日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
顔匿名化arXiv:2609.27011

HYDRO: 高忠実度ハイブリッド拡散とターゲット指向アプローチによる非可逆的な顔匿名化

HYDRO: Towards Non-Reversible Face De-Identification Using a High-Fidelity Hybrid Diffusion and Target-Oriented Approach

シェア:XThreadsFacebookLINEはてブBluesky

ターゲット指向の顔匿名化に拡散モデルを組み合わせ、復元攻撃を防ぐ非可逆的な匿名化手法を提案。

詳しい要約

1. どんなもの?

- 本論文は、対象人物の顔画像を匿名化する target-oriented face de-identification モデル HYDRO を提案する。 - 従来の target-oriented モデルは、生成エンコーダ・デコーダで顔の外観を操作し、高忠実度で属性を保持するが、微妙な identity cue が残り、再構築攻撃に対して可逆的であるリスクがある。 - HYDRO は target-oriented モデルと専用の diffusion process を組み合わせ、de-identification 手順を逆学習される可能性のある不可視情報を破壊する。 - 具体的には、顔画像を de-identify し、ノイズを注入して再構築を妨害し、diffusion-based recovery step で忠実度を改善し、データ特性へのノイズ影響を最小化する。 - さらに、Eye Similarity Discriminator (ESD) を導入し、画像忠実度と視線方向の保持を向上させる。

2. 先行研究と比べてどこがすごい?

- 従来の target-oriented face de-identification モデルは、生成エンコーダ・デコーダにより高忠実度で属性を保持するが、微妙な identity cue を保持し、再構築攻撃に対して可逆的である可能性があった。 - HYDRO は、target-oriented モデルに diffusion process を組み合わせることで、再構築攻撃に対して耐性を持つ初の target-oriented 手法である。 - 3つの多様なデータセットでの実験で、HYDRO は SOTA の忠実度と属性保持能力を示し、複数の SOTA 競合手法と比較して再構築攻撃の成功率を平均 85.7% 削減する。

3. 技術・手法の肝は?

- HYDRO は、target-oriented モデルで顔画像を de-identify した後、ノイズを注入して再構築を妨害する。 - 次に、diffusion-based recovery step を適用し、忠実度を改善し、ノイズがデータ特性に与える影響を最小化する。 - さらに、Eye Similarity Discriminator (ESD) を導入し、訓練に組み込むことで、画像忠実度と視線方向の保持を向上させる。 - これにより、不可視情報を破壊しつつ、高忠実度と属性保持を両立する。

4. どうやって有効だと検証した?

- 3つの多様なデータセットで定量的・定性的実験を実施。 - HYDRO は SOTA の忠実度と属性保持能力を示し、再構築攻撃に対して耐性を持つ唯一の target-oriented 手法である。 - 複数の SOTA 競合手法と比較して、再構築攻撃の成功率を平均 85.7% 削減した。

5. 議論はある?

- 要旨からは不明。

6. 次に読むべき論文は?

- 要旨で参照/比較されている研究や関連手法は明示されていない。同分野の定番として、target-oriented face de-identification モデル、generative encoder-decoder architectures、diffusion models、reconstruction attacks に関する論文が挙げられる。

※ AIが要旨から生成した要約です。正確性は原文をご確認ください。

著者: Felix Rosberg, Vitomir Štruc, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez

分類: cs.CV

原文アブストラクト

Target-oriented face de-identification models aim to anonymize the identity of a target individual across different images or video frames, such that the target can no longer be reliably recognized, while maintaining key characteristics of the visual data. Such models commonly leverage generative encoder-decoder architectures to manipulate facial appearances, enabling them to produce realistic high-fidelity de-identification results, while ensuring considerable attribute-retention capabilities. However, target-oriented models also carry the risk of inadvertently preserving subtle identity cues, making them (potentially) reversible and susceptible to reconstruction attacks. To address this problem, we introduce in this paper a novel (robust) face de-identification approach, called HYDRO, that combines target-oriented models with a dedicated diffusion process specifically designed to destroy any imperceptible information that may allow learning to reverse the de-identification procedure. HYDRO first de-identifies the given face image, injects noise into the de-identification result to impede reconstruction, and then applies a diffusion-based recovery step to improve fidelity and minimize the impact of the noising process on the data characteristics. To further improve image fidelity and better retain gaze directions, a novel Eye Similarity Discriminator (ESD) is also introduced and incorporated it into the training of HYDRO. Extensive quantitative and qualitative experiments on three diverse datasets demonstrate that HYDRO exhibits state-of-the-art (SOTA) fidelity and attribute-retention capabilities, while being the only target-oriented method resilient against reconstruction attacks. In comparison to multiple SOTA competitors, HYDRO reduces the success of reconstruction attacks by 85.7% on average.

PR本紙発行元 EmplifAI