arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

最近的目标是错误的:Arc2Face身份遗忘中的目标分离

The Nearest Target Is the Wrong One: Target Separation in Arc2Face Identity Unlearning

Zeynel Tok

arXiv 2608.30087首次发表:更新:

发表机构

University of Oxford(牛津大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对Arc2Face身份遗忘中重定向目标导致的失败问题,通过审计Arc2Face发现目标分离是关键设计变量,采用特定策略可提升干净遗忘率并降低遗忘身份的重新识别率。

AI 中文摘要

通过重定向面部条件生成器的条件嵌入来从其中遗忘某个身份时,如果重定向后的输出仍被验证为原始人物,则会悄然失败。我们表明,这种失败取决于重定向目标在识别空间中与遗忘身份的距离的可控选择,而最直观的目标即最近邻是最可能导致失败的。我们采用锁定的ArcFace协议和在生成前重定向身份条件的投影适配器对Arc2Face进行审计。在由符合条件的身份中最难的0.5%构建的硬邻域压力测试中,四种目标选择策略呈现单调响应:干净遗忘从最近硬目标下的9/30组上升到最不相似目标下的30/30组。平均遗忘身份的重新识别率从51.9降至0.0,而平均保留率保持不变。这反映了成功的重定向而非输出变得无法验证:720个最不相似硬生成样本中有710个到达所选目标,且无泄漏到无关身份。使用独立识别器(AdaFace)重新验证相同图像保留了该趋势,相关系数r=0.94,反对验证器人为因素的说法。因此,目标分离是身份遗忘中一个可报告的一阶设计变量。

英文摘要

Unlearning an identity from a face-conditioned generator by redirecting its conditioning embedding can silently fail if the redirected output is still verified as the original person. We show that this failure depends on a controllable choice of how far the redirection target lies from the forget identity in recognition space, and that the most intuitive target, the nearest neighbour, is the one most likely to cause it. We audit Arc2Face with a locked ArcFace protocol and a projection adapter that redirects identity conditioning before generation. On a hard-neighbour stress test built from the hardest 0.5% of eligible identities, four target-selection policies show a monotonic response: clean forgetting rises from 9/30 groups under the nearest hard target to 30/30 under the least similar one. Mean forget-identity re-identification falls from 51.9 to 0.0 while mean retention stays flat. This reflects successful redirection rather than outputs becoming unverifiable: 710 of 720 least-sim-hard generations arrive at the chosen target, with no leakage to unrelated identities. Re-verifying identical images with an independent recogniser (AdaFace) preserves that trend, correlating at r=0.94, arguing against a verifier artefact. Target separation is thus a first-order, reportable design variable for identity unlearning.

Comments16 pages, accepted at the ECCV 2026 Workshop on Unlearning and Model Editing (U&ME)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑