研究生成多少个可区分的假身份仍能通过人脸验证阈值测试。
On the Capacity of Distinguishable Synthetic Identity Generation under Face Verification
- 基于生成器与归一化特征映射,建模可区分身份生成上限。
- 在全角度表达假设下,容量由球码问题决定,随维度增长呈指数上升。
- 适用于研究对抗攻击、隐私保护中的身份混淆问题。
我们研究在固定阈值τ下,能生成多少个合成身份,使得人脸验证器对同身份对判定为匹配,异身份对判定为非匹配。针对包含生成器与单位超球面输出的归一化识别映射的生成式人脸识别流程,定义了可区分身份生成容量——即满足指定同身份与异身份验证约束的潜在身份数最大值。在确定性视角下,该容量由可实现嵌入集上的球码问题刻画,全角表达假设下退化为经典球码量。对于随机身份生成,引入中心化模型,推导出充分可容许条件:身份中心间分离角需大于arccos(τ)+2ρ,其中ρ为身份内集中半径。在全角表达假设下,得到基于球码的可达下界及嵌入维度增长的正渐近下界。此外,提出先验约束随机码容量,以成对中心分离失败概率为指标,推导高概率下界;在更强的全支撑能力模型下,获得上界与精确球码表征。
原文摘要 · Abstract (English)
We study how many synthetic identities can be generated so that a face verifier declares same-identity pairs as matches and different-identity pairs as non-matches at a fixed threshold $τ$. We formalize this question for a generative face-recognition pipeline consisting of a generator followed by a normalized recognition map with outputs on the unit hypersphere. We define the capacity of distinguishable identity generation as the largest number of latent identities whose induced embedding distributions satisfy prescribed same-identity and different-identity verification constraints. In the deterministic view-invariant regime, we show that this capacity is characterized by a spherical-code problem over the realizable set of embeddings, and reduces to the classical spherical-code quantity under a full angular expressivity assumption. For stochastic identity generation, we introduce a centered model and derive a sufficient admissibility condition in which the required separation between identity centers is $\arccos(τ)+2ρ$, where $ρ$ is a within-identity concentration radius. Under full angular expressivity, this yields spherical-code-based achievable lower bounds and a positive asymptotic lower bound on the exponential growth rate with embedding dimension. We also introduce a prior-constrained random-code capacity, in which latent identities are sampled independently from a given prior, and derive high-probability lower bounds in terms of pairwise separation-failure probabilities of the induced identity centers. Under a stronger full-cap-support model, we obtain a converse and an exact spherical-code characterization.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。