arXiv論文メモ
新着一覧
cs.CV · 査読状況未確認

顔の匿名化を逆転しにくくするHYDRO

HYDRO: Towards Non-Reversible Face De-Identification Using a High-Fidelity Hybrid Diffusion and Target-Oriented Approach

Felix Rosberg, Vitomir Štruc, Cristofer Englund, Eren Erdal Aksoy, Fernando Alonso-Fernandez

この論文をやさしく読む

ひとことで言うと

顔画像を匿名化した後、残る身元の手掛かりを雑音で壊し、画質を拡散モデルで回復する方法。

何に役立つ?

顔の匿名化画像から元の人物を再構成される危険を減らす技術の評価に役立つ。

この研究の面白いところ

匿名化、雑音の注入、拡散による画質回復を順に行い、視線保持のための識別器も使う。

どこまで分かった?

三つのデータセットと比較した攻撃に対する結果であり、あらゆる再構成手法で逆転不能と証明したわけではない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

特定の人を対象とする顔の匿名化モデルは、複数の画像や動画のコマにわたってその人を確実に認識できなくしつつ、画像の重要な特徴を保つことを目指す。こうしたモデルは、生成型のエンコーダー・デコーダーで顔の見た目を変えることが多く、自然で高品質な結果や属性の保持を実現する。しかし、目に見えにくい身元の手掛かりを残してしまい、匿名化を逆転する再構成攻撃に弱くなるおそれがある。そこでHYDROという新しい顔の匿名化方法を提案する。対象者向けのモデルと、匿名化を逆転する学習に使われ得る見えない情報を壊すための拡散過程を組み合わせる。 HYDROはまず顔画像を匿名化し、結果に雑音を加えて再構成を難しくしてから、拡散モデルによる回復で画質を上げ、雑音が画像の特徴へ与える影響を小さくする。さらに画質を高め、視線方向を保ちやすくするため、Eye Similarity Discriminatorという新しい識別器を学習に組み込む。異なる三つのデータセットでの定量・定性評価では、高い画質と属性保持を示し、比較した対象者向け手法の中で再構成攻撃に耐えたのはHYDROだけだった。複数の最高水準の比較手法に対して、再構成攻撃の成功を平均85.7%減らした。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-22(UTC)
最新改訂
2026-09-22 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Target-oriented face de-identification models aim to anonymize the identity of a target individual across different images or video frames, such that the target can no longer be reliably recognized, while maintaining key characteristics of the visual data. Such models commonly leverage generative encoder-decoder architectures to manipulate facial appearances, enabling them to produce realistic high-fidelity de-identification results, while ensuring considerable attribute-retention capabilities. However, target-oriented models also carry the risk of inadvertently preserving subtle identity cues, making them (potentially) reversible and susceptible to reconstruction attacks. To address this problem, we introduce in this paper a novel (robust) face de-identification approach, called HYDRO, that combines target-oriented models with a dedicated diffusion process specifically designed to destroy any imperceptible information that may allow learning to reverse the de-identification procedure. HYDRO first de-identifies the given face image, injects noise into the de-identification result to impede reconstruction, and then applies a diffusion-based recovery step to improve fidelity and minimize the impact of the noising process on the data characteristics. To further improve image fidelity and better retain gaze directions, a novel Eye Similarity Discriminator (ESD) is also introduced and incorporated it into the training of HYDRO. Extensive quantitative and qualitative experiments on three diverse datasets demonstrate that HYDRO exhibits state-of-the-art (SOTA) fidelity and attribute-retention capabilities, while being the only target-oriented method resilient against reconstruction attacks. In comparison to multiple SOTA competitors, HYDRO reduces the success of reconstruction attacks by 85.7% on average.

arXiv ID: 2609.27011 / 要約の誤りについて