Recoverable Facial Identity Protection via Adaptive Makeup Transfer Adversarial Attacks
Xiyao Liu, Junxing Ma, Xinda Wang, Qianyu Lin, Jian Zhang, Gerald Schaefer, Cagatay Turkay, Hui Fang
Abstract
Unauthorised face recognition (FR) systems have posed significant threats to digital identity and privacy protection. To alleviate the risk of compromised identities, recent makeup transfer-based attack methods embed adversarial signals in order to confuse unauthorised FR systems. However, their major weakness is that they set up a fixed image unrelated to both the protected and the makeup reference images as the confusion identity, which in turn has a negative impact on both attack success rate and visual quality of transferred photos. In addition, the generated images cannot be recognised by authorised FR systems once attacks are triggered. To address these challenges, in this paper, we propose a Recoverable Makeup Transferred Generative Adversarial Network (RMT-GAN) which has the distinctive feature of improving its image-transfer quality by selecting a suitable transfer reference photo as the target identity. Moreover, our method offers a solution to recover the protected photos to their original counterparts that can be recognised by authorised systems. Experimental results demonstrate that our method provides significantly improved attack success rates while maintaining higher visual quality compared to state-of-the-art makeup transfer-based adversarial attack methods. Our code and supplementary materials are available on Github.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 547c2fbf-e8e6-486d-b705-1dd7d978251eCited by top-tier papers1
Ask how each one uses itBuilds on10
- Live Face De-Identification in VideoOran Gafni, Lior Wolf, Yaniv TaigmanICCV 2019 · 154 citations
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
- LADN: Local Adversarial Disentangling Network for Facial Makeup and De-MakeupQiao Gu, Guanzhi Wang, Mang Tik Chiu, Yu-Wing Tai et al.ICCV 2019 · 119 citations
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su et al.ICCV 2021 · 109 citations
- LowKey: Leveraging Adversarial Attacks to Protect Social Media Users from Facial RecognitionValeriia Cherepanova, Micah Goldblum, Harrison Foley, Shiyuan Duan et al.ICLR 2021 · 52 citations
Related papers
- DiffAM: Diffusion-Based Adversarial Makeup Transfer for Facial Privacy ProtectionYuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li et al.CVPR 2024 · 35 citations
- Face Reconstruction from Facial Templates by Learning Latent Space of a Generator NetworkHatef Otroshi-Shahreza, Sébastien MarcelNeurIPS 2023 · 48 citations
- Revealing True Identity: Detecting Makeup Attacks in Face-based Biometric SystemsMohammad Amin Arab, Puria Azadi Moghadam, Mohamed E. Hussein, Wael Abd-Almageed et al.ACM MM 2020 · 10 citations
- SOGAN: 3D-Aware Shadow and Occlusion Robust GAN for Makeup TransferYueming Lyu, Jing Dong, Bo Peng, Wei Wang et al.ACM MM 2021 · 36 citations
- ImU: Physical Impersonating Attack for Face Recognition System with Natural Style ChangesShengwei An, Yuan Yao, Qiuling Xu, Shiqing Ma et al.S&P 2023
