For online face recognition services, the potential leakage of facial features and reconstruction techniques gives malicious attackers the opportunity to reconstruct face images, raising public concern about privacy. Previous privacy-preserving face recognition methods either require retraining the face recognition model or iterative perturbation that increases inference time. To overcome these limitations, we propose an efficient plug-and-play method that crafts Adaptive Generative perturbations for frozen Face recognition model (AGFace) to defend the reconstruction attacks. To generate perturbation with a single forward for shallow features extracted by frozen recognition model, we learn a Perturbation Generator to efficiently mine the adversarial perturbations by simultaneously minimizing the perturbation and maximizing the reconstruction error of a proxy reconstructor. To achieve privacy-utility trade-off, we propose the Adaptive Channel Selector to identify top-k reconstruction-sensitive channels for the features. By selecting these channels for perturbation, the dominant visual privacy information is protected with reconstruction-insensitive discriminative information preserved. Extensive experiments demonstrate that AGFace achieves state-of-the-art performance in terms of both privacy and utility among retraining-free methods and is comparable to retraining-dependent methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Privacy-Preserving Face Recognition with Adaptive Generative Perturbations

  • Delong Zhang,
  • Yixing Peng,
  • Ancong Wu,
  • Wei-shi Zheng

摘要

For online face recognition services, the potential leakage of facial features and reconstruction techniques gives malicious attackers the opportunity to reconstruct face images, raising public concern about privacy. Previous privacy-preserving face recognition methods either require retraining the face recognition model or iterative perturbation that increases inference time. To overcome these limitations, we propose an efficient plug-and-play method that crafts Adaptive Generative perturbations for frozen Face recognition model (AGFace) to defend the reconstruction attacks. To generate perturbation with a single forward for shallow features extracted by frozen recognition model, we learn a Perturbation Generator to efficiently mine the adversarial perturbations by simultaneously minimizing the perturbation and maximizing the reconstruction error of a proxy reconstructor. To achieve privacy-utility trade-off, we propose the Adaptive Channel Selector to identify top-k reconstruction-sensitive channels for the features. By selecting these channels for perturbation, the dominant visual privacy information is protected with reconstruction-insensitive discriminative information preserved. Extensive experiments demonstrate that AGFace achieves state-of-the-art performance in terms of both privacy and utility among retraining-free methods and is comparable to retraining-dependent methods.