[论文解读] Unsupervised Enhancement of Soft-biometric Privacy with Negative Face Recognition
本文提出负向人脸识别(NFR),一种无监督方法,通过仅存储与真实人脸特征互补的负向特征模板,而非真实模板,来增强软生物特征隐私。通过将探测模板与这些负向参考模板进行比对,该方法抑制了性别、年龄和种族等隐私敏感属性——在非受控条件下实现高达36%的抑制率,同时保持完整的识别性能,优于以往的有监督方法,在隐私保护与准确率方面均表现更优。
Current research on soft-biometrics showed that privacy-sensitive information can be deduced from biometric templates of an individual. Since for many applications, these templates are expected to be used for recognition purposes only, this raises major privacy issues. Previous works focused on supervised privacy-enhancing solutions that require privacy-sensitive information about individuals and limit their application to the suppression of single and pre-defined attributes. Consequently, they do not take into account attributes that are not considered in the training. In this work, we present Negative Face Recognition (NFR), a novel face recognition approach that enhances the soft-biometric privacy on the template-level by representing face templates in a complementary (negative) domain. While ordinary templates characterize facial properties of an individual, negative templates describe facial properties that does not exist for this individual. This suppresses privacy-sensitive information from stored templates. Experiments are conducted on two publicly available datasets captured under controlled and uncontrolled scenarios on three privacy-sensitive attributes. The experiments demonstrate that our proposed approach reaches higher suppression rates than previous work, while maintaining higher recognition performances as well. Unlike previous works, our approach does not require privacy-sensitive labels and offers a more comprehensive privacy-protection not limited to pre-defined attributes.
研究动机与目标
- 解决生物特征模板泄露软生物特征属性(如性别、年龄和种族)导致的隐私泄露问题。
- 克服有监督方法的局限性,后者需要隐私标注的训练数据,且仅限于预定义的属性。
- 设计一种对自适应功能蔓延攻击具有鲁棒性的隐私保护人脸识别系统。
- 在抑制非预期属性推断的同时,保持高人脸识别性能。
- 提供一种模板级别的无监督解决方案,具备不可逆性、可撤销性和不可关联性。
提出的方法
- 该方法引入负向人脸模板,通过基于深度特征k均值聚类的二值化策略,表示个体不存在的面部特征。
- 使用学习到的量化函数将人脸模板编码为二进制码,k=3或k=4个区间,以在抑制效果与性能之间取得平衡。
- 通过将正向探测模板与负向参考模板进行比对实现识别,利用理论得分分布模型确保可靠性。
- 建立理论框架以建模负向-正向比对空间中的期望得分分布,并在两个数据集上进行实证验证。
- 采用互补表示:正向模板描述实际面部属性,而负向模板仅编码不存在的、随机的互补特征。
- 系统在无需任何隐私敏感标签的情况下进行训练,因此为无监督方法,可扩展至未预定义的属性。
实验结果
研究问题
- RQ1无监督方法是否能在不依赖隐私标注数据的情况下,从人脸模板中抑制隐私敏感属性?
- RQ2在受控与非受控图像条件下,负向人脸识别在抑制性别、年龄和种族属性方面的有效性如何?
- RQ3该方法是否能在实现强属性抑制的同时保持高人脸识别准确率?
- RQ4面对已知晓隐私机制的自适应功能蔓延攻击者,系统表现如何?
- RQ5模板二值化区间数(k)与识别性能和属性抑制之间理论与实证关系为何?
主要发现
- 所提出的NFR方法在非受控场景下实现高达36%的隐私敏感属性抑制率,显著优于以往的有监督方法。
- 在非受控条件下,NFR在保持100%验证准确率的同时,比以往方法更有效地抑制属性。
- 该方法在多种属性和攻击模型下,抑制率比先前工作高出2至4倍,即使攻击者适应系统机制也依然有效。
- 理论得分预测模型在ColorFeret和Adience数据集上的实证得分分布中表现高度一致,验证了方法的理论基础。
- 最优区间数为k=3,可在高属性抑制与低验证错误之间实现最佳平衡;k=4则表现出更高波动性与性能下降。
- 该方法为无监督,无需隐私标注数据,可实现对预定义属性之外的全面保护。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。