arXiv:2411.16440cs.CV2024-11中稿 · WACV25被引 3

用智能噪声匿名化事件数据,防人防AI识别,保护隐私。

AnonyNoise: Anonymizing Event Data with Smart Noise to Outsmart Re-Identification and Preserve Privacy

  • 引入可学习的、数据相关的噪声,隐藏事件数据中的人脸信息
  • 使攻击者重识别能力降低60%,同时保留下游任务可用信息
  • 对未见数据泛化好,抵御图像重建和逆向攻击,适合安防场景

深度神经网络在重识别方面的进步,加之近年来公共监控的普及,严重威胁个人隐私。事件相机曾被视为潜在解决方案,因其输出稀疏,人类难以理解。但近期深度学习进展表明,神经网络能利用事件数据重建高质量灰度图像并实现个体重识别。本文首次提出事件数据匿名化流程,不仅防范人工重识别,更有效抵御神经网络攻击。方法通过引入可学习的数据相关噪声,覆盖原始事件数据中的敏感信息,使攻击者重识别能力下降最高达60%,同时保持足够信息以支持下游任务。该匿名化方案在未见数据上表现良好,且对图像重建与逆向攻击具有鲁棒性。代码已开源:https://github.com/dfki-av/AnonyNoise。

原文摘要 · Abstract (English)

The increasing capabilities of deep neural networks for re-identification, combined with the rise in public surveillance in recent years, pose a substantial threat to individual privacy. Event cameras were initially considered as a promising solution since their output is sparse and therefore difficult for humans to interpret. However, recent advances in deep learning proof that neural networks are able to reconstruct high-quality grayscale images and re-identify individuals using data from event cameras. In our paper, we contribute a crucial ethical discussion on data privacy and present the first event anonymization pipeline to prevent re-identification not only by humans but also by neural networks. Our method effectively introduces learnable data-dependent noise to cover personally identifiable information in raw event data, reducing attackers' re-identification capabilities by up to 60%, while maintaining substantial information for the performing of downstream tasks. Moreover, our anonymization generalizes well on unseen data and is robust against image reconstruction and inversion attacks. Code: https://github.com/dfki-av/AnonyNoise

隐私保护事件相机数据匿名化对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。