arXiv:2604.21465cs.CV2026-04

通过扰动身份特征防止换脸,保护隐私同时保持图像自然

ID-Eraser: Proactive Defense Against Face Swapping via Identity Perturbation

论文配图:ID-Eraser: Proactive Defense Against Face Swapping via Identity Perturbation
图 1 · 摘自论文原文
  • 在特征空间注入可学习扰动,破坏身份信息
  • 黑盒测试下识别准确率低至0.30,换脸相似度平均降为0.504
  • 兼容多种模型与商业接口,效果稳定且视觉真实

深度伪造技术迅速发展,尤其是人脸换脸对隐私和数字安全构成严重威胁。现有主动防御多依赖像素级扰动,难以应对能提取鲁棒高层身份嵌入的现代换脸模型。本文提出ID-Eraser,一种基于特征空间的主动防御方法,通过在身份嵌入中注入可学习扰动,并利用人脸恢复生成器(FRG)重建自然外观的防护图像,使人类观看时仍具真实感,但对深度伪造模型无法识别身份。实验表明,在严格黑盒设置下,ID-Eraser显著扰乱各类人脸识别与换脸系统,实现最低的Top-1准确率(0.30),最佳FID(1.64)和LPIPS(0.020)。相较于原始输入生成的换脸,受保护换脸的身份相似度平均降至0.504。该方法还展现出强跨数据集泛化能力、对常见失真的鲁棒性,以及在商用API上的实际有效性,将腾讯API的身份相似度从0.76降至0.36。

原文摘要 · Abstract (English)

Deepfake technologies have rapidly advanced with modern generative AI, and face swapping in particular poses serious threats to privacy and digital security. Existing proactive defenses mostly rely on pixel-level perturbations, which are ineffective against contemporary swapping models that extract robust high-level identity embeddings. We propose ID-Eraser, a feature-space proactive defense that removes identifiable facial information to prevent malicious face swapping. By injecting learnable perturbations into identity embeddings and reconstructing natural-looking protection images through a Face Revive Generator (FRG), ID-Eraser produces visually realistic results for humans while rendering the protected identities unusable for Deepfake models. Experiments show that ID-Eraser substantially disrupts identity recognition across diverse face recognition and swapping systems under strict black-box settings, achieving the lowest Top-1 accuracy (0.30) with the best FID (1.64) and LPIPS (0.020). Compared with swaps generated from clean inputs, the identity similarity of protected swaps drops sharply to an average of 0.504 across five representative face swapping models. ID-Eraser further demonstrates strong cross-dataset generalization, robustness to common distortions, and practical effectiveness on commercial APIs, reducing Tencent API similarity from 0.76 to 0.36.

换脸防御身份保护生成对抗隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。