Transferable Adversarial Facial Images for Privacy Protection
Minghui Li, Jiangxiong Wang, Hao Zhang, Ziqi Zhou, Shengshan Hu, Xiaobing Pei
Abstract
The success of deep face recognition (FR) systems has raised serious privacy concerns due to their ability to enable unauthorized tracking of users in the digital world. Previous studies proposed introducing imperceptible adversarial noises into face images to deceive those face recognition models, thus achieving the goal of enhancing facial privacy protection. Nevertheless, they heavily rely on user-chosen references to guide the generation of adversarial noises, and cannot simultaneously construct natural and highly transferable adversarial face images in black-box scenarios. In light of this, we present a novel face privacy protection scheme with improved transferability while maintain high visual quality. We propose shaping the entire face space directly instead of exploiting one kind of facial characteristic like makeup information to integrate adversarial noises. To achieve this goal, we first exploit global adversarial latent search to traverse the latent space of the generative model, thereby creating natural adversarial face images with high transferability. We then introduce a key landmark regularization module to preserve the visual identity information. Finally, we investigate the impacts of various kinds of latent spaces and find that F latent space benefits the trade-off between visual naturalness and adversarial transferability. Extensive experiments over two datasets demonstrate that our approach significantly enhances attack transferability while maintaining high visual quality, outperforming state-of-the-art methods by an average 25% improvement in deep FR models and 10% improvement on commercial FR APIs, including Face++, Aliyun, and Tencent.
Deep face recognition (FR) systems [30,40] have triumphed in both verification and identification scenarios and been widely applied across various domains, such as security [44], biometrics [28],
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aea3887e-0093-47d2-b911-a7f8bac0ee6cCited by top-tier papers11
- DarkSAM: Fooling Segment Anything Model to Segment NothingZiqi Zhou, Yufei Song, Minghui Li, Shengshan Hu et al.NeurIPS 2024 · 44 citations
- AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied AgentsYichen Wang, Hangtao Zhang, Hewen Pan, Ziqi Zhou et al.NeurIPS 2025 · 27 citations
- Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust FeatureYichen Wang, Yuxuan Chou, Ziqi Zhou, Hangtao Zhang et al.AAAI 2025 · 20 citations
- NumbOD: A Spatial-Frequency Fusion Attack Against Object DetectorsZiqi Zhou, Bowen Li, Yufei Song, Zhifei Yu et al.AAAI 2025 · 20 citations
- Vanish into Thin Air: Cross-prompt Universal Adversarial Attacks for SAM2Ziqi Zhou, Yifan Hu, Yufei Song, Zijing Li et al.NeurIPS 2025 · 17 citations
Builds on20
- Image2StyleGAN: How to Embed Images Into the StyleGAN Latent Space?Rameen Abdal, Yipeng Qin, Peter WonkaICCV 2019 · 1,195 citations
- High-Fidelity GAN Inversion for Image Attribute EditingTengfei Wang, Yong Zhang, Yanbo Fan, Jue Wang et al.CVPR 2022 · 227 citations
- Unrestricted Adversarial Examples via Semantic ManipulationAnand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li et al.ICLR 2020 · 177 citations
- Content-based Unrestricted Adversarial AttackZhaoyu Chen, Bo Li, Shuang Wu, Kaixun Jiang et al.NeurIPS 2023 · 132 citations
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
Related papers
- Diffusion-based Adversarial Identity Manipulation for Facial Privacy ProtectionLiqin Wang, Qianyue Hu, Wei Lu, Xiangyang LuoACM MM 2025 · 1 citation
- Machine Pareidolia: Protecting Facial Image with Emotional EditingBinh M. Le, Simon S. WooAAAI 2026
- DiffAM: Diffusion-Based Adversarial Makeup Transfer for Facial Privacy ProtectionYuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li et al.CVPR 2024 · 35 citations
- Face Encryption via Frequency-Restricted Identity-Agnostic AttacksXin Dong, Rui Wang, Siyuan Liang, Aishan Liu et al.ACM MM 2023 · 4 citations
- FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face RecognitionShuaifan Jin, He Wang, Zhibo Wang, Feng Xiao et al.USENIX Security 2024 · 9 citations
