arXiv:2607.17504cs.CVcs.AI2026-07

用不可察觉的假身份误导攻击者,保护人脸识别隐私。

DecoyFace: Beyond Obfuscation via Controllable and Imperceptible Identity Misdirection for Privacy-Preserving Face Recognition

论文配图:DecoyFace: Beyond Obfuscation via Controllable and Imperceptible Identity Misdirection for Privacy-Preserving Face Recognition
图 1 · 摘自论文原文
  • 将特征分为易被还原和不易被还原两部分,注入假身份线索。
  • 在U-Net攻击下身份泄露降为2.93%,流匹配攻击下仅0.74%。
  • 生成结果视觉真实,99.78%在LFW上有效,适合高隐私需求场景。

分割式人脸识别虽降低客户端计算负担,但中间特征易遭特征逆向攻击及诚实但好奇(HBC)服务器的非法分析。现有隐私保护方法多旨在阻止未经授权的重构,通常导致重构结果明显失真,反而暴露防护存在并诱发自适应攻击。为此,我们提出DecoyFace——一种不可察觉的伪装导向框架,引导未经授权的重构指向合理但错误的身份,同时保持识别可用性。核心思想是将中间表示分解为重建敏感子空间及其互补子空间:客户端将假身份线索注入重建敏感子空间,而真实样本的关键识别信息保留在互补子空间中。服务端通过授权规范化模块抑制主导的假身份成分,恢复利于识别的表示。该设计同时应对拦截特征的攻击者逆向与HBC服务器对规范表示的重构。实验表明,DecoyFace在保持良好识别精度的同时,显著降低身份泄露——在U-Net攻击下为2.93%,在流匹配攻击下为0.74%,且重构结果视觉合理、难以察觉,LFW数据集上人脸有效性超过99.78%。

原文摘要 · Abstract (English)

Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks. To address this issue, we propose DecoyFace, an imperceptible decoy-oriented framework that steers unauthorized reconstruction toward a plausible but incorrect identity while preserving recognition utility. The key idea is to decompose the intermediate representation into a reconstruction-sensitive subspace and its complementary subspace. The client injects decoy identity cues into the reconstruction-sensitive subspace, while limited recognition-relevant evidence from the true sample is retained in the complementary subspace. On the server side, an authorized canonicalization module suppresses decoy-dominant components and recovers a recognition-friendly representation. This design addresses both attacker-side inversion from intercepted features and HBC server-side reconstruction from canonicalized representations. Experiments show that DecoyFace preserves competitive recognition accuracy while substantially reducing identity leakage to 2.93% under U-Net attacks and 0.74% under Flow-Matching attacks while yielding visually plausible and imperceptible reconstructions, with over 99.78% face validity on LFW dataset.

隐私保护人脸识别对抗攻击伪装生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。