arXiv:2608.17147cs.CRcs.LG2026-08

对比四种方法,评估人脸生成模型的隐私保护能力。

Picture the Epsilon: Pursuing Identity-Level Privacy Guarantees for Images

论文配图:Picture the Epsilon: Pursuing Identity-Level Privacy Guarantees for Images
图 1 · 摘自论文原文
  • 提出四种黑箱审计方法,评估图像生成的隐私性。
  • 在多个模型上发现身份可区分性强,但ε值差异大。
  • 适合关注生成模型隐私的科研与安全从业者。

图像到图像的人脸生成器广泛应用,其输出与源图像的视觉差异常被视为隐私保障的证据。验证这些系统是否满足形式化的身份级(epsilon, delta)-差分隐私,需在多种将嵌入空间观测转化为差分隐私参数ε估计或边界的方法间选择。本文对四种适用于预训练、黑箱人脸生成器的审计方法进行了比较研究:基于高斯机制的逐身份敏感度读数(GaussMech);通过基础组合聚合的逐维核密度对数比(KDE-LR);从最大均值差异经总变差距离推导的纯差分隐私ε的解析群体下界(MMD-TV);以及基于交叉验证分类器的出堆外ROC检验(ROC-HT)。每种方法均明确其假设、超参数依赖、有限样本局限及ε估计有效的场景。应用于FaceFusion和InstantID,结合多种身份编码器与参考数据集,审计结果一致显示显著的身份可区分性,但各方法报告的ε值差异显著,反映其不同假设与有限样本处理方式的影响。在高可区分性条件下,实验无法可靠排序四种方法。其相对权衡应针对部分私密机制进一步评估,这被识别为自然后续研究方向。该框架将四种审计置于统一的身份级审计场景中,澄清了假设与有限样本处理如何影响差分隐私估计结果。

原文摘要 · Abstract (English)

Image-to-image face generators are widely used, and visual dissimilarity between their outputs and source images is sometimes treated as evidence of privacy. Auditing whether these systems satisfy formal identity-level (epsilon, delta)-differential privacy requires choosing among several distinct routes for converting embedding-space observations into estimates or bounds on the differential privacy parameter epsilon. We present a comparative study of four such audits applicable to pre-trained, black-box face generators: a Gaussian-mechanism reading of per-identity sensitivity (GaussMech); a per-dimension kernel-density log-ratio aggregated by basic composition (KDE-LR); an analytical population-level lower bound on pure-DP epsilon derived from the maximum mean discrepancy via the total variation distance (MMD-TV); and a hypothesis-testing evaluation of a cross-validated classifier's out-of-fold ROC (ROC-HT). For each method we make explicit its assumptions, hyperparameter dependence, finite-sample limitations, and the regime in which its epsilon estimate is informative. Applied to FaceFusion and InstantID across multiple identity encoders and reference datasets, the audits consistently reveal substantial identity distinguishability while reporting markedly different epsilon estimates that reflect each method's distinct assumptions and finite-sample treatment. In this high-distinguishability regime, the experiments do not support a reliable ranking of the four methods. Their relative trade-offs should be evaluated on partially private mechanisms, which we identify as the natural next study. The resulting framework places these audits in a shared identity-level audit setting and clarifies how their assumptions and finite-sample treatments shape the resulting differential privacy estimates.

隐私保护差分隐私人脸生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。