Alert button
Picture for Zohra Rezgui

Zohra Rezgui

Alert button

Toward Face Biometric De-identification using Adversarial Examples

Feb 07, 2023
Mahdi Ghafourian, Julian Fierrez, Luis Felipe Gomez, Ruben Vera-Rodriguez, Aythami Morales, Zohra Rezgui, Raymond Veldhuis

Figure 1 for Toward Face Biometric De-identification using Adversarial Examples
Figure 2 for Toward Face Biometric De-identification using Adversarial Examples
Figure 3 for Toward Face Biometric De-identification using Adversarial Examples
Figure 4 for Toward Face Biometric De-identification using Adversarial Examples

The remarkable success of face recognition (FR) has endangered the privacy of internet users particularly in social media. Recently, researchers turned to use adversarial examples as a countermeasure. In this paper, we assess the effectiveness of using two widely known adversarial methods (BIM and ILLC) for de-identifying personal images. We discovered, unlike previous claims in the literature, that it is not easy to get a high protection success rate (suppressing identification rate) with imperceptible adversarial perturbation to the human visual system. Finally, we found out that the transferability of adversarial examples is highly affected by the training parameters of the network with which they are generated.

* Accepted at the AAAI-23 workshop on Artificial Intelligence for Cyber Security (AICS) 
Viaarxiv icon