Examining StyleGAN as a Utility-Preserving Face De-identification Method

Examining StyleGAN as a Utility-Preserving Face De-identification Method
复制标题

DOI:
10.56553/popets-2023-0114
复制
发表时间:
2022-12
期刊:
Proc. Priv. Enhancing Technol.
影响因子:
--
通讯作者:
Seyyed Mohammad Sadegh Moosavi Khorzooghi;Shirin Nilizadeh
Seyyed Mohammad Sadegh Moosavi Khorzooghi;Shirin Nilizadeh
中科院分区:
其他
文献类型:
--
作者:
Seyyed Mohammad Sadegh Moosavi Khorzooghi;Shirin Nilizadeh

文献摘要

相似文献

已经提出了几种人脸去识别方法,通过模糊用户的脸来保护他们的隐私。然而,这些方法会降低照片的质量,而且它们通常不保留人脸的实用性,即他们的年龄、性别、姿势和面部表情。最近,先进的生成性对抗网络模型,如StyleGan[33],已经被提出,它们产生真实的、高质量的想象面孔。在本文中,我们研究了StyleGAN在通过样式混合生成去身份人脸中的使用,即将目标人脸和辅助人脸的样式或特征混合以生成携带目标人脸效用的去身份人脸。我们通过实施几种人脸检测、验证和身份识别攻击并进行用户研究,检查了这种保护实用性和隐私的去身份方法。实验结果表明,StyleGAN算法与CIAGAN和DeepPrivacy两种人脸去噪方法的性能相当或更好,保护了用户的隐私和图像的效用。特别是,基于机器学习的实验结果表明,StyleGAN0-4在保护隐私的同时,比CIAGAN和DeepPrivacy更好地保留了效用。StyleGAN 0-3在提供更多隐私的同时,保留了相同级别的实用程序。在本文中,我们还首次进行了精心设计的用户研究,从人类观察者的角度考察了StyleGan 0-3、0-4和0-5以及CIAGAN和DeepPrivacy的隐私和效用保护特性。我们的统计测试显示,参与者倾向于验证和识别StyleGAN 0-5图像比DeepPrivacy图像更容易。除StyleGan 0-5外,其余方法的识别率均显著低于CIAGAN。在效用方面,不出所料,StyleGAN 0-5在保留某些属性方面表现得明显更好。在所有的方法中,平均而言,参与者认为性别保存得最多,而自然保存得最少。
Several face de-identification methods have been proposed to preserve users’ privacy by obscuring their faces. These methods, however, can degrade the quality of photos, and they usually do not preserve the utility of faces, i.e., their age, gender, pose, and facial expression. Recently, advanced generative adversarial network models, such as StyleGAN [ 33], have been proposed, which generate realistic, high-quality imaginary faces. In this paper, we investigate the use of StyleGAN in generating de-identified faces through style mixing, where the styles or features of the target face and an auxiliary face get mixed to generate a de-identified face that carries the utilities of the target face. We examined this de-identification method for preserving utility and privacy by implementing several face detection, verification, and identification attacks and conducting a user study. The results from our extensive experiments, human evaluation, and comparison with two state-of-the-art face de-identification methods, i.e., CIAGAN and DeepPrivacy, show that StyleGAN performs on par or better than these methods, preserving users’ privacy and images’ utility. In particular, the results of the machine learning-based experiments show that StyleGAN0-4 preserves utility better than CIAGAN and DeepPrivacy while preserving privacy at the same level. StyleGAN 0-3 preserves utility at the same level while providing more privacy. In this paper, for the first time, we also performed a carefully designed user study to examine both privacy and utility-preserving properties of StyleGAN 0-3, 0-4, and 0-5, as well as CIAGAN and DeepPrivacy from the human observers’ perspectives. Our statistical tests showed that participants tend to verify and identify StyleGAN 0-5 images easier than DeepPrivacy images. All the methods but StyleGAN 0-5 had significantly lower identification rates than CIAGAN. Regarding utility, as expected, StyleGAN 0-5 performed significantly better in preserving some attributes. Among all methods, on average, participants believe gender has been preserved the most while naturalness has been preserved the least.