Towards Privacy-Preserving Visual Recognition via Adversarial Training: A Pilot Study
This paper aims to improve privacy-preserving visual recognition, an increasingly demanded feature in smart camera applications, by formulating a unique adversarial training framework. The proposed framework explicitly learns a degradation transform for the original video inputs, in order to optimize the trade-off between target task performance and the associated privacy budgets on the degraded video. A notable challenge is that the privacy budget, often defined and measured in task-driven contexts, cannot be reliably indicated using any single model performance, because a strong protection of privacy has to sustain against any possible model that tries to hack privacy information. Such an uncommon situation has motivated us to propose two strategies, i.e., budget model restarting and ensemble, to enhance the generalization of the learned degradation on protecting privacy against unseen hacker models. Novel training strategies, evaluation protocols, and result visualization methods have been designed accordingly. Two experiments on privacy-preserving action recognition, with privacy budgets defined in various ways, manifest the compelling effectiveness of the proposed framework in simultaneously maintaining high target task (action recognition) performance while suppressing the privacy breach risk.
Code (3)
Tasks
Action RecognitionPrivacy PreservingTemporal Action LocalizationSimilar Papers 제목 키워드 기반
Modeling the Trade-off of Privacy Preservation and Activity Recognition on Low-Resolution Images
A computer vision system using low-resolution image sensors can provide intelligent services (e.g., activity recognition) but preserve unnecessary visual privacy information from the hardware level. However, preserving v…
Activity RecognitionImage Super-ResolutionPrivacy PreservingSuper-ResolutionPrivacy-preserving Adversarial Facial Features
Face recognition service providers protect face privacy by extracting compact and discriminative facial features (representations) from images, and storing the facial features for real-time recognition. However, such fea…
Face RecognitionPrivacy PreservingPrivHAR: Recognizing Human Actions From Privacy-preserving Lens
The accelerated use of digital cameras prompts an increasing concern about privacy and security, particularly in applications such as action recognition. In this paper, we propose an optimizing framework to provide robus…
Action RecognitionActivity RecognitionPrivacy PreservingTemporal Action LocalizationAdversarial Privacy-preserving Filter
While widely adopted in practical applications, face recognition has been critically discussed regarding the malicious use of face images and the potential privacy problems, e.g., deceiving payment system and causing per…
Adversarial AttackFace RecognitionPrivacy PreservingPrivacy-Preserving Deep Action Recognition: An Adversarial Learning Framework and A New Dataset
We investigate privacy-preserving, video-based action recognition in deep learning, a problem with growing importance in smart camera applications. A novel adversarial training framework is formulated to learn an anonymi…
Action RecognitionPrivacy PreservingPrivacy Preserving Deep Learning