arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

DecoyFace:通过可控且不可察觉的身份误导实现超越混淆的隐私保护人脸识别

DecoyFace: Beyond Obfuscation via Controllable and Imperceptible Identity Misdirection for Privacy-Preserving Face Recognition

Zhihan Ren, Lijun He, Xinyao Wang, Xinzhu Fu, Fan Li

arXiv 2607.17504首次发表:更新:

发表机构

School of Information and Communications Engineering, Xi’an Jiaotong University; Shaanxi Key Laboratory of Deep Space Exploration Intelligent Information Technology(西安交通大学信息与通信工程学院; 陕西省深空探测智能信息技术重点实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对分割式人脸识别中隐私问题,提出DecoyFace框架,通过分解中间表示为子空间,客户端注入诱饵线索,服务器端规范化处理,在保持识别准确率的同时大幅降低身份泄露,实现隐私保护的人脸识别。

AI 中文摘要

分割式人脸识别减少了客户端计算,但会将中间特征暴露于特征反转攻击以及诚实但好奇(HBC)服务器的未经授权分析。现有隐私保护人脸识别方法主要旨在抵御未经授权的重建,通常生成的特征反转后结果明显退化,可能揭示保护的存在并引发自适应攻击。为解决此问题,我们提出DecoyFace,一个面向不可察觉诱饵的框架,在保留识别效用的同时,将未经授权的重建导向一个看似合理但错误的身份。关键思想是将中间表示分解为对重建敏感的子空间及其互补子空间。客户端将诱饵身份线索注入对重建敏感的子空间,而来自真实样本的有限识别相关证据保留在互补子空间中。在服务器端,一个授权的规范化模块抑制诱饵主导的组件并恢复一个有利于识别的表示。此设计解决了攻击者从截获特征进行的反转以及HBC服务器从规范化表示进行的重建问题。实验表明,DecoyFace在保持有竞争力的识别准确率的同时,在U-Net攻击下将身份泄露大幅降低至2.93%,在Flow-Matching攻击下降低至0.74%,同时产生视觉上合理且不可察觉的重建,在LFW数据集上的面部有效性超过99.78%。

英文摘要

Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks. To address this issue, we propose DecoyFace, an imperceptible decoy-oriented framework that steers unauthorized reconstruction toward a plausible but incorrect identity while preserving recognition utility. The key idea is to decompose the intermediate representation into a reconstruction-sensitive subspace and its complementary subspace. The client injects decoy identity cues into the reconstruction-sensitive subspace, while limited recognition-relevant evidence from the true sample is retained in the complementary subspace. On the server side, an authorized canonicalization module suppresses decoy-dominant components and recovers a recognition-friendly representation. This design addresses both attacker-side inversion from intercepted features and HBC server-side reconstruction from canonicalized representations. Experiments show that DecoyFace preserves competitive recognition accuracy while substantially reducing identity leakage to 2.93% under U-Net attacks and 0.74% under Flow-Matching attacks while yielding visually plausible and imperceptible reconstructions, with over 99.78% face validity on LFW dataset.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑