Reversible protection method of face privacy mask based on reversible neural network technology
Through the reversible protection method of face privacy masks based on reversible neural network, the problems of irresponsible face protection in the prior art are solved, and high-quality mask face generation and high-accuracy face recovery are achieved, and high reusability is achieved.
Patent Information
- Application Number
- CN202210246639.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-03-14
AI Technical Summary
The prior art cannot achieve irresponsibility and reversibility in the protection of face privacy, resulting in the protection of facial information being difficult to naturally hide and cannot be effectively restored.
The reversible protection method of face privacy masks based on reversible neural network technology is adopted. By building a reversible mask network, including Mask-Net module and reversible embedding network, the natural hiding and efficient recovery of face images is achieved.
The irresponsibility and reversibility of facial privacy protection are realized. The resulting mask has high visual quality of facial features, high accuracy in facial recovery, and high reusability.
Smart Images

Figure CN115114651B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of image privacy processing, and in particular to a reversible protection method for a face privacy mask based on a reversible neural network technology. Background Art
[0002] Computer vision technology has been widely used in tasks such as visual recognition. All of these technologies have brought great convenience to people's daily lives, but also brought huge risks. A large number of original photos and videos are uploaded to the cloud or sent to third parties for analysis and recognition tasks, including facial information. However, facial information is a kind of sensitive information that contains a lot of personal information. If it is not carefully protected, highly sensitive facial information can be easily accessed and illegally used by third parties or attackers. Protecting the privacy of this data requires a technology that can ensure the security of facial information while performing traditional computer vision technology applications.
[0003] In previous studies, the original face privacy protection method is achieved by irreversibly processing the original face using methods such as superpixels, blurring, Gaussian noise, edges, and low resolution. However, the original face privacy protection methods are all aimed at the lack of facial semantic information and cannot guarantee the reusability of the original face information. With the development of deep learning technology, GAN came into being and continued to develop, and researchers in the field of face privacy protection began to focus on GAN. Ren et al. proposed learning to anonymize faces for privacy-preserving action detection, and the video face anonymizer has minimal impact on the action detector; Maximov et al. proposed CIAGAN, an image and video anonymization model based on conditional generative adversarial networks; You et al. proposed a novel reversible face privacy protection scheme that anonymizes face information and restores the original face information when needed.
[0004] Through the analysis of existing face privacy protection methods, it can be found that these existing face privacy protection methods only retain semantic information for computer vision tasks, but permanently destroy the original face information before uploading, thereby preventing third parties and legitimate users from accessing the original face information, and almost all of these methods cannot completely restore the original face. In fact, since the blurred face is unnatural and perceptible, it is more likely to be noticed by attackers.
[0005] In addition, in some applications, we hope that blurred faces can be perceived and the original protected faces need to be restored. For example, on social platforms, many people like to record their lives and share their photos. They hope that the photos look natural without leaking facial privacy to unauthorized people. They also hope that the original face can be shown to authorized people (friends or family members, etc.). If a criminal is caught in video surveillance, the original face of the criminal also needs to be restored after protecting privacy.
[0006] Therefore, there are two problems to be solved in practical applications. The first is how to achieve the imperceptibility of face privacy protection, that is, how to hide the protected face naturally; the second is how to achieve reversibility, that is, the occluded image can be well restored to the protected face. Summary of the invention
[0007] The purpose of the present invention is to solve the defects of imperceptibility and reversibility of face privacy protection in the prior art, and to provide a reversible protection method for face privacy mask based on reversible neural network technology to solve the above problems.
[0008] In order to achieve the above object, the technical solution of the present invention is as follows:
[0009] A reversible protection method for a face privacy mask based on a reversible neural network technology comprises the following steps:
[0010] Acquisition of original face images: Acquisition of original protected face images and formation of training data sets;
[0011] Construction of reversible mask network: Construction of reversible mask network based on reversible neural network;
[0012] Training of the reversible mask network: Input the training dataset into the reversible mask network for training;
[0013] Acquisition of the face image to be protected: Acquisition of the face image to be protected;
[0014] Generation of face privacy mask: Input the face image to be protected into the trained reversible mask network to generate a face image with a mask;
[0015] Removal of face privacy mask: Input the masked face image into the trained reversible mask network to remove the face privacy mask.
[0016] The construction of the reversible mask network includes the following steps:
[0017] The reversible mask network is set to contain two submodules, namely the Mask-Net module and the reversible embedding network;
[0018] The Mask-Net module is set to consist of four modules: encoder, ID injection module, decoder and face enhancement module, and its structure is set as follows:
[0019] The input of the encoder is set to be the protected face, the encoder encodes the protected face, and outputs the encoded protected face;
[0020] The input of the ID injection module is set to be the identity information of the encoded protected face and the source face, and the identity information of the source face is transferred to the encoded protected face at the feature level;
[0021] Set the decoder to obtain the initial generated mask face;
[0022] It is set to use the face enhancement module to perform super-resolution reconstruction on the initially generated mask face to generate a mask face;
[0023] The reversible embedding network is assumed to include a forward process, a backward process and its loss function, wherein the structure of the forward process is the same as that of the backward process;
[0024] The forward process is set to include three steps: DWT, forward embedding network, and IWT; the backward part is set to include three steps: DWT, backward recovery network, and IWT; among them, DWT is used to convert the time domain features of the image into frequency domain features, and IWT is used to restore the frequency domain features to the image;
[0025] Set up a forward embedding network, which is composed of N cascaded embedding blocks;
[0026] Set up a backward recovery network, which is composed of N recovery blocks cascaded;
[0027] Set the overall LOSS function of the reversible embedding network,
[0028] The embedding loss function is defined as follows:
[0029]
[0030] in, Equivalent to θ is the network parameter, T is the number of training samples, l e It is used to measure the x value of the face wearing a mask. Masked and mask face x Mask The difference between Embedding (θ) represents the embedding loss;
[0031] The recovery loss function is defined as follows:
[0032]
[0033] Among them, face recovery Equivalent to represents the recovery process, χ is the distribution of n, T is the number of training samples, l R Represents the restored face x Recovered and protected face x Protected The difference between Recovering (θ) represents the recovery loss;
[0034] The low-frequency wavelet loss is defined as follows:
[0035]
[0036] Among them, H() LL represents the low-frequency subband, Represents a masked face x Masked The low frequency subband and mask face x Mask The difference between the low-frequency subbands, T is the number of training samples, L low-frequency (θ) represents the low-frequency loss;
[0037] Define the total loss L Total is the embedding loss L Embedding , restore the loss L Recovering and low frequency loss L low-frequency The weight sum of the three is expressed as follows:
[0038] L Total =λ1L Embedding +λ2L Recovering +λ3L low-frequency
[0039] Among them, λ1, λ2, and λ3 are used to balance the weights of different loss functions.
[0040] The training of the reversible neural network comprises the following steps:
[0041] Training parameter settings: set the learning rate to 0.00001, weight decay to 1000, batch size to 16 samples, and number of cycles to 10000;
[0042] Input the training data set into the Mask-Net module and output the masked face;
[0043] Input the protected face and mask face into the forward embedding network for training with the mask on:
[0044] The embedding process is: Input protected face x Protected and mask face x Mask ;
[0045] For protected faces x Protected and mask face x Mask Perform wavelet transform and define the change of feature map after DWT as:
[0046]
[0047] Among them, B is the batch size, H is the depth, W is the width, and C is the number of channels;
[0048] After DWT, the protected face x in the frequency domain is Protected and mask face x Mask Input to the forward embedding network, there are N embedding blocks with the same structure in the forward embedding network. For the i-th embedding block in this module, the input is and The output is and The calculation formula is as follows:
[0049]
[0050] where α is a multiplicative constant factor used as a clamping impulse function, ρ(·), η(·) is represented by dense blocks, x Protected Is a protected face, x Mask is the mask face, i represents the i-th embedding block;
[0051] After the Nth embedding block, the output and Perform IWT and obtain x Masked And the lost information m, its expression is as follows:
[0052]
[0053] Among them, m is the missing information, the face x wearing the mask Masked The lost information m follows the same distribution, and N represents the Nth recovery block;
[0054] Generate auxiliary information n by random sampling from the case-agnostic distribution, which follows the same distribution as m;
[0055] Train a reversible embedding network to remove the mask: In the process of removing the mask, use auxiliary information n to help obtain the restored face x Recovered ;
[0056] The recovery process is: input the masked face x Masked and auxiliary information n;
[0057] Wearing a mask on the face x Masked Perform DWT processing on the auxiliary information n;
[0058] After DWT, the masked face x in the frequency domain is Masked and auxiliary information n are input into the backward recovery network. There are N recovery blocks with the same structure in the backward recovery network. For the i-th recovery block in this module, the input is and n i , the output is n i+1 and The calculation formula is as follows:
[0059]
[0060] x Masked is the masked face, n is the auxiliary information, α is a multiplication factor used as a clamping impulse function, ρ(·), η(·) is represented by dense blocks, i represents the i-th embedding block;
[0061] After the Nth recovery block, the output will be and n N Perform IWT to obtain the restored face x Recovered , which is expressed as follows:
[0062]
[0063] x Masked is the face wearing a mask, n is the auxiliary information, x Recovered It is to restore the face, and N represents the Nth restoration block.
[0064] Beneficial Effects
[0065] Compared with the prior art, the reversible face privacy mask protection method based on reversible neural network technology of the present invention uses Mask-Net to naturally generate a mask face, puts the mask face on the protected face, and generates a masked face. When the authorized party removes the mask face from the masked face, the restored face is obtained. While ensuring the imperceptibility and reversibility of face privacy protection, more superior face privacy protection is achieved.
[0066] The present invention generates a "mask" face based on objective parameters, which has significantly improved visual quality compared to the prior art, and has a certain improvement in the accuracy of face restoration, and achieves high reusability that is difficult to achieve with existing face privacy protection technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 is a method sequence diagram of the present invention;
[0068] Figure 2 This is a structural diagram of the embedded block involved in the present invention;
[0069] Figure 3 This is a structural diagram of the recovery block involved in the present invention. DETAILED DESCRIPTION
[0070] In order to have a further understanding and recognition of the structural features and the effects achieved by the present invention, a preferred embodiment and accompanying drawings are used for detailed description as follows:
[0071] like Figure 1 As shown, the reversible protection method of a face privacy mask based on a reversible neural network technology of the present invention comprises the following steps:
[0072] The first step is to obtain the original face image: obtain the original protected face image and form a training data set.
[0073] The second step is to build a reversible mask network: build a reversible mask network based on the reversible neural network. Since the structure of the reversible network is symmetrical, the symmetry of the reversible network can be used to improve the reversible network and build a reversible mask network, which can greatly ensure the high similarity between the restored face and the original face, so as to ensure the high availability of the face image in the face privacy protection method, and further design the symmetric blocks of the reversible network to achieve the purpose of putting a reversible mask on the face image.
[0074] The construction of the reversible mask network includes the following steps:
[0075] (1) The reversible mask network is set to consist of two sub-modules, namely the Mask-Net module and the reversible embedding network.
[0076] (2) The Mask-Net module is set to consist of four modules: encoder, ID injection module, decoder and face enhancement module. Its structure is set as follows:
[0077] A1) setting the input of the encoder to be the protected face, encoding the protected face through the encoder, and outputting the encoded protected face;
[0078] A2) setting the input of the ID injection module to be the identity information of the encoded protected face and the source face, and transferring the identity information of the source face to the encoded protected face at the feature level;
[0079] A3) setting the mask face initially generated by the decoder;
[0080] A4) setting a facial enhancement module to perform super-resolution reconstruction on the initially generated mask face to generate a mask face.
[0081] (3) The reversible embedding network is assumed to include a forward process, a backward process, and its loss function, where the forward process has the same structure as the backward process;
[0082] B1) The forward process is set to include three steps: DWT, forward embedding network, and IWT; the backward part is set to include three steps: DWT, backward recovery network, and IWT; among them, DWT is used to convert the time domain features of the image into frequency domain features, and IWT is used to restore the frequency domain features to the image;
[0083] B2) setting a forward embedding network, which is composed of N cascaded embedding blocks;
[0084] B3) setting a backward recovery network, which is composed of N recovery blocks cascaded;
[0085] B4) Setting the overall LOSS function of the reversible embedding network,
[0086] The embedding loss function is defined as follows:
[0087]
[0088] in, Equivalent to θ is the network parameter, T is the number of training samples, l e It is used to measure the x value of the face wearing a mask. Masked and mask face x Mask The difference between Embedding (θ) represents the embedding loss;
[0089] The recovery loss function is defined as follows:
[0090]
[0091] Among them, face recovery Equivalent to represents the recovery process, χ is the distribution of n, T is the number of training samples, l R Represents the restored face x Recovered and protected face x Protected The difference between Recovering (θ) represents the recovery loss;
[0092] The low-frequency wavelet loss is defined as follows:
[0093]
[0094] Among them, H() LL represents the low-frequency subband, Represents a masked face x Masked The low frequency subband and mask face x Mask The difference between the low-frequency subbands, T is the number of training samples, L low-frequency (θ) represents the low-frequency loss;
[0095] Define the total loss L Total is the embedding loss L Embedding , restore the loss L Recovering and low frequency loss L low-frequency The weight sum of the three is expressed as follows:
[0096] LTotal =λ1L Embedding +λ2L Recovering +λ3L low-frequency
[0097] Among them, λ1, λ2, and λ3 are used to balance the weights of different loss functions.
[0098] The third step is training the reversible mask network: input the training data set into the reversible mask network for training.
[0099] During the training process, the visual quality of the face mask generated by the face swapping module of simswap will be reduced, resulting in the inability of the overall network to achieve the original effect. Therefore, the GPEN technology is used after the module to enhance the visual quality of the generated face mask. In the reversible forward embedding process, some image information is often lost during processing. Due to the needs of applications in actual scenarios, the recovery process needs to be completed without additional auxiliary information. Due to the reversible constraints of the network, the lost information and the auxiliary information n that needs to be used follow the same distribution, and the auxiliary information of the same distribution can be obtained by sampling.
[0100] The specific steps for training the reversible mask network are as follows:
[0101] (1) Training parameter settings: set the learning rate to 0.00001, the weight decay to 1000, the batch size to 16 samples, and the number of cycles to 10000.
[0102] (2) Input the training data set into the Mask-Net module and output the masked face.
[0103] (3) Input the protected face and mask face into the forward embedding network for training with the mask on:
[0104] C1) The embedding process is: Input the protected face x Protected and mask face x Mask ;
[0105] C2) For the protected face x Protected and mask face x Mask Perform wavelet transform and define the change of feature map after DWT as:
[0106]
[0107] Among them, B is the batch size, H is the depth, W is the width, and C is the number of channels;
[0108] C3) After DWT, the protected face x in the frequency domain is Protected and mask face x MaskInput into the forward embedding network, there are N embedding blocks with the same structure in the forward embedding network. The specific structure of the embedding block is as follows Figure 2 As shown, for the i-th embedding block in this module, the input is and The output is and The calculation formula is as follows:
[0109]
[0110] where α is a multiplicative constant factor used as a clamping impulse function, ρ(·), η(·) is represented by dense blocks, x Protected Is a protected face, x Mask is the mask face, i represents the i-th embedding block;
[0111] C4) After the Nth embedding block, the output and Perform IWT and obtain x Masked And the lost information m, its expression is as follows:
[0112]
[0113] Among them, m is the missing information, the face x wearing the mask Masked The lost information m follows the same distribution, and N represents the Nth recovery block;
[0114] Auxiliary information n is randomly sampled from the case-agnostic distribution, which follows the same distribution as m.
[0115] (4) Training the reversible embedding network to remove the mask: In the process of removing the mask, auxiliary information n is used to help obtain the restored face x. Recovered ;
[0116] D1) The restoration process is: Input the masked face x Masked and auxiliary information n;
[0117] D2) Wearing a mask face x Masked Perform DWT processing on the auxiliary information n;
[0118] D3) After DWT, the masked face x in the frequency domain is Masked and auxiliary information n are input into the backward recovery network. There are N recovery blocks with the same structure in the backward recovery network. The structure of the recovery block is as follows: Figure 3 As shown, for the i-th recovery block in this module, the input is and n i , the output is n i+1 and The calculation formula is as follows:
[0119]
[0120] x Masked is the masked face, n is the auxiliary information, α is a multiplication factor used as a clamping impulse function, ρ(·), η(·) is represented by dense blocks, i represents the i-th embedding block;
[0121] D4) After the Nth recovery block, the output and n N Perform IWT to obtain the restored face x Recovered , which is expressed as follows:
[0122]
[0123] x Masked is the face wearing a mask, n is auxiliary information, x Recovered It is to restore the face, and N represents the Nth restoration block.
[0124] Step 4: Acquisition of the facial image to be protected: Acquisition of the facial image to be protected.
[0125] Step 5: Generation of face privacy mask: Input the face image to be protected into the trained reversible mask network to generate a face image with a mask.
[0126] Step 6: Removal of face privacy mask: Input the masked face image into the trained reversible mask network to remove the face privacy mask.
[0127] In actual applications, the face image that needs to be protected and the face image to be used as a "mask" are input into the network; the face image wearing the "mask" is obtained, and the user's privacy information cannot be obtained through the face image wearing the "mask"; when the authorized party needs to obtain the user's privacy information, the authorized party can obtain the original face image by inputting the face image wearing the "mask" into the network again.
[0128] Table 1 gives the details of the parameter settings in the experiment. We set the batch size to 16 to make full use of the GPU. According to the mainstream settings, the learning rate is set to 1e-5, the weight decay is set to 1000, and the epoch parameter is set to 10000, and the effects of the three ratios on the recovery effect are discussed in the next table.
[0129] Table 1. Comparison of experimental settings of IMN
[0130]
[0131] Table 2 will discuss in detail the impact of the three % on the experiment. λ1, λ2, λ3 are weights for balancing different loss functions. The parameters of λ1 and λ3 are related to the mask face x Mask And put on the mask face x Masked The parameters of λ2 restore the face x Recovered and protected face x Protected The restored face x is indistinguishable not only at the visual level but also at the pixel level. In order to achieve the best restoration effect, we randomly selected 20 test images from the database, and the results are shown in Table 2. We can see that as the parameter λ2 increases, the experimental performance is better, which means that the restored face x Recovered Restore protected face to pixel level protection x Protected The closer. The 1:3:1 ratio has the best recovery effect.
[0132] Table 2 Comparison of the impact of different parameter ratios
[0133] <![CDATA[λ1:λ2:λ3]]> 1:1:1 1:2:1 1:3:1 1:4:1 PSNR 38.42 46.35 47.09 46.15 SSIM 0.943 0.988 0.991 0.988 RMSE 9.945 1.579 1.437 1.706 MAE 2.108 0.905 0.829 0.930
[0134] Table 3 discusses the comparison of experimental results on the objective parameters of the test images.
[0135] Table 3 Comparison of objective parameters of test images
[0136]
[0137] Table 4 shows the comparison of the results with similar methods. Currently, the only highly reusable method of this type is a privacy-preserving reversible mosaic transformation proposed by You et al. Obviously, the visual quality of the processed image is much worse than that of the method of the present invention. Therefore, we only compare the quality of the restored face. The experiments were conducted on the same dataset. The method of the present invention has better restoration performance than the method of You et al. The fundamental reason is that the performance of the reversible network architecture is much better than that of the autoencoder.
[0138] Table 4 Comparison of the effects of the present invention and the traditional method
[0139] Methods PSNR SSIM RMSE MAE You et al 36.67 0.988 14.72 2.74 Proposed method 52.02 0.997 0.441 0.45
[0140] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions only describe the principles of the present invention. The present invention may be subject to various changes and improvements without departing from the spirit and scope of the present invention. These changes and improvements fall within the scope of the present invention. The scope of protection claimed by the present invention is defined by the attached claims and their equivalents.
Claims
1. A reversible protection method for face privacy mask based on reversible neural network technology, characterized in that: The following steps are involved: 11) Acquisition of original face images: Acquisition of original protected face images and formation of training data sets; 12) Construction of reversible mask network: Construction of reversible mask network based on reversible neural network; The construction of the reversible mask network includes the following steps: 121) The reversible mask network is set to include two submodules, namely the Mask-Net module and the reversible embedding network; 122) The Mask-Net module is set to consist of four modules: encoder, ID injection module, decoder and face enhancement module, and its structure is set as follows: 1221) setting the input of the encoder to be the protected face, encoding the protected face through the encoder, and outputting the encoded protected face; 1222) setting the input of the ID injection module to be the identity information of the encoded protected face and the source face, and transferring the identity information of the source face to the encoded protected face at the feature level; 1223) setting a mask face initially generated by a decoder; 1224) setting a facial enhancement module to perform super-resolution reconstruction on the initially generated mask face to generate a mask face; 123) Assume that the reversible embedding network includes a forward process, a backward process and a loss function, wherein the structure of the forward process is the same as that of the backward process; 1231) The forward process is set to include three steps: DWT, forward embedding network, and IWT; the backward part is set to include three steps: DWT, backward recovery network, and IWT; wherein DWT is used to convert the time domain features of the image into frequency domain features, and IWT is used to restore the frequency domain features to the image; 1232) setting a forward embedding network, the forward embedding network is formed by cascading N embedding blocks; 1233) setting a backward recovery network, wherein the backward recovery network is formed by cascading N recovery blocks; 1234) set the overall LOSS function of the reversible embedding network, The embedding loss function is defined as follows: in, Equivalent to θ is the network parameter, T is the number of training samples, l e It is used to measure the x value of the face wearing a mask. Masked and mask face x Mask The difference between Embedding (θ) represents the embedding loss; The recovery loss function is defined as follows: Among them, face recovery Equivalent to represents the recovery process, χ is the distribution of n, T is the number of training samples, l R Represents the restored face x Recovered and protected face x Protected The difference between Recovering (θ) represents the recovery loss; The low-frequency wavelet loss is defined as follows: Among them, H() LL represents the low-frequency subband, Represents a masked face x Masked The low frequency subband and mask face x Mask The difference between the low-frequency subbands, T is the number of training samples, L low-frequency (θ) represents low-frequency loss; Define the total loss L Total is the embedding loss L Embedding , restore the loss L Recovering and low frequency loss L low-frequency The weight sum of the three is expressed as follows: L Total =λ1L Embedding +λ2L Recovering +λ3L low-frequency Among them, λ1, λ2 and λ3 are used to balance the weights of different loss functions; 13) Training of the reversible mask network: inputting the training data set into the reversible mask network for training; The training of the reversible neural network comprises the following steps: 131) Training parameter settings: set the learning rate to 0.00001, weight decay to 1000, batch size to 16 samples, and number of cycles to 10000; 132) Input the training data set into the Mask-Net module and output the masked face; 133) Input the protected face and mask face into the forward embedding network for training with the mask on: 1331) The embedding process is: Input protected face x Protected and mask face x Mask ; 1332) for protected face x Protected and mask face x Mask Perform wavelet transform and define the change of feature map after DWT as: Among them, B is the batch size, H is the depth, W is the width, and C is the number of channels; 1333) After DWT, the protected face x in the frequency domain is Protected and mask face x Mask Input to the forward embedding network, there are N embedding blocks with the same structure in the forward embedding network. For the i-th embedding block in this module, the input is and The output is and The calculation formula is as follows: where α is a multiplicative constant factor used as a clamping impulse function, ρ(·), η(·) is represented by dense blocks, x Protected Is a protected face, x Mask is the mask face, i represents the i-th embedding block; 1334) After the Nth embedding block, the output and Perform IWT and obtain x Masked And the lost information m, its expression is as follows: Among them, m is the missing information, the face x wearing the mask Masked The lost information m follows the same distribution, and N represents the Nth recovery block; Generate auxiliary information n by random sampling from the case-agnostic distribution, which follows the same distribution as m; 134) Train the reversible embedding network to remove the mask: In the process of removing the mask, use auxiliary information n to help obtain the restored face x Recovered ; 1341) The recovery process is: input the masked face x Masked and auxiliary information n; 1342) Masked face x Masked Perform DWT processing on the auxiliary information n; 1343) After DWT, the masked face x in the frequency domain is Masked and auxiliary information n are input into the backward recovery network. There are N recovery blocks with the same structure in the backward recovery network. For the i-th recovery block in this module, the input is and n i , the output is n i+1 and The calculation formula is as follows: x Masked is the masked face, n is the auxiliary information, α is a multiplication factor used as a clamping impulse function, ρ(·), η(·) is represented by dense blocks, i represents the i-th embedding block; 1344) After the Nth recovery block, the output and n N Perform IWT to obtain the restored face x Recovered , which is expressed as follows: x Masked is the face wearing a mask, n is auxiliary information, x Recovered It is to restore the face, N represents the Nth restoration block; 14) Acquisition of the facial image to be protected: Acquisition of the facial image to be protected; 15) Generation of face privacy mask: Input the face image to be protected into the trained reversible mask network to generate a face image with a mask; 16) Removal of face privacy mask: Input the masked face image into the trained reversible mask network to remove the face privacy mask.