ConfounderGAN: Protecting Image Data Privacy with Causal Confounder
Qi Tian, Kun Kuang, Kelu Jiang, Furui Liu, Zhihua Wang, Fei Wu
摘要
The success of deep learning is partly attributed to the availability of massive data downloaded freely from the Internet. However, it also means that users' private data may be collected by commercial organizations without consent and used to train their models. Therefore, it's important and necessary to develop a method or tool to prevent unauthorized data exploitation. In this paper, we propose ConfounderGAN, a generative adversarial network (GAN) that can make personal image data unlearnable to protect the data privacy of its owners. Specifically, the noise produced by the generator for each image has the confounder property. It can build spurious correlations between images and labels, so that the model cannot learn the correct mapping from images to labels in this noise-added dataset. Meanwhile, the discriminator is used to ensure that the generated noise is small and imperceptible, thereby remaining the normal utility of the encrypted image for humans. The experiments are conducted in six image classification datasets, consisting of three natural object datasets and three medical datasets. The results demonstrate that our method not only outperforms state-of-the-art methods in standard settings, but can also be applied to fast encryption scenarios. Moreover, we show a series of transferability and stability experiments to further illustrate the effectiveness and superiority of our method.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Learning Instrumental Variable from Data Fusion for Treatment Effect EstimationAnpeng Wu, Kun Kuang, Ruoxuan Xiong, Minqing Zhu 等AAAI 2023 · 被引用 10 次
- Versatile Transferable Unlearnable Example GeneratorZhihao Li, Jiale Cai, Gezheng Xu, Hao Zheng 等NeurIPS 2025 · 被引用 3 次
- Task-Oriented Training Data Privacy Protection for Cloud-based Model TrainingZhiqiang Wang, Jiahui Hou, Haifeng Sun, Jingmiao Zhang 等USENIX Security 2025
它引用的顶会 Paper9
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh 等ICCV 2019 · 被引用 5,843 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey 等ICLR 2021 · 被引用 255 次
- Adv-watermark: A Novel Watermark Perturbation for Adversarial ExamplesXiaojun Jia, Xingxing Wei, Xiaochun Cao, Xiaoguang HanACM MM 2020 · 被引用 84 次
- Data Poisoning Won't Save You From Facial RecognitionEvani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini, Florian TramèrICLR 2022 · 被引用 67 次
相关 Paper
- CUDA: Convolution-Based Unlearnable DatasetsVinu Sankar Sadasivan, Mahdi Soltanolkotabi, Soheil FeiziCVPR 2023
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li 等CVPR 2022 · 被引用 123 次
- Ungeneralizable ExamplesJingwen Ye, Xinchao WangCVPR 2024 · 被引用 3 次
- Effective De-identification Generative Adversarial Network for Face AnonymizationZhenzhong Kuang, Huigui Liu, Jun Yu, Aikui Tian 等ACM MM 2021 · 被引用 43 次
- Protecting Intellectual Property of Generative Adversarial Networks From Ambiguity AttacksDing Sheng Ong, Chee Seng Chan, Kam Woh Ng, Lixin Fan 等CVPR 2021
