Privacy-preserving Adversarial Facial Features
Zhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang, Jiahui Hu, Yan Wang, Peng Sun, Wei Yuan, Kaixin Liu, Kui Ren
Abstract
Face recognition service providers protect face privacy by extracting compact and discriminative facial features (representations) from images, and storing the facial features for real-time recognition. However, such features can still be exploited to recover the appearance of the original face by building a reconstruction network. Although several privacy-preserving methods have been proposed, the enhancement of face privacy protection is at the expense of accuracy degradation. In this paper, we propose an adversarial features-based face privacy protection (AdvFace) approach to generate privacy-preserving adversarial features, which can disrupt the mapping from adversarial features to facial images to defend against reconstruction attacks. To this end, we design a shadow model which simulates the attackers' behavior to capture the mapping function from facial features to images and generate adversarial latent noise to disrupt the mapping. The adversarial features rather than the original features are stored in the server's database to prevent leaked features from exposing facial information. Moreover, the AdvFace requires no changes to the face recognition network and can be implemented as a privacy-enhancing plugin in deployed face recognition systems. Extensive experimental results demonstrate that AdvFace outperforms the state-of-the-art face privacypreserving methods in defending against reconstruction attacks while maintaining face recognition accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- Privacy-Preserving Face Recognition Using Trainable Feature SubtractionYuxi Mi, Zhizhou Zhong, Yuge Huang, Jiazhen Ji et al.CVPR 2024 · 24 citations
- A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningXiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li et al.CVPR 2024 · 13 citations
- FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face RecognitionShuaifan Jin, He Wang, Zhibo Wang, Feng Xiao et al.USENIX Security 2024 · 9 citations
- FracFace: Breaking the Visual Clues - Fractal-Based Privacy-Preserving Face RecognitionWanying Dai, Beibei Li, Naipeng Dong, Guangdong Bai et al.NeurIPS 2025 · 7 citations
- LDP-Slicing: Local Differential Privacy for Images via Randomized Bit-Plane SlicingYuanming Cao, Chengqi Li, Wenbo HeCVPR 2026 · 2 citations
Builds on1
Related papers
- Learning Discrepant Transformations for Face Privacy ProtectionChenda Wei, Haoyue Wang, Zhenxing Qian, Sheng Li et al.ACM MM 2025
- SlerpFace: Face Template Protection via Spherical Linear InterpolationZhizhou Zhong, Yuxi Mi, Yuge Huang, Jianqing Xu et al.AAAI 2025 · 14 citations
- Privacy-Preserving Image Features via Adversarial Affine Subspace EmbeddingsMihai Dusmanu, Johannes L. Schönberger, Sudipta N. Sinha, Marc PollefeysCVPR 2021
- Realistic Face Reconstruction from Facial Embeddings via Diffusion ModelsDong Han, Yong Li, Joachim DenzlerAAAI 2026
- Transferable Adversarial Facial Images for Privacy ProtectionMinghui Li, Jiangxiong Wang, Hao Zhang, Ziqi Zhou et al.ACM MM 2024 · 11 citations
