DiffAM: Diffusion-based Adversarial Makeup Transfer for Facial Privacy Protection
Yuhao Sun, Lingyun Yu, Hongtao Xie, Jiaming Li, Yongdong Zhang

TL;DR
DiffAM uses diffusion models to create high-quality, adversarially protected face images with natural makeup, enhancing privacy against face recognition systems while maintaining visual quality and transferability.
Contribution
The paper introduces DiffAM, a novel diffusion-based method for face privacy protection that combines makeup removal and transfer with adversarial techniques for improved effectiveness.
Findings
Achieves 12.98% higher attack success rate under black-box settings.
Generates high-quality, natural-looking protected face images.
Outperforms existing methods in visual quality and transferability.
Abstract
With the rapid development of face recognition (FR) systems, the privacy of face images on social media is facing severe challenges due to the abuse of unauthorized FR systems. Some studies utilize adversarial attack techniques to defend against malicious FR systems by generating adversarial examples. However, the generated adversarial examples, i.e., the protected face images, tend to suffer from subpar visual quality and low transferability. In this paper, we propose a novel face protection approach, dubbed DiffAM, which leverages the powerful generative ability of diffusion models to generate high-quality protected face images with adversarial makeup transferred from reference images. To be specific, we first introduce a makeup removal module to generate non-makeup images utilizing a fine-tuned diffusion model with guidance of textual prompts in CLIP space. As the inverse process of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsFace recognition and analysis · Biometric Identification and Security · Facial Nerve Paralysis Treatment and Research
MethodsDiffusion · Contrastive Language-Image Pre-training
