跳到正文
返回论文列表
cs.CV提交于 已译

人脸去标识化到底有多隐私?一项对比研究

How Private is Private? A Comparative Study for Face De-Identification

Hui Wei · Hao Yu · Hui Kuurila-Zhang · Guoying Zhao

中文摘要

人脸去标识化(FDeID)已成为关键的隐私保护技术,但对其评估仍十分碎片化。现有评测协议在指标、数据集和标注覆盖度上彼此不一致,导致面向不同效用维度(如关键点与表情保持)的方法在不同基准与不同指标下被报告,方法间无法横向比较。本文从数据与指标两方面重新审视 FDeID 评估。在数据侧,提出 UtilFace:一个经过身份感知清洗、超分辨率增强与分层筛选而构建的人脸基准,具有人口统计学均衡、身份多样度高的特点,整合自四个大规模人脸数据集。在指标侧,提出 HiFD,一种分层人脸去标识化指标。该指标在一致性范式下统一身份抑制、多层级效用保持与图像质量:每个组件由预训练估计器在原始人脸与其去标识化版本上的输出计算,直接量化身份被抑制的程度以及下游可感知效用保留的程度。HiFD 将面部信号组织为三级效用层次:宏观线索(L1)、微观线索(L2)与不可感知线索(L3),并通过加权调和均值将五个组件聚合为单一可解释分数,支持面向应用的可配置加权。基于该统一协议,对对抗式、GAN 式与扩散式方法开展全面对比研究,揭示在现有协议下不可见的权衡关系与失败模式。基准与评测工具包均已开源,以促进隐私保护人脸分析领域系统、可复现的研究。

关键要点

  1. 01现有 FDeID 评测协议在指标、数据集与标注上不一致,导致不同方法无法横向比较。
  2. 02在数据侧发布 UtilFace 基准,整合四个大规模数据集,经身份感知清洗与超分辨率增强,人口统计学均衡且身份多样。
  3. 03在指标侧提出 HiFD,统一身份抑制、多级效用保持与图像质量,基于预训练估计器在原始与去标识化人脸上的输出一致性计算。
  4. 04HiFD 将效用组织为宏观、微观、不可感知三级,并加权调和聚合为单一可解释分数,支持应用自定义权重。
  5. 05在统一协议下对比对抗式、GAN 式与扩散式方法,揭示现有协议下不可见的权衡与失败模式,并开源基准与工具包。

解读

尚无解读。

原始英文摘要

arXiv:2610.10334v1 Announce Type: new Abstract: Face de-identification (FDeID) has emerged as a critical privacy-preserving technology, yet its evaluation remains fundamentally fragmented. Existing protocols rely on inconsistent metrics, heterogeneous datasets, and partial annotation coverage, so methods targeting different utility dimensions, such as landmark versus expression preservation, are reported on different benchmarks under different metrics, rendering cross-method comparison infeasible. We revisit FDeID evaluation from both the data and metric perspectives. On the data side, we introduce UtilFace, a curated, demographically balanced benchmark with high identity diversity, assembled from four large-scale face datasets through identity-aware cleaning, resolution enhancement, and stratified filtering. On the metric side, we propose HiFD, a Hierarchical Face De-identification metric that unifies identity suppression, multi-level utility preservation, and image quality under a single consistency-based paradigm: every component is computed from pretrained estimators' outputs on the original face and its de-identified counterpart, directly quantifying how much identity is suppressed and how much downstream-perceivable utility survives. HiFD organizes facial signals into a three-level utility hierarchy spanning macro cues (L1), micro cues (L2), and imperceptible cues (L3), and aggregates the five resulting components into a single interpretable score via weighted harmonic mean, with configurable application-specific profiles. Using this unified protocol, we conduct a comprehensive comparative study spanning adversarial, GAN-based, and diffusion-based methods, surfacing trade-offs and failure modes that remain invisible under existing protocols. We release the benchmark and evaluation toolkit to foster systematic and reproducible research in privacy-preserving human face analysis.

同方向论文 · cs.CV

查看全部 →