Adversarial attacks cause identity leaks in face de-identification systems
Adversarial Attacks and Identity Leakage in De-Identification Systems: An Empirical Study
Computer Vision and Pattern Recognition
Summary
Facial recognition systems that try to hide a person’s identity can still accidentally reveal it if they face subtle, tricky changes called adversarial attacks. The authors show that attacks made using one system can also fool another, exposing private identity details. They found ways to reduce this risk by training the system to resist these attacks and by filtering out harmful noise without messing up the anonymized images. This makes face de-identification safer without losing its purpose.
What this means in practice
- •For security engineers: Improve privacy protection in face anonymization systems by integrating adversarial training and noise filtering to prevent identity leaks.
- •For surveillance system operators: Enhance the robustness of facial anonymization in surveillance footage against attacks that could reveal private identity information.
Authors
Felix Rosberg, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez
Abstract
In this paper, we investigate the impact of adversarial attacks on identity encoders within a realistic de-identification framework. Our experiments show that the transferability of attacks transfers from an external surrogate model to the system model (e.g., CosFace to ArcFace) allows the adversary to cause identity information to leak in a sufficiently sensitive face recognition system. We present experimental evidence and propose strategies to mitigate this vulnerability. Specifically, we show how fine-tuning on adversarial examples helps to mitigate this effect for distortion-based attacks (i.e., snow, fog, etc.), while a simple low-pass filter can attenuate the effect of adversarial noise without affecting the de-identified images. Our mitigation results in a de-identification system that preserves its functionality while being significantly more robust to adversarial noise.