Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

CLIP2Protect: Protecting Facial Privacy using Text-Guided Makeup via Adversarial Latent Search

About

The success of deep learning based face recognition systems has given rise to serious privacy concerns due to their ability to enable unauthorized tracking of users in the digital world. Existing methods for enhancing privacy fail to generate naturalistic images that can protect facial privacy without compromising user experience. We propose a novel two-step approach for facial privacy protection that relies on finding adversarial latent codes in the low-dimensional manifold of a pretrained generative model. The first step inverts the given face image into the latent space and finetunes the generative model to achieve an accurate reconstruction of the given image from its latent code. This step produces a good initialization, aiding the generation of high-quality faces that resemble the given identity. Subsequently, user-defined makeup text prompts and identity-preserving regularization are used to guide the search for adversarial codes in the latent space. Extensive experiments demonstrate that faces generated by our approach have stronger black-box transferability with an absolute gain of 12.06% over the state-of-the-art facial privacy protection approach under the face verification task. Finally, we demonstrate the effectiveness of the proposed approach for commercial face recognition systems. Our code is available at https://github.com/fahadshamshad/Clip2Protect.

Fahad Shamshad, Muzammal Naseer, Karthik Nandakumar• 2023

Related benchmarks

TaskDatasetResultRank
Face IdentificationLFW (test)
Rank-1 PSR86.6
60
Face VerificationFFHQ
ASR (IR152)52.12
42
Black-box AttackCelebA-HQ
IRSE50 Score81.1
32
Face RecognitionLFW (test)
Rank-1 PSR39
20
Face VerificationCelebA-HQ
ASR (IR152)0.4763
19
Image Quality EvaluationCelebA-HQ
FID26.1272
16
Facial Privacy ProtectionFFHQ and CelebA-HQ
FID26.1272
10
Face VerificationCelebA-HQ
PSR (IRSE50)81.1
9
Face VerificationLADN-Dataset
PSR (IRSE50)91.57
9
Black-box AttackLADN-Dataset
IRSE5091.57
9
Showing 10 of 13 rows

Other info

Code

Follow for update