Image to Perturbation: An Image Transformation Network for Generating Visually Protected Images for Privacy-Preserving Deep Neural Networks

Image to Perturbation: An Image Transformation Network for Generating Visually Protected Images for Privacy-Preserving Deep Neural Networks
复制标题

DOI:
10.1109/access.2021.3074968
复制
发表时间:
2021-01-01
期刊:
影响因子:
3.9
通讯作者:
Kiya, Hitoshi
Kiya, Hitoshi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Ito, Hiroki;Kinoshita, Yuma;Kiya, Hitoshi

文献摘要

被引文献

相似文献

我们提出了一种新的图像变换网络,用于为保护隐私的深度神经网络(dnn)生成视觉保护图像。本文提出的转换网络通过使用普通图像数据集进行训练,将普通图像转换为具有视觉保护的图像。传统的感知加密方法会导致图像分类的精度下降,并且对最新的攻击不够鲁棒。相比之下,所提出的网络不仅使我们能够保持使用普通图像所达到的图像分类精度,而且对于包括基于dnn的攻击在内的攻击也具有很强的鲁棒性。此外,不需要像传统方法那样管理任何安全密钥。在图像分类实验中,使用ResNet和VGG两种典型的分类网络,证明了所提出的网络在保护平面图像视觉信息的同时保持了较高的分类精度。此外,通过还原普通图像的视觉信息的实验表明,视觉保护后的图像对各种攻击具有足够的鲁棒性。
We propose a novel image transformation network for generating visually protected images for privacy-preserving deep neural networks (DNNs). The proposed transformation network is trained by using a plain image dataset so that plain images are converted into visually protected ones. Conventional perceptual encryption methods cause some accuracy degradation in image classification and are not robust enough against state-of-the-art attacks. In contrast, the proposed network not only enables us to maintain the image classification accuracy that using plain images achieves but is also strongly robust against attacks including DNN-based ones. Furthermore, there is no need to manage any security keys as the conventional methods require. In an image classification experiment, the proposed network is demonstrated to strongly protect the visual information of plain images while maintaining a high classification accuracy under the use of two typical classification networks: ResNet and VGG. In addition, it is shown that the visually protected images are robust enough against various attacks in an experiment in which we tried to restore the visual information of plain images.