Adversarial Learning of Privacy-Preserving and Task-Oriented Representations
Taihong Xiao, Yi-Hsuan Tsai, Kihyuk Sohn, Manmohan Chandraker, Ming-Hsuan Yang
Abstract
Data privacy has emerged as an important issue as data-driven deep learning has been an essential component of modern machine learning systems. For instance, there could be a potential privacy risk of machine learning systems via the model inversion attack, whose goal is to reconstruct the input data from the latent representation of deep networks. Our work aims at learning a privacy-preserving and task-oriented representation to defend against such model inversion attacks. Specifically, we propose an adversarial reconstruction learning framework that prevents the latent representations decoded into original input data. By simulating the expected behavior of adversary, our framework is realized by minimizing the negative pixel reconstruction loss or the negative feature reconstruction (i.e., perceptual distance) loss. We validate the proposed method on face attribute prediction, showing that our method allows protecting visual privacy with a small decrease in utility performance. In addition, we show the utility-privacy trade-off with different choices of hyperparameter for negative perceptual distance loss at training, allowing service providers to determine the right level of privacy-protection with a certain utility performance. Moreover, we provide an extensive study with different selections of features, tasks, and the data to further analyze their influence on privacy protection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9a64da30-2f2b-47b8-b04b-87dd98d07a33Cited by top-tier papers14
- SPAct: Self-supervised Privacy Preservation for Action RecognitionIshan Rajendrakumar Dave, Chen Chen, Mubarak ShahCVPR 2022 · 62 citations
- Privacy Assessment on Reconstructed Images: Are Existing Evaluation Metrics Faithful to Human Perception?Xiaoxiao Sun, Nidham Gazagnadou, Vivek Sharma, Lingjuan Lyu et al.NeurIPS 2023 · 26 citations
- NinjaDesc: Content-Concealing Visual Descriptors via Adversarial LearningTony Ng, Hyo Jin Kim, Vincent T. Lee, Daniel DeTone et al.CVPR 2022 · 26 citations
- Purifier: Defending Data Inference Attacks via Transforming Confidence ScoresZiqi Yang, Lijin Wang, Da Yang, Jie Wan et al.AAAI 2023 · 20 citations
- Measuring Data Reconstruction Defenses in Collaborative Inference SystemsMengda Yang, Ziang Li, Juan Wang, Hongxin Hu et al.NeurIPS 2022 · 18 citations
Related papers
- Privacy-preserving Adversarial Facial FeaturesZhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang et al.CVPR 2023
- Inf2Guard: An Information-Theoretic Framework for Learning Privacy-Preserving Representations against Inference AttacksSayedeh Leila Noorbakhsh, Binghui Zhang, Yuan Hong, Binghui WangUSENIX Security 2024 · 17 citations
- InfoDecom: Decomposing Information for Defending Against Privacy Leakage in Split InferenceRuijun Deng, Zhihui Lu, Qiang DuanAAAI 2026
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang et al.CVPR 2021
- Learning Robust and Privacy-Preserving Representations via Information TheoryBinghui Zhang, Sayedeh Leila Noorbakhsh, Yun Dong, Yuan Hong et al.AAAI 2025 · 4 citations
