paper-with-me

홈 › Papers

Adaptive Hybrid Masking Strategy for Privacy-Preserving Face Recognition Against Model Inversion Attack

2024-03-14 · Yinggui Wang, Yuanqing Huang, Jianshu Li, Le Yang, Kai Song, Lei Wang

The utilization of personal sensitive data in training face recognition (FR) models poses significant privacy concerns, as adversaries can employ model inversion attacks (MIA) to infer the original training data. Existing defense methods, such as data augmentation and differential privacy, have been employed to mitigate this issue. However, these methods often fail to strike an optimal balance between privacy and accuracy. To address this limitation, this paper introduces an adaptive hybrid masking algorithm against MIA. Specifically, face images are masked in the frequency domain using an adaptive MixUp strategy. Unlike the traditional MixUp algorithm, which is predominantly used for data augmentation, our modified approach incorporates frequency domain mixing. Previous studies have shown that increasing the number of images mixed in MixUp can enhance privacy preservation but at the expense of reduced face recognition accuracy. To overcome this trade-off, we develop an enhanced adaptive MixUp strategy based on reinforcement learning, which enables us to mix a larger number of images while maintaining satisfactory recognition accuracy. To optimize privacy protection, we propose maximizing the reward function (i.e., the loss function of the FR system) during the training of the strategy network. While the loss function of the FR network is minimized in the phase of training the FR network. The strategy network and the face recognition network can be viewed as antagonistic entities in the training process, ultimately reaching a more balanced trade-off. Experimental results demonstrate that our proposed hybrid masking scheme outperforms existing defense algorithms in terms of privacy preservation and recognition accuracy against MIA.

📄 PDF Abstract BibTeX arXiv:2403.10558

Code (0)

등록된 구현이 없습니다.

Tasks

Data AugmentationFace RecognitionPrivacy Preserving

Methods 이 논문이 사용한 방법론

Mixup Mixup is a data augmentation technique that generates a weighted combination of random image pairs from the training data. Given two images and their ground truth labels:…

Similar Papers 제목 키워드 기반

AdeptHEQ-FL: Adaptive Homomorphic Encryption for Federated Learning of Hybrid Classical-Quantum Models with Dynamic Layer Sparing

2025-07-09 · Md Abrar Jahin, Taufikur Rahman Fuad, M. F. Mridha, Nafiz Fahad 외 arxiv

Federated Learning (FL) faces inherent challenges in balancing model performance, privacy preservation, and communication efficiency, especially in non-IID decentralized environments. Recent approaches either sacrifice f…

Federated Learning

Vision Token Masking Alone Cannot Prevent PHI Leakage in Medical Document OCR: A Systematic Evaluation

2025-11-23 · Richard J. Young arxiv

Large vision-language models (VLMs) are increasingly deployed for optical character recognition (OCR) in healthcare settings, raising critical concerns about protected health information (PHI) exposure during document pr…

Privacy-Preserving Nonlinear Cloud-based Model Predictive Control via Affine Masking

2021-12-20 · Kaixiang Zhang, Zhaojian Li, Yongqiang Wang, Nan Li

With the advent of 5G technology that presents enhanced communication reliability and ultra low latency, there is renewed interest in employing cloud computing to perform high performance but computationally expensive co…

Cloud ComputingModel Predictive ControlPrivacy Preserving

Privacy-Preserving Data-Enabled Predictive Leading Cruise Control in Mixed Traffic

2022-05-22 · Kaixiang Zhang, Kaian Chen, Zhaojian Li, Jun Chen 외

Data-driven predictive control of connected and automated vehicles (CAVs) has received increasing attention as it can achieve safe and optimal control without relying on explicit dynamical models. However, employing the …

Privacy Preserving

HySparK: Hybrid Sparse Masking for Large Scale Medical Image Pre-Training

2024-08-11 · Fenghe Tang, Ronghao Xu, Qingsong Yao, Xueming Fu 외

The generative self-supervised learning strategy exhibits remarkable learning representational capabilities. However, there is limited attention to end-to-end pre-training methods based on a hybrid architecture of CNN an…

DecoderSelf-Supervised Learning