用扩散模型可复原被去脸化的脑部MRI,且破坏了重要研究信息。
Pitfalls of defacing whole-head MRI: re-identification risk with diffusion models and compromised research potential
- 用级联扩散模型从去脸图像中重建人脸。
- 重建人脸与原图相似度显著高于平均人脸(p<0.05)。
- 去脸化导致肌肉密度预测失效,影响科研价值。
去脸化常用于公开头部磁共振成像(MRI)数据集以保护隐私,但其实际隐私保护能力及对下游任务的影响尚不明确。随着深度生成模型的发展,去脸化是否仍有效存疑。我们构建了一个级联扩散概率模型(DPM)重脸管道,在180名受试者图像上训练,并在484名未见受试者(其中469人来自不同数据集)图像上测试。结果表明,该模型能生成高保真人脸,表面距离显著优于人群平均脸(p<0.05),且在新数据集上表现良好。同时,我们通过面部体素预测计算机断层扫描(CT)-derived骨骼肌密度,发现使用去脸化图像时斯皮尔曼等级相关系数显著降低(p<10⁻⁴)。对于小腿肌,原始图像相关性显著(p<0.05),而去脸化后不再显著(p>0.05),表明去脸化不仅无法有效保护隐私,还破坏了有价值的科研信息。
原文摘要 · Abstract (English)
Defacing is often applied to head magnetic resonance image (MRI) datasets prior to public release to address privacy concerns. The alteration of facial and nearby voxels has provoked discussions about the true capability of these techniques to ensure privacy as well as their impact on downstream tasks. With advancements in deep generative models, the extent to which defacing can protect privacy is uncertain. Additionally, while the altered voxels are known to contain valuable anatomical information, their potential to support research beyond the anatomical regions directly affected by defacing remains uncertain. To evaluate these considerations, we develop a refacing pipeline that recovers faces in defaced head MRIs using cascaded diffusion probabilistic models (DPMs). The DPMs are trained on images from 180 subjects and tested on images from 484 unseen subjects, 469 of whom are from a different dataset. To assess whether the altered voxels in defacing contain universally useful information, we also predict computed tomography (CT)-derived skeletal muscle radiodensity from facial voxels in both defaced and original MRIs. The results show that DPMs can generate high-fidelity faces that resemble the original faces from defaced images, with surface distances to the original faces significantly smaller than those of a population average face (p < 0.05). This performance also generalizes well to previously unseen datasets. For skeletal muscle radiodensity predictions, using defaced images results in significantly weaker Spearman's rank correlation coefficients compared to using original images (p < 10-4). For shin muscle, the correlation is statistically significant (p < 0.05) when using original images but not statistically significant (p > 0.05) when any defacing method is applied, suggesting that defacing might not only fail to protect privacy but also eliminate valuable information.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。