LDP-Feat: Image Features with Local Differential Privacy
Francesco Pittaluga, Bingbing Zhuang
Abstract
Modern computer vision services often require users to share raw feature descriptors with an untrusted server. This presents an inherent privacy risk, as raw descriptors may be used to recover the source images from which they were extracted. To address this issue, researchers [11] recently proposed privatizing image features by embedding them within an affine subspace containing the original feature as well as adversarial feature samples. In this paper, we propose two novel inversion attacks to show that it is possible to (approximately) recover the original image features from these embeddings, allowing us to recover privacy-critical image content. In light of such successes and the lack of theoretical privacy guarantees afforded by existing visual privacy methods, we further propose the first method to privatize image features via local differential privacy, which, unlike prior approaches, provides a guaranteed bound for privacy leakage regardless of the strength of the attacks. In addition, our method yields strong performance in visual localization as a downstream task while enjoying the privacy guarantee.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Thinking Racial Bias in Fair Forgery Detection: Models, Datasets and EvaluationsDecheng Liu, Zongqi Wang, Chunlei Peng, Nannan Wang et al.AAAI 2025 · 11 citations
- Efficient Privacy-Preserving Visual Localization Using 3D Ray CloudsHeejoon Moon, Chunghwan Lee, Je Hyeong HongCVPR 2024 · 3 citations
- LDP-Slicing: Local Differential Privacy for Images via Randomized Bit-Plane SlicingYuanming Cao, Chengqi Li, Wenbo HeCVPR 2026 · 2 citations
- Revisiting Geometric Obfuscation with Dual Convergent Lines for Privacy-Preserving Image Queries in Visual LocalizationJeonggon Kim, Heejoon Moon, Je Hyeong HongCVPR 2026 · 1 citation
- Gaussian Splatting Feature Fields for (Privacy-Preserving) Visual LocalizationMaxime Pietrantoni, Gabriela Csurka, Torsten SattlerCVPR 2025
Builds on9
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 629 citations
- Learning With Average Precision: Training Image Retrieval With a Listwise LossJérôme Revaud, Jon Almazán, Rafael S. Rezende, César Roberto de SouzaICCV 2019 · 424 citations
- Adversarial Learning of Privacy-Preserving and Task-Oriented RepresentationsTaihong Xiao, Yi-Hsuan Tsai, Kihyuk Sohn, Manmohan Chandraker et al.AAAI 2020 · 87 citations
- Privacy Preserving Image Queries for Camera LocalizationPablo Speciale, Johannes L. Schönberger, Sudipta N. Sinha, Marc PollefeysICCV 2019 · 44 citations
- NinjaDesc: Content-Concealing Visual Descriptors via Adversarial LearningTony Ng, Hyo Jin Kim, Vincent T. Lee, Daniel DeTone et al.CVPR 2022 · 26 citations
Related papers
- Privacy-Preserving Image Features via Adversarial Affine Subspace EmbeddingsMihai Dusmanu, Johannes L. Schönberger, Sudipta N. Sinha, Marc PollefeysCVPR 2021
- Privacy Preserving Localization via Coordinate PermutationsLinfei Pan, Johannes L. Schönberger, Viktor Larsson, Marc PollefeysICCV 2023 · 10 citations
- Privacy-Preserving Representations are not Enough: Recovering Scene Content from Camera PosesKunal Chelani, Torsten Sattler, Fredrik Kahl, Zuzana KukelovaCVPR 2023
- Black-Box Embedding Inversion Attack on Vector DatabasesLichao Sun, Yuncheng Wu, Haichao Sha, Xinjian Luo et al.KDD 2026
- Privacy-preserving Adversarial Facial FeaturesZhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang et al.CVPR 2023
