顔認識モデルで指定した人物だけを識別不能にする手法
Damnatio Memoriae: Adversarially and Selectively Forgetting Identities in the Embedding Space of Face Recognition Models
この論文をやさしく読む
ひとことで言うと
顔認識を全体として使い続けながら、指定した人の別々の写真を結び付けにくくする方法を評価した。
何に役立つ?
考えられる用途は顔認識システムから特定人物の識別可能性を減らす設計の検討。要旨の実証は指定したモデルと比較条件での評価である。
この研究の面白いところ
学習画像を消すだけでは未知の人物も認識できるモデルに効かないため、埋め込み空間の幾何自体を変えている。
どこまで分かった?
効果は対象人物の画像の一部を用いた微調整と、評価した二つの規模、三つの基盤モデルで報告されたもの。ほかの運用条件での性能は要旨からは分からない。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
顔認識モデルは、別の機会に撮影された同一人物の二枚の画像について、埋め込み表現の類似度が運用上のしきい値を超えると同一人物として結び付ける。本研究は、ほかの人についてはモデルを使い続けながら、選んだ人物の画像だけを別の撮影機会をまたいで結び付けられなくすることを考える。画像の削除と再学習だけでは、モデルが学習時に見たことのない人物も認識できるため、この目的は達成できない。そこで、選んだ人物に対して埋め込み空間自体を変える必要があり、著者らはこれをオープンセット敵対的忘却と呼ぶ。三つの損失関数を提案する。一つは同一人物の埋め込みをその重心から散らし、残る二つは各画像をそれぞれの、ほぼ直交する目標へ写す。後者の目標は分類器の出力部とともに学習するか、ほぼ正規直交する枠組みとして事前に固定する。各損失は、対象人物の画像の一部に対する分類目的と併せて微調整する。二種類の忘却規模と三種類の基盤モデルで、照合と識別における先行手法四つと比較した。埋め込みの幾何に作用する損失はいずれも、忘却対象の人物をほぼ識別不能にした。正規直交の枠組みだけでも強い忘却を達成し、その部分集合の画像が比較に入る場合には効果が保たれ、異なる忘却対象者同士も結び付けられない。同時期の教師なし手法と比べても、非対象者の保持率が高い条件で上回った。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-22(UTC)
- 最新改訂
- 2026-09-22 · v1
- 査読・掲載
- 査読状況未確認
更新履歴
- v1 2026-09-22 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
A face recognition model links two images of a person recorded on separate occasions when their embedding similarity exceeds an operating threshold. We consider making chosen identities unlinkable across separate occasions while the model remains in service for the rest of the population. Deleting their images and retraining does not achieve this, since the model recognises identities never observed in training. Therefore, the embedding space must be altered against these identities, the process of which we call open-set adversarial forgetting. We propose three loss functions, one that disperses an identity's embeddings from their centroid, and two that map each image onto its own near-orthogonal target, learnt with the classifier head or fixed in advance as an almost-orthonormal frame. Each is fine-tuned alongside the classification objective on a subset of each identity's images. We evaluate them against four methods from prior work in verification and identification, at two forget scales and three backbones. Every loss acting on the embedding geometry makes the forget identities nearly unidentifiable. The orthonormal frame alone achieves strong forgetting, which holds wherever an image of that subset enters the comparison and leaves distinct forget identities unlinkable. It also surpasses a concurrent unsupervised method at a higher retain rate.
著者のコメント
15 pages, 7 figures, 5 tables. This work might be submitted to the IEEE for possible publication
arXiv ID: 2609.27115 / 要約の誤りについて