Privacy-Preserving Face Recognition Using Trainable Feature Subtraction
About
The widespread adoption of face recognition has led to increasing privacy concerns, as unauthorized access to face images can expose sensitive personal information. This paper explores face image protection against viewing and recovery attacks. Inspired by image compression, we propose creating a visually uninformative face image through feature subtraction between an original face and its model-produced regeneration. Recognizable identity features within the image are encouraged by co-training a recognition model on its high-dimensional feature representation. To enhance privacy, the high-dimensional representation is crafted through random channel shuffling, resulting in randomized recognizable images devoid of attacker-leverageable texture details. We distill our methodologies into a novel privacy-preserving face recognition method, MinusFace. Experiments demonstrate its high recognition accuracy and effective privacy protection. Its code is available at https://github.com/Tencent/TFace.
Related benchmarks
| Task | Dataset | Result | Rank | |
|---|---|---|---|---|
| Face Verification | CPLFW | Accuracy91.9 | 188 | |
| Face Recognition | CFP-FP | Accuracy96.92 | 66 | |
| Face Recognition | LFW | Accuracy99.78 | 47 | |
| Face Recognition | AgeDB | Accuracy97.57 | 33 | |
| Face Recognition | CALFW | Accuracy95.9 | 23 | |
| Face Recognition | IJB-C | TAR (FAR=1e-4)94.7 | 19 | |
| Face Recognition | IJB-B | TAR @ FAR=1e-493.37 | 19 | |
| Face Representation Storage Efficiency | Face Representation Storage Efficiency | Storage Size1 | 6 | |
| Identity Protection Evaluation | Set (test) | Protection (FracFace)85 | 3 |