CLIP2Protect: Protecting Facial Privacy Using Text-Guided Makeup via Adversarial Latent Search
Fahad ShamshadMuzammal NaseerKarthik Nandakumar
Proposes a text-guided generative framework that applies natural-looking adversarial makeup to face images, effectively deceiving commercial black-box face recognition systems while preserving human-perceived identity.
Widespread deployment of automated face recognition systems by commercial and governmental entities poses growing privacy and mass surveillance risks, particularly as images are routinely scraped from public social media platforms. Existing privacy-preserving methods typically add noticeable pixel noise, degrade visual appeal, or alter human-perceived identity, which severely undermines the user experience. The article introduces and evaluates a privacy-protection framework called CLIP2Protect, designed to generate naturalistic, artifact-free facial modifications guided by plain-text makeup descriptions to reliably deceive unknown, proprietary face recognition systems.
The framework operates in two main stages using a pretrained generative image model (StyleGAN) and a vision-language alignment model (CLIP). First, the input face is inverted into the model's internal latent representation, accompanied by fine-tuning of the generator to guarantee near-perfect initial visual reconstruction. Second, the system explores the generative model's latent space to create targeted adversarial modifications guided by user-selected text prompts (such as specific makeup styles) alongside an identity-preserving regularizer that restricts alterations to fine-grained makeup attributes while locking foundational facial geometry. The approach was evaluated against multiple leading black-box face recognition architectures across standard benchmark datasets (CelebA-HQ, LADN, and LFW) as well as commercial face-matching application programming interfaces.
The experimental findings show substantial improvements over existing privacy protection methods. In black-box face verification tests, the framework achieved an average protection success rate of 64.90%, yielding an absolute gain of roughly 12% over the leading unrestricted makeup-transfer technique and about 14% over leading noise-based masking methods. In face identification evaluations, it consistently outperformed baselines across both top-1 and top-5 retrieval settings for impersonation and dodging tasks. Real-world validation against commercial engines, including the Face++ platform, demonstrated superior matching deception scores (averaging between 52.8 and 73.8) compared to prior baselines. Furthermore, the approach exhibited strong image quality with lower visual distortion scores and proved robust across diverse makeup prompts.
These results demonstrate that online facial privacy can be effectively secured without sacrificing image aesthetics or relying on complex, image-paired training datasets. Organizations and platform providers can deploy semantic, text-driven latent adjustments to protect users against non-consensual biometric tracking while maintaining a visually appealing social media experience. As a next step, developing automated mechanisms to recommend optimal text prompts and target identities tailored to individual user images will further streamline usability.
The primary limitation of the method is its computational overhead during the generation phase, which requires iterative generator fine-tuning and latent optimization per image. Nevertheless, the reported evidence provides high confidence in the technique's capability to generalize across diverse black-box models, though stakeholders should account for processing latency in large-scale, real-time deployment environments.
- Paper: StyleCLIP: Text-Driven Manipulation of StyleGAN Imagery, Or Patashnik et al. (2021). This paper establishes the foundational framework for text-guided latent space optimization and manipulation of StyleGAN imagery using CLIP loss, which CLIP2Protect adapts for adversarial makeup generation.
- Paper: Analyzing and Improving the Image Quality of StyleGAN, Tero Karras et al. (2020). This work introduces key advancements in StyleGAN latent space representations and image synthesis quality, providing the generative manifold upon which CLIP2Protect conducts its latent inversion and adversarial search.
- Paper: A Style-Based Generator Architecture for Generative Adversarial Networks, Tero Karras et al. (2019). This foundational paper presents the style-based generator architecture and disentangled latent spaces essential for understanding latent code search and inversion in generative models.
- Paper: ArcFace: Additive Angular Margin Loss for Deep Face Recognition, Jiankang Deng et al. (2018). This paper establishes deep face recognition feature embeddings and margin losses that define the identity verification metrics targeted and perturbed by CLIP2Protect.
- Paper: Improving Transferability of Adversarial Examples With Input Diversity, Cihang Xie et al. (2018). This work introduces techniques for boosting the black-box transferability of adversarial examples, a core evaluation and objective of CLIP2Protect's facial privacy protection.
- Paper: Delving into Transferable Adversarial Examples and Black-box Attacks, Yanpei Liu et al. (2016). This paper provides fundamental principles and optimization strategies for generating transferable adversarial perturbations capable of fooling black-box vision models.
- Paper: Sibling-Attack: Rethinking Transferable Adversarial Attacks against Face Recognition, Zexin Li et al. (2023). This work extends research on black-box adversarial transferability against commercial face recognition platforms using auxiliary multi-task gradient stabilization.
- Paper: DisenBooth: Identity-Preserving Disentangled Tuning for Subject-Driven Text-to-Image Generation, Hong Chen et al. (2024). This work explores identity-preserving text-guided image generation and feature disentanglement in modern generative models, advancing beyond GAN latent space search.
