用比特平面加密图像,既防偷窥又可识别
Bit-ViP: Leveraging Bit-planes to Preserve Visual Privacy in Images through Obfuscation

- 按比特位分层处理图像,动态加噪保护隐私
- 在UCF101和HMDB51上保持识别准确率超90%
- 抗重建攻击、抗统计分析,适合云端图像处理
计算机视觉应用的迅猛发展(如监控系统、社交媒体)带来了数据存储于云端时的安全与视觉隐私问题。图像混淆可在保持可用性的同时保护隐私,但现有方法或易受模型逆向攻击,或生成不可训练的图像。本文提出一种基于比特平面的新型图像混淆方案Bit-ViP,通过端到端混淆函数生成安全且可用的图像。混淆图像中嵌入非可逆噪声(由洛伦兹混沌系统与差分隐私生成),使攻击者难以重构原始图像。我们在UCF101和HMDB51两个主流动作识别数据集上进行了大量实验,验证了Bit-ViP的有效性。面对图像重建、像素频率、信息熵及像素相关性等攻击,其安全性能显著优于现有方法。
原文摘要 · Abstract (English)
The unprecedented growth of computer vision applications, such as surveillance systems and social media, raises security and visual privacy concerns, especially when data is stored on cloud servers. Image obfuscation offers a way to preserve visual privacy while maintaining an adequate level of usability; thus, it has been a topic of great interest in recent years. However, prior obfuscation schemes are either vulnerable to malicious attacks, such as model inversion to reconstruct original images from obfuscated images, or generate non-trainable obfuscated images, making them unusable for achieving reasonable accuracy. This paper proposes a novel bit-plane-based image obfuscation scheme, {\em Bit-ViP}, to preserve visual privacy for image-based recognition tasks. The Bit-ViP scheme produces secure, usable images by incorporating an innovative end-to-end obfuscation function. While doing so, the obfuscated image would contain non-invertible noise (generated by Lorenz's chaotic system and differential privacy), making it hard for an adversary to reconstruct the original image. We conduct extensive experiments on two popular activity recognition datasets, namely UCF101 and HMDB51, to validate the effectiveness of Bit-ViP. In the face of attacks on reconstruction, pixel frequency, information entropy, and pixel inter-correlation, we present a rigorous security analysis demonstrating tangible improvements over existing schemes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。