Reversing Deep Face Embeddings with Probable Privacy Protection
- URL: http://arxiv.org/abs/2310.03005v1
- Date: Wed, 4 Oct 2023 17:48:23 GMT
- Title: Reversing Deep Face Embeddings with Probable Privacy Protection
- Authors: Daile Osorio-Roig, Paul A. Gerlitz, Christian Rathgeb, and Christoph
Busch
- Abstract summary: State-of-the-art face image reconstruction approach has been evaluated on protected face embeddings to break soft biometric privacy protection.
Results show that biometric privacy-enhanced face embeddings can be reconstructed with an accuracy of up to approximately 98%.
- Score: 6.492755549391469
- License: http://creativecommons.org/licenses/by/4.0/
- Abstract: Generally, privacy-enhancing face recognition systems are designed to offer
permanent protection of face embeddings. Recently, so-called soft-biometric
privacy-enhancement approaches have been introduced with the aim of canceling
soft-biometric attributes. These methods limit the amount of soft-biometric
information (gender or skin-colour) that can be inferred from face embeddings.
Previous work has underlined the need for research into rigorous evaluations
and standardised evaluation protocols when assessing privacy protection
capabilities. Motivated by this fact, this paper explores to what extent the
non-invertibility requirement can be met by methods that claim to provide
soft-biometric privacy protection. Additionally, a detailed vulnerability
assessment of state-of-the-art face embedding extractors is analysed in terms
of the transformation complexity used for privacy protection. In this context,
a well-known state-of-the-art face image reconstruction approach has been
evaluated on protected face embeddings to break soft biometric privacy
protection. Experimental results show that biometric privacy-enhanced face
embeddings can be reconstructed with an accuracy of up to approximately 98%,
depending on the complexity of the protection algorithm.
Related papers
- Enhancing Privacy in Face Analytics Using Fully Homomorphic Encryption [8.742970921484371]
We propose a novel technique that combines Fully Homomorphic Encryption (FHE) with an existing template protection scheme known as PolyProtect.
Our proposed approach ensures irreversibility and unlinkability, effectively preventing the leakage of soft biometric embeddings.
arXiv Detail & Related papers (2024-04-24T23:56:03Z) - Privacy-preserving Optics for Enhancing Protection in Face De-identification [60.110274007388135]
We propose a hardware-level face de-identification method to solve this vulnerability.
We also propose an anonymization framework that generates a new face using the privacy-preserving image, face heatmap, and a reference face image from a public dataset as input.
arXiv Detail & Related papers (2024-03-31T19:28:04Z) - Diff-Privacy: Diffusion-based Face Privacy Protection [58.1021066224765]
In this paper, we propose a novel face privacy protection method based on diffusion models, dubbed Diff-Privacy.
Specifically, we train our proposed multi-scale image inversion module (MSI) to obtain a set of SDM format conditional embeddings of the original image.
Based on the conditional embeddings, we design corresponding embedding scheduling strategies and construct different energy functions during the denoising process to achieve anonymization and visual identity information hiding.
arXiv Detail & Related papers (2023-09-11T09:26:07Z) - Privacy-Preserving Face Recognition Using Random Frequency Components [46.95003101593304]
Face recognition has sparked increasing privacy concerns.
We propose to conceal visual information by pruning human-perceivable low-frequency components.
We distill our findings into a novel privacy-preserving face recognition method, PartialFace.
arXiv Detail & Related papers (2023-08-21T04:31:02Z) - CLIP2Protect: Protecting Facial Privacy using Text-Guided Makeup via
Adversarial Latent Search [10.16904417057085]
Deep learning based face recognition systems can enable unauthorized tracking of users in the digital world.
Existing methods for enhancing privacy fail to generate naturalistic images that can protect facial privacy without compromising user experience.
We propose a novel two-step approach for facial privacy protection that relies on finding adversarial latent codes in the low-dimensional manifold of a pretrained generative model.
arXiv Detail & Related papers (2023-06-16T17:58:15Z) - PrivacyProber: Assessment and Detection of Soft-Biometric
Privacy-Enhancing Techniques [1.790445868185437]
We study the robustness of several state-of-the-art soft-biometric privacy-enhancing techniques to attribute recovery attempts.
We propose PrivacyProber, a high-level framework for restoring soft-biometric information from privacy-enhanced facial images.
arXiv Detail & Related papers (2022-11-16T12:20:18Z) - Privacy-Preserving Face Recognition with Learnable Privacy Budgets in
Frequency Domain [77.8858706250075]
This paper proposes a privacy-preserving face recognition method using differential privacy in the frequency domain.
Our method performs very well with several classical face recognition test sets.
arXiv Detail & Related papers (2022-07-15T07:15:36Z) - OPOM: Customized Invisible Cloak towards Face Privacy Protection [58.07786010689529]
We investigate the face privacy protection from a technology standpoint based on a new type of customized cloak.
We propose a new method, named one person one mask (OPOM), to generate person-specific (class-wise) universal masks.
The effectiveness of the proposed method is evaluated on both common and celebrity datasets.
arXiv Detail & Related papers (2022-05-24T11:29:37Z) - An Attack on Feature Level-based Facial Soft-biometric Privacy
Enhancement [13.780253190395715]
We introduce an attack on feature level-based facial soft-biometric privacy-enhancement techniques.
It is able to circumvent the privacy enhancement to a considerable degree and is able to correctly classify gender with an accuracy of up to approximately 90%.
arXiv Detail & Related papers (2021-11-24T10:41:15Z) - Towards Face Encryption by Generating Adversarial Identity Masks [53.82211571716117]
We propose a targeted identity-protection iterative method (TIP-IM) to generate adversarial identity masks.
TIP-IM provides 95%+ protection success rate against various state-of-the-art face recognition models.
arXiv Detail & Related papers (2020-03-15T12:45:10Z) - Unsupervised Enhancement of Soft-biometric Privacy with Negative Face
Recognition [13.555831336280407]
We present Negative Face Recognition (NFR), a novel face recognition approach that enhances the soft-biometric privacy on the template-level.
Our approach does not require privacy-sensitive labels and offers a more comprehensive privacy-protection not limited to pre-defined attributes.
arXiv Detail & Related papers (2020-02-21T08:37:16Z)
This list is automatically generated from the titles and abstracts of the papers in this site.
This site does not guarantee the quality of this site (including all information) and is not responsible for any consequences.