计算机科学
对抗制
计算机安全
稳健性(进化)
编码器
人工智能
嵌入
信息隐私
特征(语言学)
特征提取
灵活性(工程)
面子(社会学概念)
身份(音乐)
源代码
编码(集合论)
利用
机器学习
面部识别系统
特征学习
计算机视觉
对手
特征向量
生物识别
自编码
鉴定(生物学)
深度学习
模型攻击
解码方法
隐写术
对抗性机器学习
数据挖掘
认证(法律)
数字水印
作者
Haobo Wang,Weiqi Luo,Xiaohua Xie,Peijia Zheng,Wenmin Huang,Jiwu Huang
标识
DOI:10.1109/tifs.2025.3625635
摘要
With the rapid advancement of deep face recognition (FR) systems, concerns over the unauthorized use of facial data have become increasingly serious. Although adversarial attacks have been employed to obscure identity information and protect user privacy, existing methods often struggle with degraded visual quality, low success rates in black-box attacks, and dependence on identity-specific training. To overcome these limitations, we introduce Adv-Inversion, a novel and stealthy adversarial attack technique for facial privacy protection. Our approach leverages an encoder-based GAN inversion framework, incorporating a redesigned feature style encoder to prioritize adversarial attacks over traditional editing tasks. By embedding adversarial perturbations iteratively into the feature tensor space, the method ensures high imperceptibility, robust attack transferability, and flexibility without the need for identity-specific training. Additionally, we introduce an Identity Prior Feature Fusion Module for identity-specific scenarios, enabling alignment between reconstructed and target faces while enhancing black-box attack success through an ensemble training strategy. Extensive experiments across two datasets, four open-source FR models on both face verification and face identification tasks, and two commercial FR APIs demonstrate that Adv-Inversion significantly outperforms related methods in both identity-free and identity-specific training scenarios, achieving state-of-the-art results in attack success rate and visual quality metrics, while also exhibiting robustness against common adversarial defense methods. Multiple ablation studies further confirm the effectiveness of our model design. Our code is available at.
科研通智能强力驱动
Strongly Powered by AbleSci AI