{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,24]],"date-time":"2026-02-24T16:17:28Z","timestamp":1771949848075,"version":"3.50.1"},"reference-count":55,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2021,1,29]],"date-time":"2021-01-29T00:00:00Z","timestamp":1611878400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,4,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Advances in deep learning have made face recognition technologies pervasive. While useful to social media platforms and users, this technology carries significant privacy threats. Coupled with the abundant information they have about users, service providers can associate users with social interactions, visited places, activities, and preferences\u2013some of which the user may not want to share. Additionally, facial recognition models used by various agencies are trained by data scraped from social media platforms. Existing approaches to mitigate associated privacy risks result in an imbalanced trade-off between privacy and utility. In this paper, we address this trade-off by proposing Face-Off, a privacy-preserving framework that introduces strategic perturbations to images of the user\u2019s face to prevent it from being correctly recognized. To realize Face-Off, we overcome a set of challenges related to the black-box nature of commercial face recognition services, and the scarcity of literature for adversarial attacks on metric networks. We implement and evaluate Face-Off to find that it deceives three commercial face recognition services from Microsoft, Amazon, and Face++. Our user study with 423 participants further shows that the perturbations come at an acceptable cost for the users.<\/jats:p>","DOI":"10.2478\/popets-2021-0032","type":"journal-article","created":{"date-parts":[[2021,4,6]],"date-time":"2021-04-06T21:07:50Z","timestamp":1617743270000},"page":"369-390","source":"Crossref","is-referenced-by-count":22,"title":["Face-Off: Adversarial Face Obfuscation"],"prefix":"10.56553","volume":"2021","author":[{"given":"Varun","family":"Chandrasekaran","sequence":"first","affiliation":[{"name":"University of Wisconsin\u2013Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chuhan","family":"Gao","sequence":"additional","affiliation":[{"name":"Microsoft, work done while at University of Wisconsin\u2013Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brian","family":"Tang","sequence":"additional","affiliation":[{"name":"University of Wisconsin\u2013Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kassem","family":"Fawaz","sequence":"additional","affiliation":[{"name":"University of Wisconsin\u2013Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Somesh","family":"Jha","sequence":"additional","affiliation":[{"name":"University of Wisconsin\u2013Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Suman","family":"Banerjee","sequence":"additional","affiliation":[{"name":"University of Wisconsin\u2013Madison"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2021,1,29]]},"reference":[{"key":"2022042616594477445_j_popets-2021-0032_ref_001_w2aab3b7c38b1b6b1ab1ab1Aa","unstructured":"[1] Techcrunch, \u201cClearview said its facial recognition app was only for law enforcement as it courted private companies,\u201d https:\/\/techcrunch.com\/2020\/02\/27\/clearview-facial-recognition-private-companies\/."},{"key":"2022042616594477445_j_popets-2021-0032_ref_002_w2aab3b7c38b1b6b1ab1ab2Aa","doi-asserted-by":"crossref","unstructured":"[2] S. Ahern, D. Eckles, N. S. Good, S. King, M. Naaman, and R. Nair, \u201cOver-exposed?: Privacy patterns and considerations in online and mobile photo sharing,\u201d in Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, 2007.10.1145\/1240624.1240683","DOI":"10.1145\/1240624.1240683"},{"key":"2022042616594477445_j_popets-2021-0032_ref_003_w2aab3b7c38b1b6b1ab1ab3Aa","doi-asserted-by":"crossref","unstructured":"[3] R. Gross, L. Sweeney, J. Cohn, F. De la Torre, and S. Baker, \u201cFace de-identification,\u201d in Protecting privacy in video surveillance. Springer, 2009, pp. 129\u2013146.10.1007\/978-1-84882-301-3_8","DOI":"10.1007\/978-1-84882-301-3_8"},{"key":"2022042616594477445_j_popets-2021-0032_ref_004_w2aab3b7c38b1b6b1ab1ab4Aa","doi-asserted-by":"crossref","unstructured":"[4] M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, \u201cAccessorize to a crime: Real and stealthy attacks on state-ofthe-art face recognition,\u201d in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2016, pp. 1528\u20131540.10.1145\/2976749.2978392","DOI":"10.1145\/2976749.2978392"},{"key":"2022042616594477445_j_popets-2021-0032_ref_005_w2aab3b7c38b1b6b1ab1ab5Aa","unstructured":"[5] \u2014\u2014, \u201cAdversarial generative nets: Neural network attacks on state-of-the-art face recognition,\u201d arXiv preprint arXiv:1801.00349, 2017."},{"key":"2022042616594477445_j_popets-2021-0032_ref_006_w2aab3b7c38b1b6b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"[6] A. J. Bose and P. Aarabi, \u201cAdversarial attacks on face detectors using neural net based constrained optimization,\u201d arXiv preprint arXiv:1805.12302, 2018.","DOI":"10.1109\/MMSP.2018.8547128"},{"key":"2022042616594477445_j_popets-2021-0032_ref_007_w2aab3b7c38b1b6b1ab1ab7Aa","unstructured":"[7] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \u201cIntriguing properties of neural networks,\u201d arXiv preprint arXiv:1312.6199, 2013."},{"key":"2022042616594477445_j_popets-2021-0032_ref_008_w2aab3b7c38b1b6b1ab1ab8Aa","unstructured":"[8] I. J. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d arXiv preprint arXiv:1412.6572, 2014."},{"key":"2022042616594477445_j_popets-2021-0032_ref_009_w2aab3b7c38b1b6b1ab1ab9Aa","doi-asserted-by":"crossref","unstructured":"[9] N. Carlini and D. Wagner, \u201cTowards evaluating the robustness of neural networks,\u201d in Security and Privacy (SP), 2017 IEEE Symposium on. IEEE, 2017, pp. 39\u201357.10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"2022042616594477445_j_popets-2021-0032_ref_010_w2aab3b7c38b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] F. Schroff, D. Kalenichenko, and J. Philbin, \u201cFacenet: A unified embedding for face recognition and clustering,\u201d in Proceedings of the IEEE conference on computer vision and pattern recognition, 2015, pp. 815\u2013823.10.1109\/CVPR.2015.7298682","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"2022042616594477445_j_popets-2021-0032_ref_011_w2aab3b7c38b1b6b1ab1ac11Aa","doi-asserted-by":"crossref","unstructured":"[11] Y. Taigman, M. Yang, M. Ranzato, and L. Wolf, \u201cDeepface: Closing the gap to human-level performance in face verification,\u201d in Proceedings of the IEEE conference on computer vision and pattern recognition, 2014, pp. 1701\u20131708.10.1109\/CVPR.2014.220","DOI":"10.1109\/CVPR.2014.220"},{"key":"2022042616594477445_j_popets-2021-0032_ref_012_w2aab3b7c38b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] W. Liu, Y. Wen, Z. Yu, M. Li, B. Raj, and L. Song, \u201cSphereface: Deep hypersphere embedding for face recognition,\u201d in The IEEE Conference on Computer Vision and Pattern Recognition (CVPR), vol. 1, 2017.10.1109\/CVPR.2017.713","DOI":"10.1109\/CVPR.2017.713"},{"key":"2022042616594477445_j_popets-2021-0032_ref_013_w2aab3b7c38b1b6b1ab1ac13Aa","doi-asserted-by":"crossref","unstructured":"[13] N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, \u201cPractical black-box attacks against deep learning systems using adversarial examples,\u201d arXiv preprint, 2016.10.1145\/3052973.3053009","DOI":"10.1145\/3052973.3053009"},{"key":"2022042616594477445_j_popets-2021-0032_ref_014_w2aab3b7c38b1b6b1ab1ac14Aa","doi-asserted-by":"crossref","unstructured":"[14] P. Zhao, S. Liu, P.-Y. Chen, N. Hoang, K. Xu, B. Kailkhura, and X. Lin, \u201cOn the design of black-box adversarial examples by leveraging gradient-free optimization and operator splitting method,\u201d in Proceedings of the IEEE International Conference on Computer Vision, 2019, pp. 121\u2013130.10.1109\/ICCV.2019.00021","DOI":"10.1109\/ICCV.2019.00021"},{"key":"2022042616594477445_j_popets-2021-0032_ref_015_w2aab3b7c38b1b6b1ab1ac15Aa","unstructured":"[15] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, \u201cTowards deep learning models resistant to adversarial attacks,\u201d arXiv preprint arXiv:1706.06083, 2017."},{"key":"2022042616594477445_j_popets-2021-0032_ref_016_w2aab3b7c38b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] X. Cao and N. Z. Gong, \u201cMitigating evasion attacks to deep neural networks via region-based classification,\u201d in Proceedings of the 33rd Annual Computer Security Applications Conference. ACM, 2017, pp. 278\u2013287.10.1145\/3134600.3134606","DOI":"10.1145\/3134600.3134606"},{"key":"2022042616594477445_j_popets-2021-0032_ref_017_w2aab3b7c38b1b6b1ab1ac17Aa","unstructured":"[17] Y. Liu, X. Chen, C. Liu, and D. Song, \u201cDelving into transferable adversarial examples and black-box attacks,\u201d arXiv preprint arXiv:1611.02770, 2016."},{"key":"2022042616594477445_j_popets-2021-0032_ref_018_w2aab3b7c38b1b6b1ab1ac18Aa","unstructured":"[18] Microsoft, \u201cAzure face api,\u201d https:\/\/azure.microsoft.com\/en-us\/services\/cognitive-services\/face\/."},{"key":"2022042616594477445_j_popets-2021-0032_ref_019_w2aab3b7c38b1b6b1ab1ac19Aa","unstructured":"[19] Amazon, \u201cAws rekognition,\u201d https:\/\/aws.amazon.com\/rekognition\/."},{"key":"2022042616594477445_j_popets-2021-0032_ref_020_w2aab3b7c38b1b6b1ab1ac20Aa","unstructured":"[20] Face++, \u201cFace++,\u201d https:\/\/www.faceplusplus.com."},{"key":"2022042616594477445_j_popets-2021-0032_ref_021_w2aab3b7c38b1b6b1ab1ac21Aa","unstructured":"[21] Z. Zhang and M. Sabuncu, \u201cGeneralized cross entropy loss for training deep neural networks with noisy labels,\u201d in Advances in neural information processing systems, 2018, pp. 8778\u20138788."},{"key":"2022042616594477445_j_popets-2021-0032_ref_022_w2aab3b7c38b1b6b1ab1ac22Aa","doi-asserted-by":"crossref","unstructured":"[22] R. Feraund, O. J. Bernier, J.-E. Viallet, and M. Collobert, \u201cA fast and accurate face detector based on neural networks,\u201d IEEE Transactions on pattern analysis and machine intelligence, vol. 23, no. 1, pp. 42\u201353, 2001.10.1109\/34.899945","DOI":"10.1109\/34.899945"},{"key":"2022042616594477445_j_popets-2021-0032_ref_023_w2aab3b7c38b1b6b1ab1ac23Aa","unstructured":"[23] M. A. Turk and A. P. Pentland, \u201cFace recognition using eigenfaces,\u201d in Proceedings. 1991 IEEE computer society conference on computer vision and pattern recognition. IEEE Computer Society, 1991, pp. 586\u2013587."},{"key":"2022042616594477445_j_popets-2021-0032_ref_024_w2aab3b7c38b1b6b1ab1ac24Aa","unstructured":"[24] Techcrunch, \u201cFacebook faces fresh criticism over ad targeting sensitive attributes,\u201d https:\/\/techcrunch.com\/2018\/05\/16\/facebook-faces-fresh-criticism-over-ad-targeting-of-sensitive-interests\/."},{"key":"2022042616594477445_j_popets-2021-0032_ref_025_w2aab3b7c38b1b6b1ab1ac25Aa","unstructured":"[25] Wired, \u201cFacebook\u2019s targeted ads are more complex than it lets on,\u201d https:\/\/www.wired.com\/story\/facebooks-targeted-ads-are-more-complex-than-it-lets-on\/."},{"key":"2022042616594477445_j_popets-2021-0032_ref_026_w2aab3b7c38b1b6b1ab1ac26Aa","unstructured":"[26] B. C. for Justice, \u201cThe government is expanding its social media surveillance capabilities,\u201d https:\/\/www.brennancenter.org\/our-work\/analysis-opinion\/government-expanding-its-social-media-surveillance-capabilities."},{"key":"2022042616594477445_j_popets-2021-0032_ref_027_w2aab3b7c38b1b6b1ab1ac27Aa","doi-asserted-by":"crossref","unstructured":"[27] B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. \u0160rndi\u0107, P. Laskov, G. Giacinto, and F. Roli, \u201cEvasion attacks against machine learning at test time,\u201d in Joint European conference on machine learning and knowledge discovery in databases. Springer, 2013, pp. 387\u2013402.10.1007\/978-3-642-40994-3_25","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"2022042616594477445_j_popets-2021-0032_ref_028_w2aab3b7c38b1b6b1ab1ac28Aa","doi-asserted-by":"crossref","unstructured":"[28] K. Zhang, Z. Zhang, Z. Li, and Y. Qiao, \u201cJoint face detection and alignment using multitask cascaded convolutional networks,\u201d IEEE Signal Processing Letters, vol. 23, no. 10, pp. 1499\u20131503, 2016.","DOI":"10.1109\/LSP.2016.2603342"},{"key":"2022042616594477445_j_popets-2021-0032_ref_029_w2aab3b7c38b1b6b1ab1ac29Aa","unstructured":"[29] N. Papernot, P. McDaniel, and I. Goodfellow, \u201cTransferability in machine learning: from phenomena to black-box attacks using adversarial samples,\u201d arXiv preprint arXiv:1605.07277, 2016."},{"key":"2022042616594477445_j_popets-2021-0032_ref_030_w2aab3b7c38b1b6b1ab1ac30Aa","unstructured":"[30] B. Biggio, B. Nelson, and P. Laskov, \u201cPoisoning attacks against support vector machines,\u201d arXiv preprint arXiv:1206.6389, 2012."},{"key":"2022042616594477445_j_popets-2021-0032_ref_031_w2aab3b7c38b1b6b1ab1ac31Aa","doi-asserted-by":"crossref","unstructured":"[31] Y. Wen, K. Zhang, Z. Li, and Y. Qiao, \u201cA discriminative feature learning approach for deep face recognition,\u201d in European Conference on Computer Vision. Springer, 2016, pp. 499\u2013515.10.1007\/978-3-319-46478-7_31","DOI":"10.1007\/978-3-319-46478-7_31"},{"key":"2022042616594477445_j_popets-2021-0032_ref_032_w2aab3b7c38b1b6b1ab1ac32Aa","unstructured":"[32] Google, \u201cKeras,\u201d https:\/\/keras.io."},{"key":"2022042616594477445_j_popets-2021-0032_ref_033_w2aab3b7c38b1b6b1ab1ac33Aa","unstructured":"[33] \u2014\u2014, \u201cTensorflow,\u201d https:\/\/www.tensorflow.org."},{"key":"2022042616594477445_j_popets-2021-0032_ref_034_w2aab3b7c38b1b6b1ab1ac34Aa","unstructured":"[34] \u2014\u2014, \u201cCleverhans,\u201d https:\/\/github.com\/tensorflow\/cleverhans."},{"key":"2022042616594477445_j_popets-2021-0032_ref_035_w2aab3b7c38b1b6b1ab1ac35Aa","unstructured":"[35] G. B. Huang, M. Mattar, T. Berg, and E. Learned-Miller, \u201cLabeled faces in the wild: A database for studying face recognition in unconstrained environments,\u201d 2008."},{"key":"2022042616594477445_j_popets-2021-0032_ref_036_w2aab3b7c38b1b6b1ab1ac36Aa","doi-asserted-by":"crossref","unstructured":"[36] Q. Cao, L. Shen, W. Xie, O. M. Parkhi, and A. Zisserman, \u201cVggface2: A dataset for recognising faces across pose and age,\u201d in 2018 13th IEEE International Conference on Automatic Face & Gesture Recognition (FG 2018). IEEE, 2018, pp. 67\u201374.10.1109\/FG.2018.00020","DOI":"10.1109\/FG.2018.00020"},{"key":"2022042616594477445_j_popets-2021-0032_ref_037_w2aab3b7c38b1b6b1ab1ac37Aa","doi-asserted-by":"crossref","unstructured":"[37] Y. Guo, L. Zhang, Y. Hu, X. He, and J. Gao, \u201cMs-celeb-1m: A dataset and benchmark for large-scale face recognition,\u201d in European conference on computer vision. Springer, 2016, pp. 87\u2013102.10.1007\/978-3-319-46487-9_6","DOI":"10.1007\/978-3-319-46487-9_6"},{"key":"2022042616594477445_j_popets-2021-0032_ref_038_w2aab3b7c38b1b6b1ab1ac38Aa","unstructured":"[38] D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry, \u201cRobustness may be at odds with accuracy,\u201d arXiv preprint arXiv:1805.12152, 2018."},{"key":"2022042616594477445_j_popets-2021-0032_ref_039_w2aab3b7c38b1b6b1ab1ac39Aa","doi-asserted-by":"crossref","unstructured":"[39] G. R. Milne and M. J. Culnan, \u201cStrategies for reducing online privacy risks: Why consumers read (or don\u2019t read) online privacy notices,\u201d Journal of Interactive Marketing, vol. 18, no. 3, pp. 15 \u2013 29, 2004.10.1002\/dir.20009","DOI":"10.1002\/dir.20009"},{"key":"2022042616594477445_j_popets-2021-0032_ref_040_w2aab3b7c38b1b6b1ab1ac40Aa","doi-asserted-by":"crossref","unstructured":"[40] H. J. Smith, S. J. Milberg, and S. J. Burke, \u201cInformation privacy: Measuring individuals\u2019 concerns about organizational practices,\u201d MIS Quarterly, vol. 20, no. 2, pp. 167\u2013196, 1996. [Online]. Available: http:\/\/www.jstor.org\/stable\/24947710.2307\/249477","DOI":"10.2307\/249477"},{"key":"2022042616594477445_j_popets-2021-0032_ref_041_w2aab3b7c38b1b6b1ab1ac41Aa","unstructured":"[41] S. Holm, \u201cA simple sequentially rejective multiple test procedure,\u201d Scandinavian Journal of Statistics, vol. 6, no. 2, pp. 65\u201370, 1979. [Online]. Available: http:\/\/www.jstor.org\/stable\/4615733"},{"key":"2022042616594477445_j_popets-2021-0032_ref_042_w2aab3b7c38b1b6b1ab1ac42Aa","doi-asserted-by":"crossref","unstructured":"[42] A. Besmer and H. Richter Lipford, \u201cMoving beyond untagging: Photo privacy in a tagged world,\u201d in Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, ser. CHI \u201910. New York, NY, USA: ACM, 2010, pp. 1563\u20131572. [Online]. Available: http:\/\/doi.acm.org\/10.1145\/1753326.175356010.1145\/1753326.1753560","DOI":"10.1145\/1753326.1753560"},{"key":"2022042616594477445_j_popets-2021-0032_ref_043_w2aab3b7c38b1b6b1ab1ac43Aa","unstructured":"[43] J. Buolamwini and T. Gebru, \u201cGender shades: Intersectional accuracy disparities in commercial gender classification,\u201d in Conference on fairness, accountability and transparency, 2018, pp. 77\u201391."},{"key":"2022042616594477445_j_popets-2021-0032_ref_044_w2aab3b7c38b1b6b1ab1ac44Aa","unstructured":"[44] F. Tram\u00e8r, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, \u201cThe Space of Transferable Adversarial Examples,\u201d ArXiv e-prints, Apr. 2017."},{"key":"2022042616594477445_j_popets-2021-0032_ref_045_w2aab3b7c38b1b6b1ab1ac45Aa","unstructured":"[45] J. M. Cohen, E. Rosenfeld, and J. Z. Kolter, \u201cCertified adversarial robustness via randomized smoothing,\u201d in Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, Long Beach, California, USA, 2019, pp. 1310\u20131320. [Online]. Available: http:\/\/proceedings.mlr.press\/v97\/cohen19c.html"},{"key":"2022042616594477445_j_popets-2021-0032_ref_046_w2aab3b7c38b1b6b1ab1ac46Aa","doi-asserted-by":"crossref","unstructured":"[46] S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, \u201cUniversal adversarial perturbations,\u201d arXiv preprint, 2017.10.1109\/CVPR.2017.17","DOI":"10.1109\/CVPR.2017.17"},{"key":"2022042616594477445_j_popets-2021-0032_ref_047_w2aab3b7c38b1b6b1ab1ac47Aa","unstructured":"[47] F. Tram\u00e8r, A. Kurakin, N. Papernot, D. Boneh, and P. McDaniel, \u201cEnsemble adversarial training: Attacks and defenses,\u201d arXiv preprint arXiv:1705.07204, 2017."},{"key":"2022042616594477445_j_popets-2021-0032_ref_048_w2aab3b7c38b1b6b1ab1ac48Aa","doi-asserted-by":"crossref","unstructured":"[48] A. Rajabi, R. B. Bobba, M. Rosulek, C. V. Wright, and W.-c. Feng, \u201cOn the (im)practicality of adversarial perturbation for image privacy,\u201d in 21st Privacy Enhancing Technologies Symposium ({PETS} 21), 2021, pp. 95\u2013106.10.2478\/popets-2021-0006","DOI":"10.2478\/popets-2021-0006"},{"key":"2022042616594477445_j_popets-2021-0032_ref_049_w2aab3b7c38b1b6b1ab1ac49Aa","unstructured":"[49] S. Sabour, Y. Cao, F. Faghri, and D. J. Fleet, \u201cAdversarial manipulation of deep representations,\u201d arXiv preprint arXiv:1511.05122, 2015."},{"key":"2022042616594477445_j_popets-2021-0032_ref_050_w2aab3b7c38b1b6b1ab1ac50Aa","doi-asserted-by":"crossref","unstructured":"[50] J. Jia and N. Z. Gong, \u201cDefending against machine learning based inference attacks via adversarial examples: Opportunities and challenges,\u201d 2019.10.1007\/978-3-030-33432-1_2","DOI":"10.1007\/978-3-030-33432-1_2"},{"key":"2022042616594477445_j_popets-2021-0032_ref_051_w2aab3b7c38b1b6b1ab1ac51Aa","doi-asserted-by":"crossref","unstructured":"[51] N. Raval, A. Machanavajjhala, and L. P. Cox, \u201cProtecting visual secrets using adversarial nets,\u201d in 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). IEEE, 2017, pp. 1329\u20131332.10.1109\/CVPRW.2017.174","DOI":"10.1109\/CVPRW.2017.174"},{"key":"2022042616594477445_j_popets-2021-0032_ref_052_w2aab3b7c38b1b6b1ab1ac52Aa","doi-asserted-by":"crossref","unstructured":"[52] Q. Sun, L. Ma, S. Joon Oh, L. Van Gool, B. Schiele, and M. Fritz, \u201cNatural and effective obfuscation by head inpainting,\u201d in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2018, pp. 5050\u20135059.10.1109\/CVPR.2018.00530","DOI":"10.1109\/CVPR.2018.00530"},{"key":"2022042616594477445_j_popets-2021-0032_ref_053_w2aab3b7c38b1b6b1ab1ac53Aa","doi-asserted-by":"crossref","unstructured":"[53] Q. Sun, A. Tewari, W. Xu, M. Fritz, C. Theobalt, and B. Schiele, \u201cA hybrid model for identity obfuscation by face replacement,\u201d in Proceedings of the European Conference on Computer Vision (ECCV), 2018, pp. 553\u2013569.10.1007\/978-3-030-01246-5_34","DOI":"10.1007\/978-3-030-01246-5_34"},{"key":"2022042616594477445_j_popets-2021-0032_ref_054_w2aab3b7c38b1b6b1ab1ac54Aa","unstructured":"[54] R. McPherson, R. Shokri, and V. Shmatikov, \u201cDefeating image obfuscation with deep learning,\u201d arXiv preprint arXiv:1609.00408, 2016."},{"key":"2022042616594477445_j_popets-2021-0032_ref_055_w2aab3b7c38b1b6b1ab1ac55Aa","unstructured":"[55] S. Shan, E. Wenger, J. Zhang, H. Li, H. Zheng, and B. Y. Zhao, \u201cFawkes: Protecting privacy against unauthorized deep learning models,\u201d in 29th {USENIX} Security Symposium ({USENIX} Security 20), 2020, pp. 1589\u20131604."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0032","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:31:28Z","timestamp":1658334688000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0032.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,29]]},"references-count":55,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2021,1,29]]},"published-print":{"date-parts":[[2021,4,1]]}},"alternative-id":["10.2478\/popets-2021-0032"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0032","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,29]]}}}