用虚拟角色替换视频中的人,保护隐私同时提升模型性能。
Activity Recognition on Avatar-Anonymized Datasets with Masked Differential Privacy
- 用合成头像替换真实人物,实现上下文一致的隐私化数据
- 提出掩码差分隐私,在局部区域应用隐私保护,减少性能损失
- 在ε<1的严格隐私要求下,效果优于传统差分隐私方法
隐私保护计算机视觉是机器学习与人工智能中的重要新兴问题。现有方法多采用差分隐私(DP)或模糊化技术保护个人隐私,但常导致模型性能大幅下降。本文提出一种匿名化流程:在视频数据集中,以合成虚拟角色替换敏感人物,结合渲染与稳定扩散策略实现上下文一致的替换。此外,提出掩码差分隐私(MaskDP),可选择性对敏感区域施加差分隐私,而非对整个输入应用。该方法在保证强隐私保护的同时,显著降低传统隐私保护方法带来的性能损耗。在多个具有挑战性的动作识别数据集上的实验表明,相比标准差分隐私训练,本方法在ε<1的严苛隐私条件下实现了更优的隐私-效用权衡。
原文摘要 · Abstract (English)
Privacy-preserving computer vision is an important emerging problem in machine learning and artificial intelligence. Prevalent methods tackling this problem use differential privacy (DP) or obfuscation techniques to protect the privacy of individuals. In both cases, the utility of the trained model is sacrificed heavily in this process. In this work, we present an anonymization pipeline that replaces sensitive human subjects in video datasets with synthetic avatars within context, employing a combined rendering and stable diffusion-based strategy. Additionally we propose masked differential privacy ({MaskDP}) to protect non-anonymized but privacy sensitive background information. MaskDP allows for controlling sensitive regions where differential privacy is applied, in contrast to applying DP on the entire input. This combined methodology provides strong privacy protection while minimizing the usual performance penalty of privacy preserving methods. Experiments on multiple challenging action recognition datasets demonstrate that our proposed techniques result in better utility-privacy trade-offs compared to standard differentially private training in the especially demanding $ε<1$ regime.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。