arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Damnatio Memoriae:在人脸识别模型嵌入空间中对身份进行对抗性与选择性遗忘

Damnatio Memoriae: Adversarially and Selectively Forgetting Identities in the Embedding Space of Face Recognition Models

Ünsal Öztürk, Vedrana Krivokuća Hahn, Sushil Bhattacharjee, Sébastien Marcel

arXiv 2609.27115首次发表:更新:

发表机构

Idiap Research Institute; UNIL(伊迪亚普研究所; 洛桑大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对人脸识别模型,提出三种损失函数在嵌入空间进行开放集对抗性遗忘,使选定身份不可关联,其中正交框架方法效果最佳且保留率高。

AI 中文摘要

人脸识别模型在两次不同场合记录的同一个人图像,当其嵌入相似度超过操作阈值时,会将两者关联起来。我们考虑在模型继续为其余人群服务的同时,使选定的身份在不同场合之间无法被关联。删除其图像并重新训练无法实现这一点,因为模型能够识别训练中从未出现过的身份。因此,必须针对这些身份改变嵌入空间,我们将这一过程称为开放集对抗性遗忘。我们提出了三种损失函数:一种将身份的嵌入从其质心分散开,另外两种将每张图像映射到其自身的近正交目标上,该目标可通过分类器头学习或预先固定为近标准正交框架。每种损失函数都在每个身份图像子集上,与分类目标一起进行微调。我们在验证和识别任务中,针对先前工作中的四种方法,在两种遗忘规模和三种骨干网络下对它们进行评估。每种作用于嵌入几何的损失函数都使被遗忘的身份几乎无法被识别。仅使用标准正交框架即可实现强遗忘,无论该子集的图像在比较中出现于何处,都能保持不同被遗忘身份之间不可关联性。它还在更高的保留率下超越了并行的无监督方法。

英文摘要

A face recognition model links two images of a person recorded on separate occasions when their embedding similarity exceeds an operating threshold. We consider making chosen identities unlinkable across separate occasions while the model remains in service for the rest of the population. Deleting their images and retraining does not achieve this, since the model recognises identities never observed in training. Therefore, the embedding space must be altered against these identities, the process of which we call open-set adversarial forgetting. We propose three loss functions, one that disperses an identity's embeddings from their centroid, and two that map each image onto its own near-orthogonal target, learnt with the classifier head or fixed in advance as an almost-orthonormal frame. Each is fine-tuned alongside the classification objective on a subset of each identity's images. We evaluate them against four methods from prior work in verification and identification, at two forget scales and three backbones. Every loss acting on the embedding geometry makes the forget identities nearly unidentifiable. The orthonormal frame alone achieves strong forgetting, which holds wherever an image of that subset enters the comparison and leaves distinct forget identities unlinkable. It also surpasses a concurrent unsupervised method at a higher retain rate.

Comments15 pages, 7 figures, 5 tables. This work might be submitted to the IEEE for possible publication

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑