arXiv:2604.23688cs.CV2026-04

实测发现,人脸保护扰动在常见图像处理后失效,易被低成本清除。

Do Protective Perturbations Really Protect Portrait Privacy under Real-world Image Transformations?

论文配图:Do Protective Perturbations Really Protect Portrait Privacy under Real-world Image Transformations?
图 1 · 摘自论文原文
  • 用序列化图像操作测试防护扰动的鲁棒性
  • 多数防护方法在压缩/缩放后失效,隐私泄露风险高
  • 提出新框架可低成本还原真实人脸,适合安全评估

主动防御方法通过引入像素级保护扰动来防止人脸未经授权的编辑或说话脸生成(TFG),近年来受到广泛关注。然而在真实场景中,图像在显示和传播过程中不可避免地会经历一系列良性操作,如缩放和色彩压缩,这些操作直接改变像素值。现有研究与鲁棒性防御多孤立分析单一变换,而对序列组合变换的探索仍不足。为此,我们系统评估了基于GAN与扩散模型的代表性主动防御方法,在应对未经授权图像编辑及说话脸生成时,是否能在连续图像变换下保持有效性。涵盖通用与专用于人脸的防御方法,并进行定性与定量分析。实验结果表明,基于像素扰动的防御难以抵御常见的连续图像变换,存在实际应用中的失效风险。为进一步证明该漏洞可被低成本利用,我们提出无需训练的TIP-RSR框架,结合序列变换与现成修复模型,实现高效净化保护扰动,同时保持图像保真度,计算开销远低于扩散模型修复方法。研究揭示当前主动人脸防御的实际脆弱性,强调未来设计需考虑真实世界序列变换的影响。代码已公开于https://github.com/Richen7418/TIP-RSR。

原文摘要 · Abstract (English)

Proactive defense methods protect portrait images from unauthorized editing or talking face generation (TFG) by introducing pixel-level protective perturbations, and have attracted increasing attention for privacy protection. In real-world use, images inevitably undergo sequences of benign operations during display and dissemination, such as resizing and color compression, which directly alter pixel values. Existing studies and robustness defenses mainly examine individual transformations in isolation, while sequentially composed transformations remain underexplored. To address this gap, we systematically evaluate whether representative proactive defenses against unauthorized image editing using GANs and diffusion models, as well as talking face generation, remain effective under sequential image transformations. The evaluated methods span general-purpose and portrait-specific defenses and are assessed qualitatively and quantitatively. Experimental results show that pixel-level perturbation-based defenses struggle to withstand sequences of common image transformations, posing a risk of failure in real-world applications. To further demonstrate that this vulnerability can be exploited at low cost, we introduce Transformation-Induced Purification via Region-wise Super-Resolution (TIP-RSR), a simple training-free framework combining sequential image transformations with off-the-shelf restoration models. TIP-RSR efficiently purifies protective perturbations while preserving image fidelity and requiring substantially less computation than diffusion-based purification methods. These findings expose a practical vulnerability in current proactive portrait defenses and highlight the need to account for sequential real-world transformations when designing future protection mechanisms. Our code is publicly available at https://github.com/Richen7418/TIP-RSR.

隐私保护图像防御扰动净化人脸安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。