A face image attribute protection method based on adaptive confrontation

By introducing a natural loss function and an adaptive PGD algorithm into the total loss function, and combining momentum mechanism and SMAC algorithm to optimize the attack step size, the generality and adaptability problems of existing face image attribute protection methods are solved, achieving effective protection against various face tampering attacks and maintaining the visual naturalness of images.

CN122415306APending Publication Date: 2026-07-17GUANGDONG POLYTECHNIC NORMAL UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG POLYTECHNIC NORMAL UNIV
Filing Date
2026-02-05
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing methods for protecting facial image attributes suffer from poor versatility, lack of adaptive adjustment capabilities, and insufficient visual naturalness. They are difficult to adapt to various facial tampering attack models, and fixed perturbation parameters lead to unstable protection effects and an imbalance in image usability.

Method used

An adaptive adversarial face image attribute protection method is adopted. By introducing a natural loss function into the total loss function, the perturbation is dynamically adjusted using an adaptive PGD algorithm. The attack step size is optimized by combining momentum mechanism and SMAC algorithm, and image-level and model-level perturbation fusion is performed to achieve adaptive adjustment of adversarial perturbation and preservation of visual naturalness.

Benefits of technology

It achieves adaptive protection against various face tampering attack models, maintains the visual naturalness and usability of images, and improves the generalization ability and stability of the defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122415306A_ABST
    Figure CN122415306A_ABST
Patent Text Reader

Abstract

本发明公开的属于计算机视觉和网络安全技术领域,具体为一种基于自适应对抗的人脸图像属性保护方法,首先在对抗的起始阶段于总损失函数中设置模型训练的自然损失函数;接着在攻击过程中,采用自适应PGD以根据不同的数据输入动态调节产生对抗性扰动,并通过动量机制实现攻击方向的持续优化与局部震荡抑制;随后通过攻击步长自适应调节机制,循环地进行小批量的攻击以自动地搜索最优的攻击步长,然后使用最优的步长进行大批量攻击;最后通过图像级和模型级扰动融合输出最终的水印;基于此,本发明设计了一种自然损失函数,考虑了受保护的图像的视觉质量,能够在保护人脸图像属性的同时不影响使用者在社交媒体的正常用途。
Need to check novelty before this filing date? Find Prior Art