Hugging Face Trending Papers

DecoyFace: Beyond Obfuscation via Controllable and Imperceptible Identity Misdirection for Privacy-Preserving Face Recognition

Split face recognition reduces client-side computation but exposes intermediate features to feature inversion attacks and unauthorized analysis by honest-but-curious (HBC) servers. Existing privacy-preserving face recognition methods mainly aim to resist unauthorized reconstruction, typically producing features whose inversion yields visibly degraded results, which may reveal the existence of protection and motivate adaptive attacks.

arXiv Machine Learning
Aug 19

Picture the Epsilon: Pursuing Identity-Level Privacy Guarantees for Images

The paper compares four audit methods for assessing identity‑level differential privacy in pre‑trained, black‑box face generators. Each method—GaussMech, KDE‑LR, MMD‑TV, and ROC‑HT—has distinct assumptions, hyperparameters, and finite‑sample limitations, and they produce markedly different epsilon estimates when applied to FaceFusion and InstantID. The study finds that all methods reveal significant identity distinguishability, but none can be reliably ranked in this high‑distinguishability regime, suggesting that future work should evaluate them on partially private mechanisms.

By Arman Zareian Jahromi, Vishnu Bondalakunta, Mohammad Akbar Bin Shah, Naimul Haque, Shuangqing Wei, George T. Amariucai
Hugging Face Trending Papers
Aug 27

FIDA: Feature Instability-Driven Attack on Self-Supervised Facial Representation

FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self-supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss to make the encoder more sensitive to perturbations, thereby avoiding the rigid feature patterns seen in earlier attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving normal model performance.

arXiv AI
Aug 11

A Combined Feature-Based Framework for Disguise and Spoofing Detection in Face Recognition Systems

arXiv:2608. 08521v1 Announce Type: cross Abstract: Face recognition systems face two distinct, commonly-separated failure modes: spoofing, where an impostor presents a photograph or video of an authorized user, and disguise, where a legitimate user is rejected because their appearance differs from their enrolled template due to accessories, facial hair, illumination, or pose.

By Sangiya Pararajasingham
arXiv Computer Vision
Aug 28

FIDA: Feature Instability-Driven Attack on Self-Supervised Facial Representation

FIDA (Feature Instability-Driven Attack) is a new backdoor attack framework targeting self‑supervised facial representation models. It employs subtle semantic triggers and a novel Feature Instability Loss that trains the encoder to heighten sensitivity of triggered features along perturbation directions, thereby avoiding the rigid feature patterns seen in prior attacks. Experiments demonstrate that FIDA achieves high attack success while largely preserving benign utility, exposing a significant threat to real‑world facial analysis applications.

By Zhiyang Chen, Changchun Yin, Huiqin Yang, Liming Fang