提出多任务评估框架,揭示隐私图像变换下分类之外的性能差异。
Beyond Classification: Task-Dependent Learnability under Privacy-Motivated Image Transformations
- 设计轻量级代理任务,覆盖视觉结构不同方面,快速评估隐私变换效果。
- 发现同类分类准确率下,不同隐私技术在其他任务上表现差异显著。
- 适合关注隐私保护与模型性能平衡的研究者和工程实践者。
计算机视觉中的隐私增强技术(PETs)通常依赖噪声或图像扰动,在安全处理视觉数据的同时实现隐私保护,但由此产生任务性能与保护强度之间的权衡。现有评估多基于图像分类,该任务仅反映语义可分性,对几何、空间布局或局部边界变化具有鲁棒性,难以作为通用视觉任务的有效代理。然而,全面下游任务评估计算成本高昂,因需为每种PET变换及参数设置重新训练模型。为此,我们提出一种计算感知的多任务评估协议,通过组合若干轻量级代理任务,针对视觉结构的不同方面进行评估,兼具高效性与代表性。在不可逆隐私变换、基于密钥的块原语以及可学习图像加密方案中,我们验证了:即使分类准确率相近,不同PETs在其他任务上的表现仍存在显著差异。结果强调了应建立超越单一分类报告的评估体系。
原文摘要 · Abstract (English)
Privacy-Enhancing Technologies (PETs) in computer vision often rely on noise or image perturbations to protect visual data while securely processing it, creating a trade-off between task performance and protection. This trade-off is commonly evaluated using image classification, which primarily captures semantic separability and remains robust despite significant geometric, spatial layout or local boundary alterations. As a result, it is too simplistic as a proxy for generic vision tasks. Exhaustive downstream-task evaluation, however, is computationally expensive because models must often be trained for each PET transformation and parameter setting. We therefore propose a compute-aware multi-task protocol for evaluating PETs in model training. It combines lightweight proxy tasks that target complementary aspects of visual structure while remaining simple and fast to compute. Across irreversible privacy transformations, key-based block primitives, and learnable image encryption schemes, we demonstrate that PETs with similar classification accuracy can differ substantially on other tasks. The outcomes highlight the need for PET evaluation protocols that move beyond classification-only reporting.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。