身份删除失败主因是目标太近,选远点才能真正擦除身份痕迹。
The Nearest Target Is the Wrong One: Target Separation in Arc2Face Identity Unlearning

- 通过控制重定向目标与遗忘身份在识别空间的距离,实现可控身份删除。
- 最远目标下30组全部成功遗忘,最近目标仅9组有效,误认率从51.9降至0.0。
- 适用于需精准删除人脸生成模型中特定身份的研究者与开发者。
通过调整面部条件生成器的条件嵌入来删除特定身份时,若重定向输出仍被验证为原身份,则删除会悄然失败。我们发现,这种失败取决于重定向目标与遗忘身份在识别空间中的距离,而最直观的最近邻目标恰恰最易导致失败。在采用固定ArcFace协议和投影适配器的Arc2Face系统上进行测试,针对最难的0.5%身份构建压力测试集,四种目标选择策略呈现单调响应:在最近硬目标下,30组中有9组成功遗忘;而在最不相似目标下,30组全部成功遗忘。平均遗忘身份重识别率从51.9降至0.0,平均保留率保持稳定。710/720个最不相似硬目标生成结果准确抵达目标,无泄露至无关身份。使用独立识别器AdaFace复核,相关性达r=0.94,排除验证器伪影。因此,目标分离是身份删除的一阶可报告设计变量。
原文摘要 · Abstract (English)
Unlearning an identity from a face-conditioned generator by redirecting its conditioning embedding can silently fail if the redirected output is still verified as the original person. We show that this failure depends on a controllable choice of how far the redirection target lies from the forget identity in recognition space, and that the most intuitive target, the nearest neighbour, is the one most likely to cause it. We audit Arc2Face with a locked ArcFace protocol and a projection adapter that redirects identity conditioning before generation. On a hard-neighbour stress test built from the hardest 0.5% of eligible identities, four target-selection policies show a monotonic response: clean forgetting rises from 9/30 groups under the nearest hard target to 30/30 under the least similar one. Mean forget-identity re-identification falls from 51.9 to 0.0 while mean retention stays flat. This reflects successful redirection rather than outputs becoming unverifiable: 710 of 720 least-sim-hard generations arrive at the chosen target, with no leakage to unrelated identities. Re-verifying identical images with an independent recogniser (AdaFace) preserves that trend, correlating at r=0.94, arguing against a verifier artefact. Target separation is thus a first-order, reportable design variable for identity unlearning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。