Towards Face Encryption by Generating Adversarial Identity Masks
Xiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su, Jun Zhu, Yuefeng Chen, Hui Xue
Abstract
As billions of personal data being shared through social media and network, the data privacy and security have drawn an increasing attention. Several attempts have been made to alleviate the leakage of identity information from face photos, with the aid of, e.g., image obfuscation techniques. However, most of the present results are either perceptually unsatisfactory or ineffective against face recognition systems. Our goal in this paper is to develop a technique that can encrypt the personal photos such that they can protect users from unauthorized face recognition systems but remain visually identical to the original version for human beings. To achieve this, we propose a targeted identity-protection iterative method (TIP-IM) to generate adversarial identity masks which can be overlaid on facial images, such that the original identities can be concealed without sacrificing the visual quality. Extensive experiments demonstrate that TIP-IM provides 95%+ protection success rate against various state-of-the-art face recognition models under practical test scenarios. Besides, we also show the practical and effective applicability of our method on a commercial API service.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers28
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding et al.NeurIPS 2022 · 84 citations
- DiffAM: Diffusion-Based Adversarial Makeup Transfer for Facial Privacy ProtectionYuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li et al.CVPR 2024 · 35 citations
- Hiding Visual Information via Obfuscating Adversarial PerturbationsZhigang Su, Dawei Zhou, Nannan Wang, Decheng Liu et al.ICCV 2023 · 16 citations
- Transferable Adversarial Facial Images for Privacy ProtectionMinghui Li, Jiangxiong Wang, Hao Zhang, Ziqi Zhou et al.ACM MM 2024 · 11 citations
Builds on5
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Boosting Adversarial Training with Hypersphere EmbeddingTianyu Pang, Xiao Yang, Yinpeng Dong, Taufik Xu et al.NeurIPS 2020 · 170 citations
- Live Face De-Identification in VideoOran Gafni, Lior Wolf, Yaniv TaigmanICCV 2019 · 154 citations
- Analyzing and Improving the Image Quality of StyleGANTero Karras, Samuli Laine, Miika Aittala, Janne Hellsten et al.CVPR 2020
- Fawkes: Protecting Privacy against Unauthorized Deep Learning ModelsShawn Shan, Emily Wenger, Jiayun Zhang, Huiying Li et al.USENIX Security 2020
Related papers
- Face Encryption via Frequency-Restricted Identity-Agnostic AttacksXin Dong, Rui Wang, Siyuan Liang, Aishan Liu et al.ACM MM 2023 · 4 citations
- Once-for-all: Efficient Visual Face Privacy Protection via Person-specific VeilsZixuan Yang, Yushu Zhang, Tao Wang, Zhongyun Hua et al.ACM MM 2024 · 2 citations
- Effective De-identification Generative Adversarial Network for Face AnonymizationZhenzhong Kuang, Huigui Liu, Jun Yu, Aikui Tian et al.ACM MM 2021 · 43 citations
- Enhancing Facial Privacy Protection via Weakening Diffusion PurificationAli Salar, Qing Liu, Yingli Tian, Guoying ZhaoCVPR 2025
- Transferable Facial Privacy Protection against Blind Face Restoration via Domain-Consistent Adversarial ObfuscationKui Zhang, Hang Zhou, Jie Zhang, Wenbo Zhou et al.ICML 2024 · 1 citation
