Privacy-Preserving Face Recognition Using Trainable Feature Subtraction
Yuxi Mi, Zhizhou Zhong, Yuge Huang, Jiazhen Ji, Jianqing Xu, Jun Wang, Shaoming Wang, Shouhong Ding, Shuigeng Zhou
TL;DR
This work addresses privacy concerns in face recognition by introducing MinusFace, a trainable feature-subtraction framework that creates a visually uninformative yet identity-preserving representation. It generates a high-dimensional residue $r = x - x'$ from a regenerated image $X' = g(X)$ and leverages a DCT-based encoding $e$ with invertible decoding $d$, followed by random channel shuffling to produce $X_p$, the protection target. The approach optimizes a dual objective that preserves recognizability via a FR model on $r$ while minimizing visual information through the regeneration-based subtraction, yielding strong privacy against recovery attacks and competitive recognition accuracy across standard benchmarks. Extensive experiments show MinusFace outperforms competing transform-based PPFR methods in privacy protection (low recoverability) while maintaining accuracy close to unprotected baselines, with favorable efficiency and compatibility. The method's practicality is underscored by its public code release and its applicability to diverse FR backbones and losses.
Abstract
The widespread adoption of face recognition has led to increasing privacy concerns, as unauthorized access to face images can expose sensitive personal information. This paper explores face image protection against viewing and recovery attacks. Inspired by image compression, we propose creating a visually uninformative face image through feature subtraction between an original face and its model-produced regeneration. Recognizable identity features within the image are encouraged by co-training a recognition model on its high-dimensional feature representation. To enhance privacy, the high-dimensional representation is crafted through random channel shuffling, resulting in randomized recognizable images devoid of attacker-leverageable texture details. We distill our methodologies into a novel privacy-preserving face recognition method, MinusFace. Experiments demonstrate its high recognition accuracy and effective privacy protection. Its code is available at https://github.com/Tencent/TFace.
