arXiv:2607.27764cs.CVcs.AI2026-07

提出新方法发布人脸数据,既保护隐私又保留识别能力。

Private Face Recognition Training Dataset Publication via Identity-Decoupled and Geometry-Preserving Face Distillation

论文配图:Private Face Recognition Training Dataset Publication via Identity-Decoupled and Geometry-Preserving Face Distillation
图 1 · 摘自论文原文
  • 用正交几何保持和关系拓扑对齐,分离身份信息但保留识别结构。
  • 在IJB-C上将识别率提升3.94%,同时降低原始身份关联风险。
  • 适合需要发布敏感人脸识别数据的研究者使用。

发布私人人脸识别(FR)训练数据存在隐私风险,因人脸可能暴露身份信息。现有方法通过释放受保护的代理数据替代原始人脸来缓解风险,但会引发身份悖论:使代理数据适用于识别监督的身份线索,也使其易与真实个体关联。受保护的人脸应脱离原始身份,但仍需具备可靠的身份样本特性以支持学习。过度去除身份线索会破坏识别所需的类别结构,而保留过强则增加源身份可链接性。我们指出该悖论源于混淆了源对齐的身份语义与识别有用的代理几何结构。前者应抑制以降低关联风险,后者应保留以支持识别学习。基于此,我们提出私有面部蒸馏(Private Face Distillation),采用正交几何保持构建去身份化的代理身份表示,同时维持超球面几何;并利用关系拓扑对齐保留身份间关系以支持识别学习。多领域迁移场景实验表明,该方法优于现有基线,在IJB-C监控场景下,$ ext{TAR}@{ ext{FAR}=1 ext{e-}3}$ 提升3.94%,同时显著降低源身份可链接性。结果表明,私有人脸识别数据发布应解耦源身份对应关系,同时保留代理身份几何结构。

原文摘要 · Abstract (English)

Publishing private face recognition~(FR) training datasets is privacy-sensitive because faces expose identity information. Private FR training dataset publication mitigates this risk by releasing protected proxies as substitutes for private training faces. However, training FR models with such data introduces an identity paradox: \emph{the identity cues that make released faces useful for recognition supervision are also the cues that make them linkable to real individuals.} A protected face should be decoupled from the original identity, yet still behave as a reliable identity sample for training. Removing these cues too aggressively may destroy the class structure needed for recognition learning, whereas preserving them too faithfully may increase source-identity linkability. We argue that this paradox stems from conflating source-aligned identity semantics with recognition-useful proxy identity geometry. The former should be suppressed to reduce linkage to private individuals, while the latter should be preserved for FR learning. Based on this insight, we propose \textbf{Private Face Distillation}, an identity-decoupling and geometry-preserving framework. It uses Orthogonal Geometry Preservation to construct decoupled proxy identities from private identity representations while maintaining hyperspherical geometry, and Relational Topology Alignment to preserve identity relations for recognition learning. Experiments across multiple domain-shifted FR scenarios show that Private Face Distillation achieves stronger utility than the evaluated publication baselines. On IJB-C surveillance, it improves $\mathrm{TAR}@\mathrm{FAR}{=}1\text{e-}{3}$ by 3.94\% over the baseline while reducing source-identity linkability. These results suggest that private FR training dataset publication should decouple source-identity correspondence while preserving proxy identity geometry.

人脸识别隐私保护数据蒸馏

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。