognition, enhanced facial privacy protection, and robustness to various attacks. However, there are limited studies to further verify privacy risks by reconstructing realistic high-resolution face images from embeddings of these systems, especially for PPFR. In this work, we propose the face embedding mapping (FEM), a general framework that explores Kolmogorov-Arnold Network (KAN) for conducting the embedding-to-face attack by leveraging pre-trained Identity-Preserving diffusion model against state-of-the-art (SOTA) FR and PPFR systems. Based on extensive experiments, we verify that reconstructed faces can be used for accessing other real-word FR systems. Besides, the proposed method shows the robustness in reconstructing faces from the partial and protected face embeddings. Moreover, FEM can be utilized as a tool for evaluating safety of FR and PPFR systems in terms of privacy leakage. All images used in this work are from public datasets.

人脸重建扩散模型隐私安全嵌入攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。