CamPro: Camera-based Anti-Facial Recognition (2401.00151v1)
Abstract: The proliferation of images captured from millions of cameras and the advancement of facial recognition (FR) technology have made the abuse of FR a severe privacy threat. Existing works typically rely on obfuscation, synthesis, or adversarial examples to modify faces in images to achieve anti-facial recognition (AFR). However, the unmodified images captured by camera modules that contain sensitive personally identifiable information (PII) could still be leaked. In this paper, we propose a novel approach, CamPro, to capture inborn AFR images. CamPro enables well-packed commodity camera modules to produce images that contain little PII and yet still contain enough information to support other non-sensitive vision applications, such as person detection. Specifically, CamPro tunes the configuration setup inside the camera image signal processor (ISP), i.e., color correction matrix and gamma correction, to achieve AFR, and designs an image enhancer to keep the image quality for possible human viewers. We implemented and validated CamPro on a proof-of-concept camera, and our experiments demonstrate its effectiveness on ten state-of-the-art black-box FR models. The results show that CamPro images can significantly reduce face identification accuracy to 0.3\% while having little impact on the targeted non-sensitive vision application. Furthermore, we find that CamPro is resilient to adaptive attackers who have re-trained their FR models using images generated by CamPro, even with full knowledge of privacy-preserving ISP parameters.
- alfa ai. Ai movements scanning. https://www.alfa-ai.com/, 2023.
- Proposal for a standard default color space for the internet—srgb. In Color and imaging conference, 1996.
- Optics lens design for privacy-preserving scene captioning. In 2022 IEEE International Conference on Image Processing (ICIP), 2022.
- Adversarially learned representations for information obfuscation and inference. In International Conference on Machine Learning, 2019.
- Face swapping: automatically replacing faces in photographs. ACM SIGGRAPH 2008 papers, 2008.
- Calipsa. The story of cctv in europe, from resistance to adoption. https://tinyurl.com/bddwnj6c, 2021.
- Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp), 2017.
- Deep learning for sensor-based human activity recognition: Overview, challenges, and opportunities. ACM Computing Surveys (CSUR), 2021a.
- Fall detection system based on real-time pose estimation and svm. 2021 IEEE 2nd International Conference on Big Data, Artificial Intelligence and Internet of Things Engineering (ICBAIE), 2021b.
- Lowkey: Leveraging adversarial attacks to protect social media users from facial recognition. In Proceedings of the International Conference on Learning Representations (ICLR), 2021.
- MMPose Contributors. Openmmlab pose estimation toolbox and benchmark. https://github.com/open-mmlab/mmpose, 2020.
- Sensor-based and vision-based human activity recognition: A comprehensive survey. Pattern Recognition, 2020.
- Arcface: Additive angular margin loss for deep face recognition. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2019.
- Retinaface: Single-shot multi-level face localisation in the wild. 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2020.
- The elements of end-to-end deep face recognition: A survey of recent advances. ACM Computing Surveys (CSUR), 2022.
- Face++. Face searching. https://www.faceplusplus.com/face-searching/, 2022.
- Color correction using root-polynomial regression. IEEE Transactions on Image Processing, 2015.
- Handbook of modern sensors: physics, designs, and applications, volume 3. Springer, 2010.
- Wayne Fulton. What and why is gamma correction in photo images? https://www.scantips.com/lights/gamma2.html, 2022.
- Generative adversarial nets. In NIPS, 2014.
- Explaining and harnessing adversarial examples. CoRR, abs/1412.6572, 2015.
- Google. The hal and camera subsystem. https://tinyurl.com/te8kmj3u, 2022.
- Google. Color space transform. https://tinyurl.com/3xjuftxj, 2023a.
- Google. Tonemap curve. https://tinyurl.com/46uujf8z, 2023b.
- Toward open-set face recognition. 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), 2017.
- Perceptually constrained adversarial attacks. arXiv preprint arXiv:2102.07140, 2021.
- Taylor Hatmaker. Portland passes expansive city ban on facial recognition tech. TechCrunch.[Google Scholar], 2020.
- Learning privacy-preserving optics for human pose estimation. 2021 IEEE/CVF International Conference on Computer Vision (ICCV), 2021.
- Privhar: Recognizing human actions from privacy-preserving lens. In Computer Vision–ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23–27, 2022, Proceedings, Part IV, 2022.
- Image quality metrics: Psnr vs. ssim. In 2010 20th international conference on pattern recognition, 2010.
- Labeled faces in the wild: A database forstudying face recognition in unconstrained environments. In Workshop on faces in’Real-Life’Images: detection, alignment, and recognition, 2008.
- Face/off: Preventing privacy leakage from photos in social networks. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015.
- Walsh Joe. Tiktok settles privacy lawsuit for $92 million. Forbes, 2021.
- The megaface benchmark: 1 million faces for recognition at scale. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2015.
- Adaface: Quality adaptive margin for face recognition. 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2022.
- Adam: A method for stochastic optimization. CoRR, abs/1412.6980, 2014.
- Factors on the sense of privacy in video surveillance. In CARPE ’06, 2006.
- Effective de-identification generative adversarial network for face anonymization. Proceedings of the 29th ACM International Conference on Multimedia, 2021.
- Lavis: A library for language-vision intelligence, 2022a.
- Blip: Bootstrapping language-image pre-training for unified vision-language understanding and generation. In International Conference on Machine Learning, 2022b.
- Microsoft coco: Common objects in context. In European conference on computer vision, 2014.
- Deep learning face attributes in the wild. In Proceedings of International Conference on Computer Vision (ICCV), 2015.
- Decoupled weight decay regularization. In International Conference on Learning Representations, 2017.
- Towards deep learning models resistant to adversarial attacks. ArXiv, abs/1706.06083, 2018.
- Magface: A universal representation for face recognition and quality assessment. 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2021.
- Smart surveillance as an edge network service: From harr-cascade, svm to a lightweight cnn. In 2018 ieee 4th international conference on collaboration and internet computing (cic), 2018.
- Frvt 1:n identification. https://pages.nist.gov/frvt/html/frvt1N.html, 2023a.
- personally identifiable information. https://tinyurl.com/3jcmdbku, 2023b.
- Stuart L Pardau. The california consumer privacy act: Towards a european-style privacy regime in the united states. J. Tech. L. & Pol’y, 2018.
- McKnight Patrick. Historic biometric privacy suit settles for $650 million. Business Law Today, 2021.
- F. Pittaluga and Sanjeev J. Koppal. Privacy preserving optics for miniature vision sensors. 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2015.
- Sensor-level privacy for thermal cameras. 2016 IEEE International Conference on Computational Photography (ICCP), 2016.
- Monitoring covid-19 social distancing with person detection and tracking via fine-tuned yolo v3 and deepsort techniques. arXiv preprint arXiv:2005.01385, 2020.
- Data poisoning won’t save you from facial recognition. In International Conference on Learning Representations, 2022.
- Yolov3: An incremental improvement. arXiv preprint arXiv:1804.02767, 2018.
- Amazon Rekognition. Comparefaces. https://tinyurl.com/j8mrvfad, 2022.
- Self-critical sequence training for image captioning. In Proceedings of the IEEE conference on computer vision and pattern recognition, 2017.
- Cartoon-like avatar generation using facial component matching. International Journal of Multimedia and Ubiquitous Engineering, 2013.
- Ltd. Rockchip Electronics Co. Rockchip Developement Guide ISP20, 2020.
- U-net: Convolutional networks for biomedical image segmentation. In Medical Image Computing and Computer-Assisted Intervention–MICCAI 2015: 18th International Conference, Munich, Germany, October 5-9, 2015, Proceedings, Part III 18, 2015.
- Privacy-preserving human activity recognition from extreme low resolution. In Proceedings of the AAAI conference on artificial intelligence, 2017.
- Facenet: A unified embedding for face recognition and clustering. In Proceedings of the IEEE conference on computer vision and pattern recognition, 2015.
- Fawkes: Protecting privacy against unauthorized deep learning models. In 29th USENIX security symposium (USENIX Security 20), 2020.
- Maya Shwayder. Clearview ai’s facial-recognition app is a nightmare for stalking victims. Digital Trends, 2020.
- Deep high-resolution representation learning for human pose estimation. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2019.
- Optimized transmission of jpeg2000 streams over wireless channels. IEEE Transactions on image processing, 2005.
- Deeppose: Human pose estimation via deep neural networks. In Proceedings of the IEEE conference on computer vision and pattern recognition, 2014.
- Hyperparameter optimization in black-box image processing using differentiable proxies. ACM Transactions on Graphics, 2019.
- ultralytics. yolov5. https://github.com/ultralytics/yolov5, 2022.
- Laurens Van der Maaten and Geoffrey Hinton. Visualizing data using t-sne. Journal of machine learning research, 9(11), 2008.
- Cider: Consensus-based image description evaluation. 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2014.
- Ai coach: Deep human pose estimation and analysis for personalized athletic training assistance. In 27th ACM International Conference on Multimedia, 2019.
- Towards real-world blind face restoration with generative facial prior. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2021.
- Uformer: A general u-shaped transformer for image restoration. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2022a.
- Camshield: Securing smart cameras through physical replication and isolation. In USENIX Security Symposium, 2022b.
- Multiscale structural similarity for image quality assessment. In The Thrity-Seventh Asilomar Conference on Signals, Systems & Computers, 2003, 2003.
- Image quality assessment: from error visibility to structural similarity. IEEE transactions on image processing, 2004.
- Sok: Anti-facial recognition technology. In 2023 IEEE Symposium on Security and Privacy (SP), 2022.
- Towards privacy-preserving visual recognition via adversarial training: A pilot study. ArXiv, abs/1807.08379, 2018.
- Privacy-preserving deep action recognition: An adversarial learning framework and a new dataset. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2020.
- AMD XILINX. Gamma lut. https://tinyurl.com/4n4snxrv, 2022.
- A study of face obfuscation in imagenet. In International Conference on Machine Learning, 2022.
- Towards face encryption by generating adversarial identity masks. In 2021 IEEE/CVF International Conference on Computer Vision (ICCV), 2021.
- Adv-makeup: A new imperceptible and transferable attack on face recognition. arXiv preprint arXiv:2105.03162, 2021.
- Joint face detection and alignment using multitask cascaded convolutional networks. IEEE signal processing letters, 2016.