家用机器人导出的感知数据可能泄露隐私,即使不传原始图像。
Seeing Less Is Not Seeing Safely: Privacy Leakage from Task-Scoped Robot Perception Exports

- 设计任务导向的感知压缩框架,按任务需求控制信息外泄。
- 相同导航成功率下,隐私泄露程度差异高达53%至97%。
- 适用于关注家庭隐私安全的机器人研发与评估人员。
家用机器人依赖丰富感知在私密环境中运行,但即便原始传感器数据保留在本地,隐私风险依然存在。结构化表示如导出至下游规划器、云端服务、日志或学习管道,仍可通过语义、几何、空间结构和任务目标暴露家庭信息。本文提出任务功能感知蒸馏(TFPD)框架,将丰富感知保留在本地,根据任务效用、直接暴露度及多重残余推理风险对下游输出进行建模。基于120个AI2-THOR场景(场景不重叠划分训练/验证/测试集)、冻结攻击者选择和表示感知留出攻击,评估导航、碰撞检测和物体目标执行任务。三种导航输出均实现成功率达1.000,平均路径比为0.898,但表示层可关联性从0.532到0.970不等。将显式目标标签替换为目标区域,使目标类别宏F1从1.000降至0.077,但成功率仍保持在0.995;几何粗化使物体类别宏F1从0.704降至0.556,并带来可测量的碰撞性能损失。ProcTHOR复现验证了任务等价性与隐私不等价的发现,且归一化与拓扑导出的相对排序发生变化。结果表明,单纯移除领域或增强抽象无法建立通用隐私排序,亟需面向任务、多风险的完整公开表示评估。
原文摘要 · Abstract (English)
Domestic robots rely on rich perception to operate in private homes, but privacy risk persists even when raw sensor data remain local. Structured representations exported to downstream planners, cloud services, logs, or learning pipelines can still reveal household information through semantics, geometry, spatial structure, and task targets. We introduce Task-Functional Perception Distillation (TFPD), a task-scoped representation-export framework that keeps rich perception local and profiles downstream exports according to task utility, direct exposure, and multiple residual inference risks. Using 120 AI2-THOR scenes with scene-disjoint train/validation/test splits, frozen attacker selection, and representation-aware held-out attacks, we evaluate navigation, collision checking, and object-goal execution. Three navigation exports achieve identical success (1.000) and mean path ratio (0.898), yet representation-level linkability ranges from 0.532 to 0.970. Replacing an explicit target label with a target region reduces target-category macro-F1 from 1.000 to 0.077 while preserving success at 0.995, while geometric coarsening reduces object-category macro-F1 from 0.704 to 0.556 at a measurable collision-utility cost. A ProcTHOR replication preserves the navigation task-equivalence/privacy-inequivalence finding while changing the relative ordering of normalized and topological exports. These results show that neither field removal nor stronger abstraction induces a universal privacy ordering and motivate task-specific, multi-risk evaluation of the complete public representation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。