Adv-Inversion: Stealthy Adversarial Attacks via GAN-Inversion for Facial Privacy Protection

计算机科学 对抗制 计算机安全 稳健性(进化) 编码器 人工智能 嵌入 信息隐私 特征(语言学) 特征提取 灵活性(工程) 面子(社会学概念) 身份(音乐) 源代码 编码(集合论) 利用 机器学习 面部识别系统 特征学习 计算机视觉 对手 特征向量 生物识别 自编码 鉴定(生物学) 深度学习 模型攻击 解码方法 隐写术 对抗性机器学习 数据挖掘 认证(法律) 数字水印
作者
Haobo Wang,Weiqi Luo,Xiaohua Xie,Peijia Zheng,Wenmin Huang,Jiwu Huang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:20: 11892-11906 被引量:1
标识
DOI:10.1109/tifs.2025.3625635
摘要

With the rapid advancement of deep face recognition (FR) systems, concerns over the unauthorized use of facial data have become increasingly serious. Although adversarial attacks have been employed to obscure identity information and protect user privacy, existing methods often struggle with degraded visual quality, low success rates in black-box attacks, and dependence on identity-specific training. To overcome these limitations, we introduce Adv-Inversion, a novel and stealthy adversarial attack technique for facial privacy protection. Our approach leverages an encoder-based GAN inversion framework, incorporating a redesigned feature style encoder to prioritize adversarial attacks over traditional editing tasks. By embedding adversarial perturbations iteratively into the feature tensor space, the method ensures high imperceptibility, robust attack transferability, and flexibility without the need for identity-specific training. Additionally, we introduce an Identity Prior Feature Fusion Module for identity-specific scenarios, enabling alignment between reconstructed and target faces while enhancing black-box attack success through an ensemble training strategy. Extensive experiments across two datasets, four open-source FR models on both face verification and face identification tasks, and two commercial FR APIs demonstrate that Adv-Inversion significantly outperforms related methods in both identity-free and identity-specific training scenarios, achieving state-of-the-art results in attack success rate and visual quality metrics, while also exhibiting robustness against common adversarial defense methods. Multiple ablation studies further confirm the effectiveness of our model design. Our code is available at.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
梦幻时空完成签到,获得积分10
4秒前
timesever完成签到,获得积分10
8秒前
lilycat完成签到,获得积分10
9秒前
12秒前
2316690509完成签到 ,获得积分10
12秒前
回首不再是少年完成签到,获得积分0
13秒前
13秒前
14秒前
落叶捎来讯息完成签到 ,获得积分10
15秒前
沉静幻天发布了新的文献求助10
18秒前
初景发布了新的文献求助10
21秒前
21秒前
月上柳梢头A1完成签到,获得积分10
28秒前
28秒前
小机灵发布了新的文献求助10
32秒前
鹿邑完成签到 ,获得积分10
32秒前
德芙应助timesever采纳,获得10
33秒前
沉静幻天完成签到,获得积分10
36秒前
eternal_dreams完成签到 ,获得积分10
38秒前
40秒前
爆米花应助科研通管家采纳,获得30
44秒前
nicky完成签到 ,获得积分10
45秒前
45秒前
认真的不评应助ping采纳,获得20
46秒前
陈M雯完成签到 ,获得积分10
49秒前
DZZH完成签到 ,获得积分10
50秒前
高级丹药师完成签到,获得积分10
54秒前
俭朴从安完成签到,获得积分10
54秒前
55秒前
55秒前
58秒前
真实的天空完成签到 ,获得积分10
1分钟前
1分钟前
顶钻师完成签到 ,获得积分10
1分钟前
Rqbnicsp完成签到,获得积分10
1分钟前
尘埃完成签到,获得积分10
1分钟前
青龙大帝发布了新的文献求助10
1分钟前
shilly完成签到 ,获得积分10
1分钟前
墨z完成签到 ,获得积分10
1分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
日本現代怪異事典 副読本 700
悉尼大学博士学位论文,题目:Modelling and testing of one-sided stitched laminated composites. 作者:Kristopher P. Plain 650
Machine Learning for Asset Management and Pricing 600
Numerical analysis of the coupled atmosphere-ocean models (CAO II). II 600
Models for the coupled atmosphere and ocean 600
Évora na Idade Média 555
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7384650
求助须知:如何正确求助?哪些是违规求助? 8991530
关于积分的说明 19126110
捐赠科研通 7022278
什么是DOI,文献DOI怎么找? 3227391
关于科研通互助平台的介绍 2390416
邀请新用户注册赠送积分活动 2208519