On the Feasibility of Identity Manipulation for Diffusion-Based Face Privacy Preservation
Abstract
Face privacy preservation aims to suppress identity-related information while maintaining realistic facial appearance, for which diffusion models have recently emerged as a powerful paradigm. However, identity manipulation under diffusion-based generation exhibits inconsistent behavior during denoising, where certain perturbations are progressively attenuated while others are amplified into unstable distortions. This phenomenon suggests that identity manipulation is inherently constrained by the underlying diffusion denoising dynamics. In this work, we study the feasibility of identity manipulation under such dynamics and show that effective perturbations exhibit a practical operating regime along the denoising trajectory. Building on this insight, we propose a feasibility-aware diffusion-based identity manipulation framework. The framework anchors latent updates to a reference diffusion state and regularizes optimization toward a diffusion-compatible neighborhood, enabling stable identity suppression without compromising visual fidelity. Extensive experiments demonstrate strong robustness and competitive image quality over existing diffusion-based face privacy methods.