Skip to main content
Kent Academic Repository

An Exploration of Presentation-Level Facial Privacy Protection Systems using Adversarial Techniques

Hasan, Md Rezwan (2026) An Exploration of Presentation-Level Facial Privacy Protection Systems using Adversarial Techniques. Doctor of Philosophy (PhD) thesis, University of Kent. (doi:10.22024/UniKent/01.02.116300) (Access to this publication is currently restricted. You may be able to access a copy if URLs are provided) (KAR id:116300)

PDF
Language: English

Restricted to Repository staff only until September 2029.

Contact us about this publication
[thumbnail of PhD Thesis - Rezwan.pdf]
Official URL:
https://doi.org/10.22024/UniKent/01.02.116300

Abstract

The widespread deployment of face recognition (FR) systems in mobile applications and public surveillance infrastructures has increased concerns over individual privacy, particularly given the immutable and uniquely identifiable nature of facial biometric data. While these systems offer convenience and operational efficiency, they also enable the mass capture and analysis of sensitive personal information, often without explicit consent. This thesis addresses this challenge by focusing on presentation-level facial privacy protection (FPP) systems, a user-controlled, proactive form of protection in which individuals apply measures before or at the point of image acquisition to obscure or alter the facial features available to an unwanted surveillance system. The study treats face detection and face recognition as two distinct intervention points in a surveillance pipeline. It first evaluates whether presentation-level patches can prevent or weaken face detection, and then investigates recognition-stage protection where a face remains detectable but the person's identity is not reliably recovered. Recent advances in adversarial machine learning have demonstrated that deep neural networks (DNNs), which highlight modern FR systems, can be deceived by carefully crafted perturbations. However, most existing FPP methods remain vulnerable under black-box conditions, suffer from poor generalisability across diverse face detectors and recognisers, or are too conspicuous for real-world deployment. To address these limitations, this thesis presents an attention-diversion-based adversarial patch framework for physical facial privacy protection. Leveraging internal attention maps generated via Grad-CAM, the system selectively perturbs high-salience facial regions, aiming to mislead FR systems while trying to preserve a low visual profile. To the best of our knowledge, this is the first work to apply attention-diversion techniques to presentation-level adversarial patches for facial privacy, with a systematic evaluation across both white-box and black-box scenarios using multiple deep FR models. The thesis also introduces a multi-dimensional evaluation framework, incorporating metrics for face-image quality, robustness to an evaluated adversarial countermeasure, and privacy efficacy. Additionally, it proposes a Composite FPP score that combines these measured components within a single evaluation framework. The main contributions of this work are: i. A critical review of presentation-level FPP systems with a focus on adversarial patch strategies; ii. The adaptation and application of attention-diversion mechanisms for facial privacy protection in the physical world; iii. An extensive empirical analysis demonstrating the effectiveness of targeted patch designs across varying facial regions and operational contexts; and iv. A holistic evaluation framework for comparing privacy protection systems under real-world constraints. By advancing the application of attention-guided adversarial perturbations to the domain of presentation-level facial privacy, this thesis offers new insights and tools for safeguarding individual identity in an era of pervasive surveillance. By escalating both the theoretical understanding and practical deployment of presentation-level FPP systems, this thesis provides a meaningful contribution to the development of privacy-preserving technologies in an era of ubiquitous surveillance.

Item Type: Thesis (Doctor of Philosophy (PhD))
Thesis advisor: Guest, Richard
Thesis advisor: Deravi, Farzin
Thesis advisor: Hoque, Sanaul
DOI/Identification number: 10.22024/UniKent/01.02.116300
Uncontrolled keywords: Privacy-Protection Adversarial-Techniques, Face-Recognition Attention-Diversion Biometric-Recognition
Subjects: T Technology
Institutional Unit: Schools > School of Engineering, Mathematics and Physics > Engineering
Former Institutional Unit:
There are no former institutional units.
Funders: European Union (https://ror.org/019w4f821)
Depositing User: System Moodle
Date Deposited: 22 Sep 2026 13:10 UTC
Last Modified: 30 Sep 2026 02:54 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/116300 (The current URI for this page, for reference purposes)

University of Kent Author Information

  • Depositors only (login required):

Total unique views of this page since July 2020. For more details click on the image.