DiffAM: Diffusion-based Adversarial Makeup Transfer for Facial Privacy Protection

被引:3
|
作者
Sun, Yuhao [1 ]
Yu, Lingyun [1 ]
Xie, Hongtao [1 ]
Li, Jiaming [1 ]
Zhang, Yongdong [1 ]
机构
[1] Univ Sci & Technol China, Hefei, Peoples R China
关键词
D O I
10.1109/CVPR52733.2024.02321
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the rapid development of face recognition (FR) systems, the privacy of face images on social media is facing severe challenges due to the abuse of unauthorized FR systems. Some studies utilize adversarial attack techniques to defend against malicious FR systems by generating adversarial examples. However, the generated adversarial examples, i.e., the protected face images, tend to suffer from subpar visual quality and low transferability. In this paper, we propose a novel face protection approach, dubbed DiffAM, which leverages the powerful generative ability of diffusion models to generate high-quality protected face images with adversarial makeup transferred from reference images. To be specific, we first introduce a makeup removal module to generate non-makeup images utilizing a fine-tuned diffusion model with guidance of textual prompts in CLIP space. As the inverse process of makeup transfer, makeup removal can make it easier to establish the deterministic relationship between makeup domain and non-makeup domain regardless of elaborate text prompts. Then, with this relationship, a CLIP-based makeup loss along with an ensemble attack strategy is introduced to jointly guide the direction of adversarial makeup domain, achieving the generation of protected face images with natural-looking makeup and high black-box transferability. Extensive experiments demonstrate that DiffAM achieves higher visual quality and attack success rates with a gain of 12.98% under black-box setting compared with the state of the arts. The code will be available at https://github.com/HansSunY/DiffAM.
引用
收藏
页码:24584 / 24594
页数:11
相关论文
共 50 条
  • [41] ACGAN: Age-compensated makeup transfer based on homologous continuity generative adversarial network model
    Wu, Guoqiang
    He, Feng
    Zhou, Yuan
    Jing, Yimai
    Ning, Xin
    Wang, Chen
    Jin, Bo
    IET COMPUTER VISION, 2023, 17 (05) : 537 - 548
  • [42] A diffusion-based approximate model for radiation heat transfer in a solar thermochemical reactor
    Dombrovsky, L. A.
    Lipinski, W.
    Steinfeld, A.
    JOURNAL OF QUANTITATIVE SPECTROSCOPY & RADIATIVE TRANSFER, 2007, 103 (03): : 601 - 610
  • [43] FrseGAN: Free-style editable facial makeup transfer based on GAN combined with transformer
    Xu, Weifeng
    Wang, Pengjie
    Yang, Xiaosong
    COMPUTER ANIMATION AND VIRTUAL WORLDS, 2024, 35 (03)
  • [44] DiffProsody: Diffusion-Based Latent Prosody Generation for Expressive Speech Synthesis With Prosody Conditional Adversarial Training
    Oh, Hyung-Seok
    Lee, Sang-Hoon
    Lee, Seong-Whan
    IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2024, 32 : 2654 - 2666
  • [45] Frequency domain-based reversible adversarial attacks for privacy protection in Internet of Things
    Lu, Yang
    Ma, Tianfeng
    Pang, Zilong
    Chai, Xiuli
    Chen, Zhen
    Tang, Zongwei
    JOURNAL OF ELECTRONIC IMAGING, 2024, 33 (04)
  • [46] A Location Trajectory Privacy Protection Method Based on Generative Adversarial Network and Attention Mechanism
    Yang, Xirui
    Zhang, Chen
    Computers, Materials and Continua, 2024, 81 (03): : 3781 - 3804
  • [47] TRANSFER OF CHEMICALS FROM SOIL SOLUTION TO SURFACE RUNOFF - A DIFFUSION-BASED SOIL MODEL
    WALLACH, R
    JURY, WA
    SPENCER, WF
    SOIL SCIENCE SOCIETY OF AMERICA JOURNAL, 1988, 52 (03) : 612 - 618
  • [48] Medical Data Privacy Protection Based On Blockchain Asymmetric Encryption Algorithm And Generative Adversarial Network
    Gao, Yuanyuan
    Kim, Jin-whan
    JOURNAL OF APPLIED SCIENCE AND ENGINEERING, 2025, 28 (09): : 1731 - 1738
  • [49] A Face Occlusion Removal and Privacy Protection Method for IoT Devices Based on Generative Adversarial Networks
    Zhu, Wenqiu
    Wang, Xiaoyi
    Wu, Yuezhong
    Zou, Guang
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [50] D3R-Net: Denoising Diffusion-Based Defense Restore Network for Adversarial Defense in Remote Sensing Scene Classification
    Liu, Xuehu
    Feng, Zhixi
    Ma, Yue
    Yang, Shuyuan
    Chang, Zhihao
    Jiao, Licheng
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62