USENIX Security2024Top-tier venue
FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face Recognition
Shuaifan Jin, He Wang, Zhibo Wang, Feng Xiao, Jiahui Hu, Yuan He, Wenwen Zhang, Zhongjie Ba, Weijie Fang, Shuhong Yuan, Kui Ren
Abstract
As face recognition is widely used in various securitysensitive scenarios, face privacy issues are receiving increasing attention. Recently, many face recognition works have focused on privacy preservation and converted the original images into protected facial features. However, our study reveals that emerging Deep Learning-based (DL-based) reconstruction attacks exhibit notable ability in learning and removing the protection patterns introduced by existing schemes and recovering the original facial images, thus posing a significant threat to face privacy. To address this threat, we introduce FaceObfuscator, a lightweight privacy-preserving face recognition system that first removes visual information that is noncrucial for face recognition from facial images via frequency domain and then generates obfuscated features interleaved in the feature space to resist gradient descent in DL-based reconstruction attacks. To minimize the loss in face recognition accuracy, obfuscated features with different identities are well-designed to be interleaved but non-duplicated in the feature space. This non-duplication ensures that FaceObfuscator can extract identity information from the obfuscated features for accurate face recognition. Extensive experimental results demonstrate that FaceObfuscator's privacy protection capability improves around 90% compared to existing privacypreserving methods in two major leakage scenarios including channel leakage and database leakage, with a negligible 0.3% loss in face recognition accuracy. Our approach has also been evaluated in a real-world environment and protected more than 100K people's face data of a major university.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 45e9c698-2175-46fa-a9b6-bd9ea534767dCited by top-tier papers2
- FracFace: Breaking the Visual Clues - Fractal-Based Privacy-Preserving Face RecognitionWanying Dai, Beibei Li, Naipeng Dong, Guangdong Bai et al.NeurIPS 2025 · 7 citations
- InfoDecom: Decomposing Information for Defending Against Privacy Leakage in Split InferenceRuijun Deng, Zhihui Lu, Qiang DuanAAAI 2026
Builds on16
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- Oblivious Neural Network Predictions via MiniONN TransformationsJian Liu, Mika Juuti, Yao Lu, N. AsokanCCS 2017 · 800 citations
- MLPerf Inference BenchmarkVijay Janapa Reddi, Christine Cheng, David Kanter, Peter Mattson et al.ISCA 2020 · 517 citations
- InstaHide: Instance-hiding Schemes for Private Distributed LearningYangsibo Huang, Zhao Song, Kai Li, Sanjeev AroraICML 2020 · 178 citations
- Privacy-Preserving Face Recognition in the Frequency DomainYinggui Wang, Jian Liu, Man Luo, Le Yang et al.AAAI 2022 · 62 citations
Related papers
- Privacy-preserving Adversarial Facial FeaturesZhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang et al.CVPR 2023
- Learning Discrepant Transformations for Face Privacy ProtectionChenda Wei, Haoyue Wang, Zhenxing Qian, Sheng Li et al.ACM MM 2025
- PRO-Face: A Generic Framework for Privacy-preserving Recognizable Obfuscation of Face ImagesLin Yuan, Linguo Liu, Xiao Pu, Zhao Li et al.ACM MM 2022 · 38 citations
- Frequency-domain Manipulation for Face ObfuscationJintae Kim, Keunsoo Ko, Chang-Su KimCVPR 2026
- Do Not DeepFake Me: Privacy-Preserving Neural 3D Head Reconstruction Without Sensitive ImagesJiayi Kong, Xurui Song, Shuo Huai, Baixin Xu et al.AAAI 2025 · 3 citations
