Adaptive Image Anonymization in the Context of Image Classification with Neural Networks
Nadiya Shvai, Arcadi Llanza Carmona, Amir Nakib
Abstract
Deep learning based methods have become the de-facto standard for various computer vision tasks. Nevertheless, they have repeatedly shown their vulnerability to various form of input perturbations such as pixels modification, region anonymization, etc. which are closely related to the adversarial attacks. This research particularly addresses the case of image anonymization, which is significantly important to preserve privacy and hence to secure digitized form of personal information from being exposed and potentially misused by different services that have captured it for various purposes. However, applying anonymization causes the classifier to provide different class decisions before and after applying it and therefore reduces the classifier’s reliability and usability. In order to achieve a robust solution to this problem we propose a novel anonymization procedure that allows the existing classifiers to become class decision invariant on the anonymized images without any modification requires to apply on the classification models. We conduct numerous experiments on the popular ImageNet benchmark as well as on a large scale industrial toll classification problem’s dataset. Obtained results confirm the efficiency and effectiveness of the proposed method as it obtained 0% rate of class decision change for both datasets compared to 15.95% on ImageNet and 0.18% on toll dataset obtained by applying the naïve anonymization approaches. Moreover, it has shown a great potential to be applied to similar problems from different domains.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 62ec8a67-dde1-40ad-a6db-a732dd8f1ef6Builds on3
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- A Study of Face Obfuscation in ImageNetKaiyu Yang, Jacqueline H. Yau, Li Fei-Fei, Jia Deng et al.ICML 2022 · 163 citations
Related papers
- Hiding Visual Information via Obfuscating Adversarial PerturbationsZhigang Su, Dawei Zhou, Nannan Wang, Decheng Liu et al.ICCV 2023 · 16 citations
- Fake Gradient: A Security and Privacy Protection Framework for DNN-based Image ClassificationXianglong Feng, Yi Xie, Mengmei Ye, Zhongze Tang et al.ACM MM 2021 · 1 citation
- Learnability Lock: Authorized Learnability Control Through Adversarial Invertible TransformationsWeiqi Peng, Jinghui ChenICLR 2022 · 6 citations
- Delegate-based Utility Preserving Synthesis for Pedestrian Image AnonymizationZhenzhong Kuang, Longbin Teng, Zhou Yu, Jun Yu et al.ACM MM 2022 · 4 citations
- Effective De-identification Generative Adversarial Network for Face AnonymizationZhenzhong Kuang, Huigui Liu, Jun Yu, Aikui Tian et al.ACM MM 2021 · 43 citations
