面向人脸交换匿名化中可解释的隐私保障
Toward Interpretable Privacy Guarantees in Face-Swapping Anonymization
浏览论文内容
中文总结 AI 辅助
针对人脸交换匿名化存在的身份泄露问题,提出线性随机模型解释泄露机制,旨在实现可解释的形式化隐私保障。
中文摘要 AI 辅助
人脸交换已成为一种有前景的面部隐私保护方法,它将目标个体的外观替换为捐赠者的外观,同时保留非面部上下文。生成的图像在视觉上与捐赠者相似,人脸识别系统往往会抑制目标的匹配分数——表面上满足隐私要求。然而,对一系列人脸交换模型的实证评估显示,仍会发生显著的目标身份泄露。这引发了一个更深层次的问题:泄露为何会发生,又能否被预测?我们提出了一种线性随机模型,将人脸交换器视为身份嵌入空间上的变换,为泄露机制提供了可解释的解释。该模型拟合于实证观测结果,并用于推导可检验的预测。其目标是将隐私评估建立在有原则的、可解释的分析基础上,从而使形式化的隐私保障可解释——且可完善——而非纯粹基于观测。
英文摘要
Face-swapping has emerged as a promising approach to facial privacy protection, replacing a target individual's appearance with that of a donor while preserving non-facial context. The resulting images visually resemble the donor, and face recognition systems tend to suppress the target's match scores -- ostensibly satisfying privacy requirements. Empirical evaluation across a range of face-swapping models, however, reveals that significant target identity leakage still occurs. This raises a deeper question: why does leakage occur, and can it be predicted? We propose a linear stochastic model that treats face-swappers as transformations on the space of identity embeddings, providing an interpretable account of the leakage mechanism. The model is fit to empirical observations and used to derive testable predictions. The aim is to ground privacy assessments in principled, interpretable analysis, thus making formal privacy guarantees explainable -- and perfectible -- rather than purely observational.