DiffAM: Diffusion-Based Adversarial Makeup Transfer for Facial Privacy Protection
Yuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li, Yongdong Zhang
Abstract
With the rapid development of face recognition (FR) systems, the privacy of face images on social media is facing severe challenges due to the abuse of unauthorized FR systems. Some studies utilize adversarial attack techniques to defend against malicious FR systems by generating adversarial examples. However, the generated adversarial examples, i.e., the protected face images, tend to suffer from sub-par visual quality and low transferability. In this paper, we propose a novel face protection approach, dubbed DiffAM, which leverages the powerful generative ability of diffusion models to generate high-quality protected face images with adversarial makeup transferred from reference images. To be specific, we first introduce a makeup removal module to generate non-makeup images utilizing a fine-tuned diffusion model with guidance of textual prompts in CLIP space. As the inverse process of makeup transfer, makeup removal can make it easier to establish the deterministic relationship between makeup domain and non-makeup domain regardless of elaborate text prompts. Then, with this relationship, a CLIP-based makeup loss along with an ensemble attack strategy is introduced to jointly guide the direction of adversarial makeup domain, achieving the generation of protected face images with natural-looking makeup and high black-box transferability. Extensive experiments demonstrate that DiffAM achieves higher visual quality and attack success rates with a gain of 12.98% under black-box setting compared with the state of the arts. The code will be available at https://github.com/HansSunYIDiffAM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 54ed7f9e-12ab-4959-be80-847e6271d1afCited by top-tier papers11
- ReCot: Reflective Self-Correction Training for Mitigating Confirmation Bias in Large Vision-Language ModelsMengxue Qu, Yibo Hu, Kunyang Han, Yunchao Wei et al.ICCV 2025 · 3 citations
- Vpr-Cloak: a First Look at Privacy Cloak Against Visual Place RecognitionShuting Dong, Mingzhi Chen, Feng Lu, Hao Yu et al.ICCV 2025 · 2 citations
- Diffusion-based Adversarial Identity Manipulation for Facial Privacy ProtectionLiqin Wang, Qianyue Hu, Wei Lu, Xiangyang LuoACM MM 2025 · 1 citation
- DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR StrategyWenshu Fan, Minxing Zhang, Hongwei Li, Wenbo Jiang et al.CCS 2025 · 1 citation
- Realistic Face Reconstruction from Facial Embeddings via Diffusion ModelsDong Han, Yong Li, Joachim DenzlerAAAI 2026
Builds on22
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Improved Denoising Diffusion Probabilistic ModelsAlexander Quinn Nichol, Prafulla DhariwalICML 2021 · 5,234 citations
- SDEdit: Guided Image Synthesis and Editing with Stochastic Differential EquationsChenlin Meng, Yutong He, Yang Song, Jiaming Song et al.ICLR 2022 · 2,128 citations
Related papers
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
- Recoverable Facial Identity Protection via Adaptive Makeup Transfer Adversarial AttacksXiyao Liu, Junxing Ma, Xinda Wang, Qianyu Lin et al.AAAI 2025 · 1 citation
- Enhancing Facial Privacy Protection via Weakening Diffusion PurificationAli Salar, Qing Liu, Yingli Tian, Guoying ZhaoCVPR 2025
- Transferable Adversarial Facial Images for Privacy ProtectionMinghui Li, Jiangxiong Wang, Hao Zhang, Ziqi Zhou et al.ACM MM 2024 · 11 citations
- Adv-Diffusion: Imperceptible Adversarial Face Identity Attack via Latent Diffusion ModelDecheng Liu, Xijun Wang, Chunlei Peng, Nannan Wang et al.AAAI 2024 · 39 citations
