about
This Person (Probably) Exists. Identity Attacks Against GAN Generated Faces (arxiv.org)
2 points by sohkamyung on Oct 14, 2021 | hide | past | pdf | discuss on HN

In plain words: A new test tells whether a generated face matches a person in the training photos, not an exact copy. It works across face datasets and training setups, and shows that a person who appears often in the data can be exposed in a diverse set.

Abstract · This Person (Probably) Exists. Identity Membership Attacks Against GAN Generated Faces

Recently, generative adversarial networks (GANs) have achieved stunning realism, fooling even human observers. Indeed, the popular tongue-in-cheek website {\small \url{ http://thispersondoesnotexist.com}}, taunts users with GAN generated images that seem too real to believe. On the other hand, GANs do leak information about their training data, as evidenced by membership attacks recently demonstrated in the literature. In this work, we challenge the assumption that GAN faces really are novel creations, by constructing a successful membership attack of a new kind. Unlike previous works, our attack can accurately discern samples sharing the same identity as training samples without being the same samples. We demonstrate the interest of our attack across several popular face datasets and GAN training procedures. Notably, we show that even in the presence of significant dataset diversity, an over represented person can pose a privacy concern.

Ryan Webster, Julien Rabin, Loic Simon, Frederic Jurie
arXiv:2107.06018 · cs.CV, cs.AI · submitted Jul 13, 2021
abstract · pdf · html

add comment on HN