跳到主要导航 跳到搜索 跳到主要内容

Face Encryption via Frequency-Restricted Identity-Agnostic Attacks

  • Xin Dong
  • , Rui Wang*
  • , Siyuan Liang
  • , Aishan Liu
  • , Lihua Jing
  • *此作品的通讯作者
  • CAS - Institute of Information Engineering
  • University of Chinese Academy of Sciences
  • Chinese Academy of Sciences
  • The Institute of Dataspace

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Billions of people are sharing their daily live images on social media everyday. However, malicious collectors use deep face recognition systems to easily steal their biometric information (e.g., faces) from these images. Some studies are being conducted to generate encrypted face photos using adversarial attacks by introducing imperceptible perturbations to reduce face information leakage. However, existing studies need stronger black-box scenario feasibility and more natural visual appearances, which challenge the feasibility of privacy protection. To address these problems, we propose a frequency-restricted identity-agnostic (FRIA) framework to encrypt face images from unauthorized face recognition without access to personal information. As for the weak black-box scenario feasibility, we obverse that representations of the average feature in multiple face recognition models are similar, thus we propose to utilize the average feature via the crawled dataset from the Internet as the target to guide the generation, which is also agnostic to identities of unknown face recognition systems; in nature, the low-frequency perturbations are more visually perceptible by the human vision system. Inspired by this, we restrict the perturbation in the low-frequency facial regions by discrete cosine transform to achieve the visual naturalness guarantee. Extensive experiments on several face recognition models demonstrate that our FRIA outperforms other state-of-the-art methods in generating more natural encrypted faces while attaining high black-box attack success rates of 96%. In addition, we validate the efficacy of FRIA using real-world black-box commercial API, which reveals the potential of FRIA in practice. Our codes can be found in https://github.com/XinDong10/FRIA.

源语言英语
主期刊名MM 2023 - Proceedings of the 31st ACM International Conference on Multimedia
出版商Association for Computing Machinery, Inc
579-588
页数10
ISBN(电子版)9798400701085
DOI
出版状态已出版 - 27 10月 2023
活动31st ACM International Conference on Multimedia, MM 2023 - Ottawa, 加拿大
期限: 29 10月 20233 11月 2023

出版系列

姓名MM 2023 - Proceedings of the 31st ACM International Conference on Multimedia

会议

会议31st ACM International Conference on Multimedia, MM 2023
国家/地区加拿大
Ottawa
时期29/10/233/11/23

学术指纹

探究 'Face Encryption via Frequency-Restricted Identity-Agnostic Attacks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此