paper-with-me

Papers

DiffProtect: Generate Adversarial Examples with Diffusion Models for Facial Privacy Protection

2023-05-23 · Jiang Liu, Chun Pong Lau, Rama Chellappa

The increasingly pervasive facial recognition (FR) systems raise serious concerns about personal privacy, especially for billions of users who have publicly shared their photos on social media. Several attempts have been made to protect individuals from being identified by unauthorized FR systems utilizing adversarial attacks to generate encrypted face images. However, existing methods suffer from poor visual quality or low attack success rates, which limit their utility. Recently, diffusion models have achieved tremendous success in image generation. In this work, we ask: can diffusion models be used to generate adversarial examples to improve both visual quality and attack performance? We propose DiffProtect, which utilizes a diffusion autoencoder to generate semantically meaningful perturbations on FR systems. Extensive experiments demonstrate that DiffProtect produces more natural-looking encrypted images than state-of-the-art methods while achieving significantly higher attack success rates, e.g., 24.5% and 25.1% absolute improvements on the CelebA-HQ and FFHQ datasets.

📄 PDF Abstract BibTeX arXiv:2305.13625

Code (1)

joellliu/diffprotect 공식 구현 pytorch

Tasks

Image Generation

Methods 이 논문이 사용한 방법론

Diffusion Diffusion models generate samples by gradually removing noise from a signal, and their training objective can be expressed as a reweighted variational lower-bound…

Similar Papers 제목 키워드 기반

Using a GAN to Generate Adversarial Examples to Facial Image Recognition

2021-11-30 · Andrew Merrigan, Alan F. Smeaton

Images posted online present a privacy concern in that they may be used as reference examples for a facial recognition system. Such abuse of images is in violation of privacy rights but is difficult to counter. It is wel…

Face RecognitionGenerative Adversarial NetworkKnowledge Distillation

Diffusion-Driven Deceptive Patches: Adversarial Manipulation and Forensic Detection in Facial Identity Verification

2026-01-14 · Shahrzad Sayyafzadeh, Hongmei Chi, Shonda Bernadin arxiv

This work presents an end-to-end pipeline for generating, refining, and evaluating adversarial patches to compromise facial biometric systems, with applications in forensic analysis and security testing. We utilize FGSM …

DiffAM: Diffusion-based Adversarial Makeup Transfer for Facial Privacy Protection

2024-05-16 · CVPR 2024 1 · Yuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li 외

With the rapid development of face recognition (FR) systems, the privacy of face images on social media is facing severe challenges due to the abuse of unauthorized FR systems. Some studies utilize adversarial attack tec…

Adversarial AttackFace Recognition

Information-containing Adversarial Perturbation for Combating Facial Manipulation Systems

2023-03-21 · Yao Zhu, Yuefeng Chen, Xiaodan Li, Rong Zhang 외

With the development of deep learning technology, the facial manipulation system has become powerful and easy to use. Such systems can modify the attributes of the given facial images, such as hair color, gender, and age…

Fake Image Detection

Diffusion-based Adversarial Identity Manipulation for Facial Privacy Protection

2025-04-30 · Liqin Wang, Qianyue Hu, Wei Lu, Xiangyang Luo

The success of face recognition (FR) systems has led to serious privacy concerns due to potential unauthorized surveillance and user tracking on social networks. Existing methods for enhancing privacy fail to generate na…

Face RecognitionFace Verification