This paper proposes a novel paradigm for facial privacy protection that unifies multiple characteristics including anonymity, diversity, reversibility and security within a single lightweight framework. We name it PRO-Face S, short for Privacy-preserving Reversible Obfuscation of Face images via Secure flow-based model. In the framework, an Invertible Neural Network (INN) is utilized to process the input image along with its pre-obfuscated form, and generate the privacy protected image that visually approximates to the pre-obfuscated one, thus ensuring privacy. The pre-obfuscation applied can be in diversified form with different strengths and styles specified by users. Along protection, a secret key is injected into the network such that the original image can only be recovered from the protection image via the same model given the correct key provided. Two modes of image recovery are devised to deal with malicious recovery attempts in different scenarios. Finally, extensive experiments conducted on three public image datasets demonstrate the superiority of the proposed framework over multiple state-of-the-art approaches.
翻译:本文提出一种面向面部隐私保护的新范式,在单一轻量化框架内统一实现匿名性、多样性、可逆性与安全性等多重特性,命名为PRO-Face S(Privacy-preserving Reversible Obfuscation of Face images via Secure flow-based model)。该框架利用可逆神经网络(INN)对输入图像及其预脱敏版本进行联合处理,生成视觉上近似于预脱敏结果的隐私保护图像,从而确保隐私安全。预脱敏处理可采用用户指定的多种形式,具备差异化的强度与风格。在保护过程中,秘密密钥被注入网络,使得原始图像仅能通过同一模型在提供正确密钥的前提下从保护图像中恢复。针对不同场景下的恶意恢复行为,本文设计了两种图像恢复模式。最后,在三个公开图像数据集上的广泛实验表明,所提框架在性能上优于多种当前最优方法。