DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark
Yunming Zhang, Dengpan Ye, Caiyun Xie, Sipeng Shen, Ziyi Liu, Jiacheng, Deng, Long Tang

TL;DR
DIP-Watermark introduces a novel double identity protection scheme using traceable adversarial watermarking to deceive unauthorized face recognition systems while enabling trusted verification, enhancing privacy protection against adversarial attacks.
Contribution
It is the first to combine adversarial attack and watermarking for double identity protection in face recognition, with a novel collaborative meta-optimization strategy for robust watermark embedding.
Findings
Achieves high attack success rates on state-of-the-art FR models.
Maintains high traceability accuracy for authorized identity verification.
Outperforms existing privacy protection methods in robustness and effectiveness.
Abstract
The wide deployment of Face Recognition (FR) systems poses privacy risks. One countermeasure is adversarial attack, deceiving unauthorized malicious FR, but it also disrupts regular identity verification of trusted authorizers, exacerbating the potential threat of identity impersonation. To address this, we propose the first double identity protection scheme based on traceable adversarial watermarking, termed DIP-Watermark. DIP-Watermark employs a one-time watermark embedding to deceive unauthorized FR models and allows authorizers to perform identity verification by extracting the watermark. Specifically, we propose an information-guided adversarial attack against FR models. The encoder embeds an identity-specific watermark into the deep feature space of the carrier, guiding recognizable features of the image to deviate from the source identity. We further adopt a collaborative…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Steganography and Watermarking Techniques · Biometric Identification and Security · Face recognition and analysis
MethodsDeterministic Policy Gradient
