Abstract
Sharing personal photos on social media exposes users to unauthorized identity recognition and unconsented model training, raising severe privacy and copyright concerns. Existing methods typically focus on either privacy protection, which misleads recognition models to prevent unauthorized automated recognition, or tracing forensics, which embeds traceable patterns for ownership verification. However, they fail to achieve both simultaneously. The core challenge is to jointly achieve privacy protection and tracing forensics within a single perturbation, since the two objectives rely on different feature behaviors and naive combinations are ineffective in practice. In this work, we propose ATP (Adversarial Tracing Perturbation), a novel perturbation generation method that activates robustness-aware feature channels to balance privacy and traceability. ATP leverages non-robust channel activation to mislead recognition models for privacy protection, while robust channel activation embeds traceable patterns for reliable tracing forensics. Extensive experiments on image classification and face recognition show that ATP achieves strong dual protection, improving overall dual-protection performance by 3.54 × over the baselines while remaining effective under adaptive attacks, thereby demonstrating strong robustness and practical applicability.
| Original language | English |
|---|---|
| Journal | IEEE Transactions on Dependable and Secure Computing |
| DOIs | |
| State | Accepted/In press - 2026 |
Keywords
- Deep learning
- forensics
- privacy
Fingerprint
Dive into the research topics of 'Leveraging Robustness-Aware Channel Activation for Privacy Protection and Tracing Forensics'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver