vix.ing · top · new · best · stats · spec

Controllable Inversion of Black-Box Face Recognition Models via Diffusion

2023/03/23 by Manuel Kansy, Kansy, Manuel, Anton Raël +11 · 6 citations
Computer Science · #Computer Vision and Pattern Recognition (cs.CV) #FOS: Computer and information sciences #Face and Expression Recognition #Face recognition and analysis #Generative Adversarial Networks and Image Synthesis #Graphics (cs.GR) #I.2 #I.3.3 #I.4 #Machine Learning (cs.LG)

paper · pdf · doi:10.48550/arxiv.2303.13006

openalex publication_date 2023/03/23 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Face recognition models embed a face image into a low-dimensional identity vector containing abstract encodings of identity-specific facial features that allow individuals to be distinguished from one another. We tackle the challenging task of inverting the latent space of pre-trained face recognition models without full model access (i.e. black-box setting). A variety of methods have been proposed in literature for this task, but they have serious shortcomings such as a lack of realistic outputs and strong requirements for the data set and accessibility of the face recognition model. By analyzing the black-box inversion problem, we show that the conditional diffusion model loss naturally emerges and that we can effectively sample from the inverse distribution even without an identity-specific loss. Our method, named identity denoising diffusion probabilistic model (ID3PM), leverages the stochastic nature of the denoising diffusion process to produce high-quality, identity-preserving face images with various backgrounds, lighting, poses, and expressions. We demonstrate state-of-the-art performance in terms of identity preservation and diversity both qualitatively and quantitatively, and our method is the first black-box face recognition model inversion method that offers intuitive control over the generation process.

Cited by

Related