The success of deep learning based face recognition systems has given rise to serious privacy concerns due to their ability to enable unauthorized tracking of users in the digital world. Existing methods for enhancing privacy fail to generate naturalistic images that can protect facial privacy without compromising user experience. We propose a novel two-step approach for facial privacy protection that relies on finding adversarial latent codes in the low-dimensional manifold of a pretrained generative model. The first step inverts the given face image into the latent space and finetunes the generative model to achieve an accurate reconstruction of the given image from its latent code. This step produces a good initialization, aiding the generation of high-quality faces that resemble the given identity. Subsequently, user-defined makeup text prompts and identity-preserving regularization are used to guide the search for adversarial codes in the latent space. Extensive experiments demonstrate that faces generated by our approach have stronger black-box transferability with an absolute gain of 12.06% over the state-of-the-art facial privacy protection approach under the face verification task. Finally, we demonstrate the effectiveness of the proposed approach for commercial face recognition systems. Our code is available at https://github.com/fahadshamshad/Clip2Protect.
翻译:基于深度学习的面部识别系统的成功引发了严重的隐私担忧,因为其能够在数字世界中实现未经授权的用户追踪。现有增强隐私的方法无法生成既能保护面部隐私又不影响用户体验的自然图像。我们提出了一种新颖的两步面部隐私保护方法,该方法依赖于在预训练生成模型的低维流形中寻找对抗性潜在编码。第一步将给定人脸图像反演到潜在空间,并微调生成模型,以从其潜在编码实现对给定图像的精确重建。此步骤提供了良好的初始化,有助于生成与给定身份相似的高质量人脸。随后,使用用户定义的妆容文本提示和身份保持正则化来引导潜在空间中对对抗性编码的搜索。大量实验证明,我们的方法生成的人脸具有更强的黑盒迁移性,在人脸验证任务上比最先进的面部隐私保护方法绝对提升了12.06%。最后,我们展示了所提方法在商业人脸识别系统中的有效性。我们的代码可在 https://github.com/fahadshamshad/Clip2Protect 获取。