Gender Obfuscation: Weaponizing Morphing Attacks for Privacy

Gender Obfuscation through Face Morphing

2021-05-06
Shunxin Wang, Una M. Kelly, Raymond N. J. Veldhuis
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a face morphing-based scheme for gender obfuscation, designed to prevent automated gender classifiers from extracting soft biometric data while maintaining the image's utility for identity verification. By morphing a target face with an "average face" of the opposite gender, the authors successfully degrade gender classification accuracy to near-random levels while preserving high identity verification performance.

TL;DR

Researchers have developed a surprisingly simple yet effective way to hide your gender from AI classifiers without breaking facial recognition systems. By using Face Morphing to blend a face with an "average" face of the opposite gender, the system makes gender prediction nearly impossible (AUC 0.5) while keeping identity verification accuracy as high as 99.9%.

Background: The Privacy Leak in Your Face

Every time you upload a photo for identity verification, you aren't just sharing your identity. You are leaking "soft biometrics"—gender, age, and ethnicity. Under regulations like GDPR, using this data for unauthorized profiling is a major privacy violation. The challenge is: how do you "blur" the gender while keeping the "identity" sharp enough for a security gate?

The Insight: Morphing as a Shield

While the cybersecurity world usually treats Face Morphing as a threat (where one photo represents two people to fool a system), this paper flips the script.

The authors suggest that if you morph a male face with a "prototypical" average female face, you can create a hybrid that inhabits a "gender-neutral" zone in the eyes of a neural network.

The Methodology

The process involves three distinct steps:

  1. Landmark Detection: Identifying 71 specific points on the face.
  2. Morphing (The Core): Using Delaunay Triangulation to warp the geometry () and cross-dissolve the texture () between the subject and an "obfuscator" (the average face).
  3. Blending: The morphed face is pasted into a gender-neutral background using Poisson blending to ensure visual Seamlessness.

Gender Obfuscation Scheme Figure 1: The pipeline from non-obfuscated input to the final gender-protected image.

Finding the "Sweet Spot"

The researchers tested various combinations of warping and blending parameters. They discovered that:

  • (Texture) has a much stronger impact on gender classification than (Shape).
  • The Result: Setting both parameters to 0.5 provides the best balance. It confuses classifiers (like ShuffleNet) while allowing high-end FaceVacs systems to still recognize the individual.
ModuleIdentity Preservation ()Gender Obfuscation ()
FaceVacs99.92%0.077 (Low is good)
ShuffleNet96.48%0.179 (Low is good)

Can the Protection be Broken?

The authors explored two "attack" vectors to see if a malicious actor could recover the hidden gender:

  1. Face Demorphing: Trying to mathematically reverse the blend.
  2. Retraining: Training a new AI specifically to recognize "morphed" genders.

The results were promising for privacy advocates. Even when attackers knew the process, the gender score distributions remained heavily overlapped, making recovery extremely difficult.

Effectiveness of Obfuscation Figure 2: ROC curves showing gender classifiers performing near the diagonal (random guess) after obfuscation.

Critical Insight & Conclusion

This work's elegance lies in its simplicity. Unlike GAN-based approaches which require massive GPU clusters and complex latent space manipulation, landmark-based morphing is computationally "cheap" and visually predictable.

The Takeaway: This approach is particularly potent for identity verification systems already sensitive to morphing attacks. By intentionally "attacking" the image with gender-flipped data, we create a silhouette that is identifiable only to the authorized system, but anonymous to the profiling algorithms.

Limitations: The study primarily focuses on White faces due to the limitations of the Python face_recognition library. Future work must bridge this "diversity gap" to ensure privacy tools are equitable across all ethnicities.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize face morphing or warping techniques specifically for multi-attribute privacy protection (e.g., age and ethnicity obfuscation).
  • Which paper first identified the vulnerability of face recognition systems to morphing attacks, and how does this paper invert that vulnerability for privacy?
  • Investigate how GAN-based facial attribute manipulation compares to traditional landmark-based morphing in terms of identity preservation scores (AUC/EER).
Contents
Gender Obfuscation: Weaponizing Morphing Attacks for Privacy
1. TL;DR
2. Background: The Privacy Leak in Your Face
3. The Insight: Morphing as a Shield
3.1. The Methodology
4. Finding the "Sweet Spot"
5. Can the Protection be Broken?
6. Critical Insight & Conclusion