arXiv:2608.04501cs.CV2026-08

系统梳理隐私保护动作识别方法与权衡,推动技术落地。

Privacy-Preserving Action Recognition: Taxonomy, Methods, and Privacy-Utility Trade-offs

论文配图:Privacy-Preserving Action Recognition: Taxonomy, Methods, and Privacy-Utility Trade-offs
图 1 · 摘自论文原文
  • 按五类方法构建隐私-效用二维分类体系
  • 仅10%论文采用正式隐私定义,多数评估标准不统一
  • 提出统一评测协议,助力模型可比性与实际部署

公共安全、医疗及智能环境中的视频监控已成常态,带来个人身份与外貌暴露风险。隐私保护动作识别(PPAR)旨在平衡视频理解效用与隐私泄露风险,近年受广泛关注。但现有综述多局限于单一方法类别,忽略近期对抗与混合方案,且评估体系薄弱。本研究基于PRISMA指南,从885篇文献中筛选32篇(2018–2026)进行系统分析。方法分为五类:对抗学习(52%)、基于骨架(20%)、密码学(12%)、差分隐私(8%)和混合方法(8%),各自呈现不同隐私-效用-效率权衡。评估方面,仅10%论文使用正式隐私定义,65%依赖非标准化指标,40%报告不一致的cMAP值。性能表现差异显著:骨架方法达约85%准确率但丢失外观信息;对抗方法在中等隐私下保持近80%效用(cMAP 0.9至0.3–0.5);差分隐私常低于70%。更严苛场景普遍未充分测试:跨数据集泛化不足15%,自适应攻击测试少于10%,边缘实时部署几乎空白。本文贡献包括二维隐私空间分类、形式化威胁模型、对比权衡分析、PPAR统一评测协议及以基准标准化为核心的路线图,为技术从原型迈向实际应用奠定基础,其经验亦适用于人脸识别与医学影像。

原文摘要 · Abstract (English)

Video surveillance in public safety, healthcare, and smart environments has made continuous human monitoring routine, raising real risks to personal identity and appearance. Privacy-preserving action recognition (PPAR) tackles the tension between the utility of video understanding and this exposure, and has drawn fast-growing interest. However, existing surveys remain narrow. Most catalog a single mechanism family, predate recent adversarial and hybrid work, or barely address evaluation. The result is a fragmented literature with incompatible threat models, inconsistent metrics, and no shared evaluation standard. We address this with a PRISMA-guided review of 32 peer-reviewed papers (2018--2026) drawn from 885 screened records. Methods sort into five families, namely adversarial learning (52%), skeleton-based (20%), cryptographic (12%), differential privacy (8%), and hybrid (8%), each with distinct privacy, utility, and efficiency trade-offs. Evaluation is the weak point. Only 10% of papers adopt a formal privacy definition, 65% rely on ad-hoc metrics, and 40% report an inconsistently defined cMAP. The trade-offs are steep. Skeleton methods reach about 85% accuracy but drop appearance, adversarial methods hold near 80% utility at moderate privacy (cMAP 0.9 to 0.3--0.5), and differential privacy often falls below 70%. Harder conditions stay under-tested, with fewer than 15% of papers checking cross-dataset generalization, under 10% testing adaptive attackers, and real-time edge deployment nearly untouched. We contribute a two-dimensional privacy-space taxonomy, a formal threat model, a comparative trade-off analysis, the PPAR Unified Evaluation Protocol, and a roadmap centered on benchmark standardization. With this grounding, we argue PPAR can move from prototypes toward deployment, with lessons extending to face recognition and medical imaging.

隐私保护动作识别评估标准权衡分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。