用可逆扰动保护人脸,让盗用者无法训练出有效识别模型。
Unlearnable Faces: Privacy Protection Surviving Extraction Pipeline

- 在图像共享前添加不可察觉的扰动,使模型无法学习干净人脸。
- 在裁剪+缩放提取后攻击下,攻击准确率低于10%,仍保持不可察觉。
- 针对提取过程优化扰动,适配不同相册和未见过的用户。
不可学习样本能防止公开分享的照片被未经授权的人脸识别模型学习。在分享前添加微小扰动,使基于受保护图片训练的模型在干净人脸上的表现失效。然而,当攻击者从提取出的、裁剪并缩放至识别器输入尺寸的人脸中训练时,该保护机制会崩溃。我们提出LPID,将提取过程纳入不可学习样本的目标函数中。LPID将扰动限制在提取后的人脸区域,并通过可微分的提取模型优化扰动,使其能量集中在提取过程保留的频率带内。由于这种鲁棒性是变换本身的属性而非特定身份,LPID可针对每个相册重新优化,甚至能保护从未见过的用户。在所有评估设置中,LPID均实现最低攻击准确率,在未见过的身份上经裁剪+缩放提取后攻击准确率低于10%,同时保持32.7 dB PSNR与0.161 LPIPS的不可察觉性。
原文摘要 · Abstract (English)
Unlearnable examples keep publicly shared photos from being learned by unauthorized face-recognition models. An imperceptible perturbation, added before sharing, makes any model trained on the protected photos fail on clean faces. The perturbation is crafted on the shared image, however the attacker trains on the face it extracts, cropped and resized to the recognizer input, and under this extraction the protection collapses. We propose LPID, which builds the extraction into the unlearnable-example objective. LPID confines the perturbation to the extracted face region and optimizes it through a differentiable model of the extraction, concentrating its energy in the frequency band the extraction preserves. Because this robustness is a property of the transform rather than of any identity, LPID is re-optimized per album and protects even users it has never seen. LPID attains the lowest attacker accuracy of all methods in every setting we evaluate, holding the attacker below $10\%$ under crop+resize extraction on identities unseen at protection time, while remaining imperceptible at $32.7$\,dB PSNR and $0.161$ LPIPS.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。