跳到主要导航 跳到搜索 跳到主要内容

Leveraging Robustness-Aware Channel Activation for Privacy Protection and Tracing Forensics

  • Haodi Wang
  • , Zihan Wang
  • , Kai Dong
  • , Jiakai Wang
  • , Xianglong Liu
  • , Guangdong Bai*
  • *此作品的通讯作者
  • Southeast University, Nanjing
  • University of Queensland
  • Zhongguancun Laboratory
  • The University of Hong Kong

科研成果: 期刊稿件文章同行评审

摘要

Sharing personal photos on social media exposes users to unauthorized identity recognition and unconsented model training, raising severe privacy and copyright concerns. Existing methods typically focus on either privacy protection, which misleads recognition models to prevent unauthorized automated recognition, or tracing forensics, which embeds traceable patterns for ownership verification. However, they fail to achieve both simultaneously. The core challenge is to jointly achieve privacy protection and tracing forensics within a single perturbation, since the two objectives rely on different feature behaviors and naive combinations are ineffective in practice. In this work, we propose ATP (Adversarial Tracing Perturbation), a novel perturbation generation method that activates robustness-aware feature channels to balance privacy and traceability. ATP leverages non-robust channel activation to mislead recognition models for privacy protection, while robust channel activation embeds traceable patterns for reliable tracing forensics. Extensive experiments on image classification and face recognition show that ATP achieves strong dual protection, improving overall dual-protection performance by 3.54 × over the baselines while remaining effective under adaptive attacks, thereby demonstrating strong robustness and practical applicability.

指纹

探究 'Leveraging Robustness-Aware Channel Activation for Privacy Protection and Tracing Forensics' 的科研主题。它们共同构成独一无二的指纹。

引用此