Enhancing Facial Privacy Protection via Weakening Diffusion Purification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Salar, Ali, Liu, Qing, Tian, Yingli, Zhao, Guoying
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910873973424128
author Salar, Ali
Liu, Qing
Tian, Yingli
Zhao, Guoying
author_facet Salar, Ali
Liu, Qing
Tian, Yingli
Zhao, Guoying
contents The rapid growth of social media has led to the widespread sharing of individual portrait images, which pose serious privacy risks due to the capabilities of automatic face recognition (AFR) systems for mass surveillance. Hence, protecting facial privacy against unauthorized AFR systems is essential. Inspired by the generation capability of the emerging diffusion models, recent methods employ diffusion models to generate adversarial face images for privacy protection. However, they suffer from the diffusion purification effect, leading to a low protection success rate (PSR). In this paper, we first propose learning unconditional embeddings to increase the learning capacity for adversarial modifications and then use them to guide the modification of the adversarial latent code to weaken the diffusion purification effect. Moreover, we integrate an identity-preserving structure to maintain structural consistency between the original and generated images, allowing human observers to recognize the generated image as having the same identity as the original. Extensive experiments conducted on two public datasets, i.e., CelebA-HQ and LADN, demonstrate the superiority of our approach. The protected faces generated by our method outperform those produced by existing facial privacy protection approaches in terms of transferability and natural appearance.
format Preprint
id arxiv_https___arxiv_org_abs_2503_10350
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Enhancing Facial Privacy Protection via Weakening Diffusion Purification
Salar, Ali
Liu, Qing
Tian, Yingli
Zhao, Guoying
Computer Vision and Pattern Recognition
The rapid growth of social media has led to the widespread sharing of individual portrait images, which pose serious privacy risks due to the capabilities of automatic face recognition (AFR) systems for mass surveillance. Hence, protecting facial privacy against unauthorized AFR systems is essential. Inspired by the generation capability of the emerging diffusion models, recent methods employ diffusion models to generate adversarial face images for privacy protection. However, they suffer from the diffusion purification effect, leading to a low protection success rate (PSR). In this paper, we first propose learning unconditional embeddings to increase the learning capacity for adversarial modifications and then use them to guide the modification of the adversarial latent code to weaken the diffusion purification effect. Moreover, we integrate an identity-preserving structure to maintain structural consistency between the original and generated images, allowing human observers to recognize the generated image as having the same identity as the original. Extensive experiments conducted on two public datasets, i.e., CelebA-HQ and LADN, demonstrate the superiority of our approach. The protected faces generated by our method outperform those produced by existing facial privacy protection approaches in terms of transferability and natural appearance.
title Enhancing Facial Privacy Protection via Weakening Diffusion Purification
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2503.10350