Privacy-Preserving Face Recognition with Adaptive Generative Perturbations
摘要
For online face recognition services, the potential leakage of facial features and reconstruction techniques gives malicious attackers the opportunity to reconstruct face images, raising public concern about privacy. Previous privacy-preserving face recognition methods either require retraining the face recognition model or iterative perturbation that increases inference time. To overcome these limitations, we propose an efficient plug-and-play method that crafts Adaptive Generative perturbations for frozen Face recognition model (AGFace) to defend the reconstruction attacks. To generate perturbation with a single forward for shallow features extracted by frozen recognition model, we learn a Perturbation Generator to efficiently mine the adversarial perturbations by simultaneously minimizing the perturbation and maximizing the reconstruction error of a proxy reconstructor. To achieve privacy-utility trade-off, we propose the Adaptive Channel Selector to identify top-k reconstruction-sensitive channels for the features. By selecting these channels for perturbation, the dominant visual privacy information is protected with reconstruction-insensitive discriminative information preserved. Extensive experiments demonstrate that AGFace achieves state-of-the-art performance in terms of both privacy and utility among retraining-free methods and is comparable to retraining-dependent methods.