arXiv:2409.11536cs.CV2024-09被引 7

发现几何混淆方法可被邻域信息逆向恢复,隐私保护无效

Obfuscation Based Privacy Preserving Representations are Recoverable Using Neighborhood Information

  • 利用点云邻域共现特征重建被混淆的原始坐标
  • 在所有现有混淆方案下均能实现高精度点位置还原
  • 警示用户:当前主流混淆技术无法真正保护定位隐私

AR/VR/MR应用和基于云的视觉定位系统兴起,带来用户内容隐私新挑战。深度神经网络可从稀疏的3D/2D点及其描述子中重构出详细场景图像,即“反演攻击”。为防御此类攻击,研究者提出多种几何混淆技术,如将点提升至高维空间(线或面)或交换坐标。本文揭示这些方法存在共同缺陷:在已知邻域关系的前提下,可恢复原始点位置。我们进一步提出通过学习描述子在邻域中的共现模式来推断邻域结构。大量实验表明,该方法对所有现有混淆方案均有效,证明这些方案实际不具备隐私保护能力。代码将公开于https://github.com/kunalchelani/RecoverPointsNeighborhood。

原文摘要 · Abstract (English)

Rapid growth in the popularity of AR/VR/MR applications and cloud-based visual localization systems has given rise to an increased focus on the privacy of user content in the localization process. This privacy concern has been further escalated by the ability of deep neural networks to recover detailed images of a scene from a sparse set of 3D or 2D points and their descriptors - the so-called inversion attacks. Research on privacy-preserving localization has therefore focused on preventing these inversion attacks on both the query image keypoints and the 3D points of the scene map. To this end, several geometry obfuscation techniques that lift points to higher-dimensional spaces, i.e., lines or planes, or that swap coordinates between points % have been proposed. In this paper, we point to a common weakness of these obfuscations that allows to recover approximations of the original point positions under the assumption of known neighborhoods. We further show that these neighborhoods can be computed by learning to identify descriptors that co-occur in neighborhoods. Extensive experiments show that our approach for point recovery is practically applicable to all existing geometric obfuscation schemes. Our results show that these schemes should not be considered privacy-preserving, even though they are claimed to be privacy-preserving. Code will be available at https://github.com/kunalchelani/RecoverPointsNeighborhood.

隐私保护点云安全反演攻击几何混淆

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。