用扩散模型无训练优化,让走路姿态骗过识别系统却保持自然。
GaitProtector: Impersonation-Driven Gait De-Identification via Training-Free Diffusion Latent Optimization

- 以模仿目标身份为锚点,同时隐藏原身份,平衡隐私与结构保真。
- 在CASIA-B上使识别准确率从89.6%降至15.0%,黑盒攻击成功率达56.7%。
- 无需重训练,直接优化预训练3D扩散模型潜空间,适合医疗等敏感应用。
传统步态去标识方法常面临隐私保护不足或引入时空畸变的矛盾。本文提出GaitProtector,一种基于模仿驱动的步态去标识框架,将隐私保护统一建模为两个紧密耦合的组件:(i) 混淆,使受保护步态远离原始身份;(ii) 模仿,使其向选定目标身份靠近。目标身份作为语义锚点,在预训练扩散先验下引导优化朝向结构合理的步态模式,有效保留人体基本形态与运动动态。通过无训练的扩散潜空间优化流程实现:不需为每数据集重新训练生成器,而是将输入轮廓序列反推至预训练3D视频扩散模型的潜轨迹,并使用可微分对抗目标迭代优化潜码,生成受保护步态。在CASIA-B数据集上,GaitProtector实现56.7%的黑盒模仿成功率,将Rank-1识别准确率从89.6%降至15.0%,同时保持良好视觉与时间质量。在Scoliosis1K数据集上,诊断准确率仅从91.4%下降至74.2%。据我们所知,这是首个以无训练方式利用预训练3D扩散先验进行基于轮廓的步态去标识工作。
原文摘要 · Abstract (English)
Conventional gait de-identification methods often encounter an inherent trade-off: they either provide insufficient identity suppression or introduce spatiotemporal distortions that impede structure-sensitive downstream applications. We propose GaitProtector, an impersonation-driven gait de-identification framework that formulates privacy protection as a unified objective with two tightly coupled components: (i) obfuscation, which repels the protected gait from the source identity, and (ii) impersonation, which attracts it toward a selected target identity. The target identity serves as a semantic anchor that biases optimization toward structurally plausible gait patterns under the pretrained diffusion prior, helping preserve dominant body shape and motion dynamics. We instantiate this idea through a training-free diffusion latent optimization pipeline. Instead of retraining a generator for each dataset, we invert each input silhouette sequence into the latent trajectory of a pretrained 3D video diffusion model and iteratively optimize latent codes with a differentiable adversarial objective to synthesize protected gaits. Experiments on the CASIA-B dataset show that GaitProtector achieves a 56.7% impersonation success rate under black-box gait recognition and reduces Rank-1 identification accuracy from 89.6% to 15.0%, while maintaining favorable visual and temporal quality. We further evaluate downstream utility on the Scoliosis1K dataset, where diagnostic accuracy decreases only from 91.4% to 74.2%. To the best of our knowledge, this work is the first to leverage pretrained 3D diffusion priors in a training-free manner for silhouette-based gait de-identification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。