arXiv:2603.28605cs.CVcs.CY2026-03中稿 · CVPR被引 2

自动匿名化图像敏感区域,保护隐私同时保持模型可用性。

Unsafe2Safe: Controllable Image Anonymization for Downstream Utility

  • 用多模态扩散编辑仅改敏感区域,保留整体结构和语义。
  • 在多个数据集上显著降低人脸、文字相似度与身份可预测性。
  • 适合需要隐私安全的图像数据集构建与模型训练场景。

大规模图像数据集常包含可识别或敏感内容,训练模型时可能记忆并泄露这些信息,带来隐私风险。我们提出Unsafe2Safe,一个全自动流程,通过视觉语言模型检测隐私风险图像,并利用多模态引导的扩散编辑重写其敏感区域。该流程分两阶段:第一阶段使用视觉语言模型(VLM)分析图像,生成包含与不包含敏感属性的配对图文描述,并由大语言模型生成基于公开描述的结构化、去标识化编辑指令;第二阶段采用指令驱动的扩散编辑器,结合双重文本提示生成隐私安全图像,既保留全局结构和任务相关语义,又消除私密内容。为评估匿名化效果,我们引入涵盖质量、作弊、隐私与效用的统一评估体系。在MS-COCO、Caltech101和MIT Indoor67数据集上,Unsafe2Safe大幅降低人脸相似度、文本相似度及人口统计可预测性,同时下游模型准确率接近原始数据训练水平。通过在自动生成的三元组(私密描述、公开描述、编辑指令)上微调扩散编辑器,进一步提升隐私保护与语义保真度。Unsafe2Safe为构建大规模隐私安全数据集提供了可扩展、有原则的解决方案,兼顾视觉一致性与下游任务效用。

原文摘要 · Abstract (English)

Large-scale image datasets frequently contain identifiable or sensitive content, raising privacy risks when training models that may memorize and leak such information. We present Unsafe2Safe, a fully automated pipeline that detects privacy-prone images and rewrites only their sensitive regions using multimodally guided diffusion editing. Unsafe2Safe operates in two stages. Stage 1 uses a vision-language model to (i) inspect images for privacy risks, (ii) generate paired private and public captions that respectively include and omit sensitive attributes, and (iii) prompt a large language model to produce structured, identity-neutral edit instructions conditioned on the public caption. Stage 2 employs instruction-driven diffusion editors to apply these dual textual prompts, producing privacy-safe images that preserve global structure and task-relevant semantics while neutralizing private content. To measure anonymization quality, we introduce a unified evaluation suite covering Quality, Cheating, Privacy, and Utility dimensions. Across MS-COCO, Caltech101, and MIT Indoor67, Unsafe2Safe reduces face similarity, text similarity, and demographic predictability by large margins, while maintaining downstream model accuracy comparable to training on raw data. Fine-tuning diffusion editors on our automatically generated triplets (private caption, public caption, edit instruction) further improves both privacy protection and semantic fidelity. Unsafe2Safe provides a scalable, principled solution for constructing large, privacy-safe datasets without sacrificing visual consistency or downstream utility.

图像匿名隐私保护扩散模型数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。