Pith. sign in

REVIEW 2 cited by

Transferable Adversarial Facial Images for Privacy Protection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2408.01428 v1 pith:XCZNZ6T5 submitted 2024-07-18 cs.CV cs.AI

classification cs.CVcs.AI
keywords adversarialfaceimageslatentprivacytransferabilityvisualfacial
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

The success of deep face recognition (FR) systems has raised serious privacy concerns due to their ability to enable unauthorized tracking of users in the digital world. Previous studies proposed introducing imperceptible adversarial noises into face images to deceive those face recognition models, thus achieving the goal of enhancing facial privacy protection. Nevertheless, they heavily rely on user-chosen references to guide the generation of adversarial noises, and cannot simultaneously construct natural and highly transferable adversarial face images in black-box scenarios. In light of this, we present a novel face privacy protection scheme with improved transferability while maintain high visual quality. We propose shaping the entire face space directly instead of exploiting one kind of facial characteristic like makeup information to integrate adversarial noises. To achieve this goal, we first exploit global adversarial latent search to traverse the latent space of the generative model, thereby creating natural adversarial face images with high transferability. We then introduce a key landmark regularization module to preserve the visual identity information. Finally, we investigate the impacts of various kinds of latent spaces and find that $\mathcal{F}$ latent space benefits the trade-off between visual naturalness and adversarial transferability. Extensive experiments over two datasets demonstrate that our approach significantly enhances attack transferability while maintaining high visual quality, outperforming state-of-the-art methods by an average 25% improvement in deep FR models and 10% improvement on commercial FR APIs, including Face++, Aliyun, and Tencent.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Local Features Meet Stochastic Anonymization: Revolutionizing Privacy-Preserving Face Recognition for Black-Box Models

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A stochastic, high-frequency-preserving anonymization method is claimed to keep faces unrecognizable to people while retaining 94.21% average accuracy on face recognition models that were not used during optimization.

  2. ErasableMask: A Robust and Erasable Privacy Protection Scheme against Black-box Face Recognition Models

    cs.CV 2024-12 conditional novelty 5.0 of 10

    A conditional GAN adds transferable, self-erasable semantic masks that break black-box face recognition while allowing a trusted partner to reconstruct the original face.

Pith tools