用情绪变化伪装人脸,保护隐私还更自然
Machine Pareidolia: Protecting Facial Image with Emotional Editing
- 通过调整表情让人脸识别系统误认身份
- 在多种肤色和场景下都有效,比噪声/化妆更可靠
- 适合关注隐私又不想失真的普通用户
面部识别系统的普及引发了数字隐私担忧,恶意使用带来严重威胁。传统防护手段如妆容迁移在黑盒环境下迁移性差,且对男性及深肤色人群适用性有限。为此,我们提出新型隐私保护方法MAP,通过人类情绪变化修改人脸,使原始身份被伪装成目标身份。该方法微调评分网络,联合优化目标身份与情绪表达两个目标,利用梯度投影确保收敛至共享局部最优解。同时,通过局部平滑正则化与分数匹配损失优化,提升保护图像的感知质量。实验表明,MAP在定性保真度与定量指标上均优于噪声、妆容及自由属性等基线方法。此外,MAP对在线面部识别API有效,且在罕见拍摄场景中表现出更强适应性。
原文摘要 · Abstract (English)
The proliferation of facial recognition (FR) systems has raised privacy concerns in the digital realm, as malicious uses of FR models pose a significant threat. Traditional countermeasures, such as makeup style transfer, have suffered from low transferability in black-box settings and limited applicability across various demographic groups, including males and individuals with darker skin tones. To address these challenges, we introduce a novel facial privacy protection method, dubbed \textbf{MAP}, a pioneering approach that employs human emotion modifications to disguise original identities as target identities in facial images. Our method uniquely fine-tunes a score network to learn dual objectives, target identity and human expression, which are jointly optimized through gradient projection to ensure convergence at a shared local optimum. Additionally, we enhance the perceptual quality of protected images by applying local smoothness regularization and optimizing the score matching loss within our network. Empirical experiments demonstrate that our innovative approach surpasses previous baselines, including noise-based, makeup-based, and freeform attribute methods, in both qualitative fidelity and quantitative metrics. Furthermore, MAP proves its effectiveness against an online FR API and shows advanced adaptability in uncommon photographic scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。