提出可逆隐私保护机制,防止人脸信息被恶意恢复
Asymmetric Invertible Threat: Learning Reversible Privacy Defense for Face Recognition

- 用密钥绑定保护变换,确保只有授权者能还原
- 训练时引入模拟反向修复攻击,提升抗破解能力
- 支持密钥验证与篡改提示,适合高隐私需求场景
人脸识别系统广泛应用,但存在未经授权采集和滥用面部数据的隐私风险。现有对抗性隐私保护方法依赖输入空间扰动混淆身份信息,但面对攻击者学习到的还原或净化映射时,保护效果会下降。本文将此问题视为非对称对抗攻击,因现有防御未控制可逆性而使逆向操作成为可能。为此提出不对称可逆人脸保护(ARFP),在统一框架中集成隐私保护、密钥恢复与篡改指示。ARFP包含三个组件:密钥条件流形绑定,将保护变换与用户密钥关联;对抗性还原感知训练,在训练中引入代理还原对手以增强对评估逆向净化攻击的鲁棒性;授权可逆还原,支持正确密钥下的恢复并提供基于随机数的篡改指示。在本文考虑的威胁模型下,大量实验表明ARFP在保持授权恢复可用性的同时,显著提升了对还原攻击的抵抗力,实证了密钥敏感恢复行为与篡改感知能力。
原文摘要 · Abstract (English)
Face Recognition systems are widely deployed in real-world applications, but they also raise privacy concerns due to unauthorized collection and misuse of facial data. Existing adversarial privacy protection methods rely on input-space perturbations to obfuscate identity information, yet their protection can degrade when adversaries learn restoration or purification mappings that partially invert the transformation. We study this setting as an asymmetric adversarial attack, in which reverse manipulation becomes feasible because existing defense paradigms do not control reversibility. To address this problem, we propose Asymmetric Reversible Face Protection (ARFP), a restoration-aware extension of personalized face cloaking that integrates privacy protection, keyed recovery, and tamper indication in a single framework. ARFP consists of three components: Key-Conditioned Manifold Binding, which ties the protection transformation to a user-provided key; Adversarial Restoration-Aware Training, which introduces a surrogate restoration adversary during training to improve robustness against evaluated inverse purification attacks; and Authorized Reversible Restoration, which supports recovery with the correct key while providing nonce-based tamper indication. Extensive experiments under the threat models considered in this work show that ARFP improves resistance to the evaluated restoration attacks while preserving authorized recovery utility. These results provide empirical evidence of key-sensitive recovery behavior and tamper awareness in the tested settings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。