To address privacy leaks and maintain recognition accuracy in face recognition systems, this paper proposes NPDP,a method integrating knowledge distillation and adaptive differential privacy. Leveraging the inherent privacy advantages of frequency domain features while preserving identity information, we design a client-server collaborative framework. On the server side, an enhanced ResNet-18 teacher model extracts deep semantic features via cross-domain attention, guiding a lightweight convolutional student model through multi-level knowledge distillation to boost client-side feature representation. Clients employ a dual-path architecture combining principal component analysis (PCA) and non-negative matrix factorization (NMF) to capture global topology and local discriminative features in frequency space, dynamically fusing features via the student model. To enhance privacy, we introduce a channel attention-guided adaptive noise mechanism that allocates Laplace noise based on frequency channel importance, balancing privacy budgets and accuracy. Experiments on public datasets demonstrate NPDP achieves original model-level accuracy while resisting image reconstruction and identity inference attacks. Compared to existing methods, NPDP improves accuracy by 2%-5% under identical privacy budgets.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Face Recognition Differential Privacy Protection Method Based on NMF and PCA

  • Jingxian Zhou,
  • Yunyan Li,
  • Shuang Wang,
  • Tongkun Xing

摘要

To address privacy leaks and maintain recognition accuracy in face recognition systems, this paper proposes NPDP,a method integrating knowledge distillation and adaptive differential privacy. Leveraging the inherent privacy advantages of frequency domain features while preserving identity information, we design a client-server collaborative framework. On the server side, an enhanced ResNet-18 teacher model extracts deep semantic features via cross-domain attention, guiding a lightweight convolutional student model through multi-level knowledge distillation to boost client-side feature representation. Clients employ a dual-path architecture combining principal component analysis (PCA) and non-negative matrix factorization (NMF) to capture global topology and local discriminative features in frequency space, dynamically fusing features via the student model. To enhance privacy, we introduce a channel attention-guided adaptive noise mechanism that allocates Laplace noise based on frequency channel importance, balancing privacy budgets and accuracy. Experiments on public datasets demonstrate NPDP achieves original model-level accuracy while resisting image reconstruction and identity inference attacks. Compared to existing methods, NPDP improves accuracy by 2%-5% under identical privacy budgets.