Enhancing Facial Privacy Protection via Weakening Diffusion Purification

  • 2025-03-13 13:27:53
  • Ali Salar, Qing Liu, Yingli Tian, Guoying Zhao
  • 0

Abstract

The rapid growth of social media has led to the widespread sharing ofindividual portrait images, which pose serious privacy risks due to thecapabilities of automatic face recognition (AFR) systems for mass surveillance.Hence, protecting facial privacy against unauthorized AFR systems is essential.Inspired by the generation capability of the emerging diffusion models, recentmethods employ diffusion models to generate adversarial face images for privacyprotection. However, they suffer from the diffusion purification effect,leading to a low protection success rate (PSR). In this paper, we first proposelearning unconditional embeddings to increase the learning capacity foradversarial modifications and then use them to guide the modification of theadversarial latent code to weaken the diffusion purification effect. Moreover,we integrate an identity-preserving structure to maintain structuralconsistency between the original and generated images, allowing human observersto recognize the generated image as having the same identity as the original.Extensive experiments conducted on two public datasets, i.e., CelebA-HQ andLADN, demonstrate the superiority of our approach. The protected facesgenerated by our method outperform those produced by existing facial privacyprotection approaches in terms of transferability and natural appearance.