Facial Privacy Protection via Attention-Guided Latent Diffusion Model for Adversarial Sample Generation
摘要
Existing privacy protection methods face issues such as an imbalance between visual quality and adversarial effectiveness, as well as weak transferability. This paper leverages the high-quality generation capability and computational efficiency of the Latent Diffusion Model (LDM) and proposes a face privacy protection algorithm, LDM-CA, which uses makeup transfer as the key perturbation. LDM integrates feature distillation loss into the attention mechanism of the UNet model and combines text guidance during image generation. This allows the makeup of the reference image to be transferred onto the source image. The model also incorporates a portability enhancement module to ensure that the generated makeup effect visually aligns with the reference makeup domain, achieving high black-box transferability. Experiments on the CelebA-HQ and LADN datasets demonstrate that, compared to existing techniques, the images generated by the LDM-CA method exhibit superior visual quality and a 12% increase in black-box attack success rate over GAN-based methods.