Face De-Identification

Diffusion-based Defense

Destroys any remaining identity signal with noise, and recovers the data distribution with our diffusion model.

Apply Reconstruction?

Applies the reconstruction attack model after de-identification.

Which Reconstructor?

Baseline is trained on de-identified images without diffusion defense. Use Baseline without applying Diffusion-based defense, and you can expect reconstruction that face recognition will find a match for.Diffusion Trained is trained on de-identified images with diffusion defense.

10 1000
1 1000
0 2
10 50000
0.1 1
10 1000
Tracker Type

Determines which type of anchor identities to use. If not Normal, uses precalculated average of identities from the VGGFace2 dataset.

0 1
0 1
0 1
Debug Box

Generates the affine transformation 'bounding box'.

1 99
1 99
0 1
Examples