Transferable Facial Privacy Protection against Blind Face Restoration via Domain-Consistent Adversarial Obfuscation
Kui Zhang, Hang Zhou, Jie Zhang, Wenbo Zhou, Weiming Zhang, Nenghai Yu
Abstract
With the rise of social media and the proliferation of facial recognition surveillance, concerns surrounding privacy have escalated significantly. While numerous studies have concentrated on safeguarding users against unauthorized face recognition, a new and often overlooked issue has emerged due to advances in facial restoration techniques: traditional methods of facial obfuscation may no longer provide a secure shield, as they can potentially expose anonymous information to human perception. Our empirical study shows that blind face restoration (BFR) models can restore obfuscated faces with high probability by simply retraining them on obfuscated (e.g., pixelated) faces. To address it, we propose a transferable adversarial obfuscation method for privacy protection against BFR models. Specifically, we observed a common characteristic among BFR models, namely, their capability to approximate an inverse mapping of a transformation from a high-quality image domain to a low-quality image domain. Leveraging this shared model attribute, we have developed a domain-consistent adversarial method for generating obfuscated images. In essence, our method is designed to minimize overfitting to surrogate models during the perturbation generation process, thereby enhancing the generalization of adversarial obfuscated facial images. Extensive experiments on various BFR models demonstrate the effectiveness and transferability of the proposed method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4af649e4-c3bc-4e23-b42d-a7064024ed95Builds on19
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Towards Robust Blind Face Restoration with Codebook Lookup TransformerShangchen Zhou, Kelvin C. K. Chan, Chongyi Li, Chen Change LoyNeurIPS 2022 · 431 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
- Live Face De-Identification in VideoOran Gafni, Lior Wolf, Yaniv TaigmanICCV 2019 · 154 citations
- RestoreFormer: High-Quality Blind Face Restoration from Undegraded Key-Value PairsZhouxia Wang, Jiawei Zhang, Runjian Chen, Wenping Wang et al.CVPR 2022 · 109 citations
Related papers
- DiffAM: Diffusion-Based Adversarial Makeup Transfer for Facial Privacy ProtectionYuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li et al.CVPR 2024 · 35 citations
- FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face RecognitionShuaifan Jin, He Wang, Zhibo Wang, Feng Xiao et al.USENIX Security 2024 · 9 citations
- Red-Teaming Privacy-Protective Perturbations: Blind Face Restoration as an Attack StrategyZelin Li, Yifan Liu, Huimin Zeng, Yaokun Liu et al.WWW 2026
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su et al.ICCV 2021 · 109 citations
- Frequency-domain Manipulation for Face ObfuscationJintae Kim, Keunsoo Ko, Chang-Su KimCVPR 2026
