ConfounderGAN: Protecting Image Data Privacy with Causal Confounder
Qi Tian, Kun Kuang, Kelu Jiang, Furui Liu, Zhihua Wang, Fei Wu
Abstract
The success of deep learning is partly attributed to the availability of massive data downloaded freely from the Internet. However, it also means that users' private data may be collected by commercial organizations without consent and used to train their models. Therefore, it's important and necessary to develop a method or tool to prevent unauthorized data exploitation. In this paper, we propose ConfounderGAN, a generative adversarial network (GAN) that can make personal image data unlearnable to protect the data privacy of its owners. Specifically, the noise produced by the generator for each image has the confounder property. It can build spurious correlations between images and labels, so that the model cannot learn the correct mapping from images to labels in this noise-added dataset. Meanwhile, the discriminator is used to ensure that the generated noise is small and imperceptible, thereby remaining the normal utility of the encrypted image for humans. The experiments are conducted in six image classification datasets, consisting of three natural object datasets and three medical datasets. The results demonstrate that our method not only outperforms state-of-the-art methods in standard settings, but can also be applied to fast encryption scenarios. Moreover, we show a series of transferability and stability experiments to further illustrate the effectiveness and superiority of our method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 63e6462a-b0f7-4a41-bcb0-de44d57202a7Cited by top-tier papers3
- Learning Instrumental Variable from Data Fusion for Treatment Effect EstimationAnpeng Wu, Kun Kuang, Ruoxuan Xiong, Minqing Zhu et al.AAAI 2023 · 10 citations
- Versatile Transferable Unlearnable Example GeneratorZhihao Li, Jiale Cai, Gezheng Xu, Hao Zheng et al.NeurIPS 2025 · 3 citations
- Task-Oriented Training Data Privacy Protection for Cloud-based Model TrainingZhiqiang Wang, Jiahui Hou, Haifeng Sun, Jingmiao Zhang et al.USENIX Security 2025
Builds on9
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
- Adv-watermark: A Novel Watermark Perturbation for Adversarial ExamplesXiaojun Jia, Xingxing Wei, Xiaochun Cao, Xiaoguang HanACM MM 2020 · 84 citations
- Data Poisoning Won't Save You From Facial RecognitionEvani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini, Florian TramèrICLR 2022 · 67 citations
Related papers
- CUDA: Convolution-Based Unlearnable DatasetsVinu Sankar Sadasivan, Mahdi Soltanolkotabi, Soheil FeiziCVPR 2023
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li et al.CVPR 2022 · 123 citations
- Ungeneralizable ExamplesJingwen Ye, Xinchao WangCVPR 2024 · 3 citations
- Effective De-identification Generative Adversarial Network for Face AnonymizationZhenzhong Kuang, Huigui Liu, Jun Yu, Aikui Tian et al.ACM MM 2021 · 43 citations
- Protecting Intellectual Property of Generative Adversarial Networks From Ambiguity AttacksDing Sheng Ong, Chee Seng Chan, Kam Woh Ng, Lixin Fan et al.CVPR 2021
