arXiv:2603.21867cs.CVcs.AI2026-03

用简单图案干扰人脸识别,保护现实世界隐私

Adversarial Camouflage

  • 设计低维颜色形状参数空间,生成可投影的伪装图案
  • 在多模型上使识别准确率下降超70%,跨模型攻击有效
  • 适合关注隐私的普通用户,实测效果优于多数现有方法

尽管人脸识别算法迅速发展,带来了诸多便利应用,但其大规模部署也引发了对集体监控和个体隐私泄露的担忧。本文提出一种名为「对抗伪装」的新方法,旨在保护用户隐私。该方法通过定义由颜色、形状和角度参数化的低维模式空间,优化出的图案被投影到语义有效的面部区域进行评估。所提方法最大化多个模型的识别误差,确保对抗样本具有强跨模型迁移能力,即使面对黑盒系统也有效。模拟实验中显著降低所有测试的先进人脸识别模型性能;真实人类实验中表现出良好效果,并揭示了不同模型间鲁棒性差异及攻击迁移现象。

原文摘要 · Abstract (English)

While the rapid development of facial recognition algorithms has enabled numerous beneficial applications, their widespread deployment has raised significant concerns about the risks of mass surveillance and threats to individual privacy. In this paper, we introduce \textit{Adversarial Camouflage} as a novel solution for protecting users' privacy. This approach is designed to be efficient and simple to reproduce for users in the physical world. The algorithm starts by defining a low-dimensional pattern space parameterized by color, shape, and angle. Optimized patterns, once found, are projected onto semantically valid facial regions for evaluation. Our method maximizes recognition error across multiple architectures, ensuring high cross-model transferability even against black-box systems. It significantly degrades the performance of all tested state-of-the-art face recognition models during simulations and demonstrates promising results in real-world human experiments, while revealing differences in model robustness and evidence of attack transferability across architectures.

隐私保护对抗攻击人脸识别

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。