Privacy-Preserving Deep Action Recognition: An Adversarial Learning Framework and A New Dataset

Privacy-Preserving Deep Action Recognition: An Adversarial Learning Framework and A New Dataset
复制标题

DOI:
10.1109/tpami.2020.3026709
复制
发表时间:
2020-09
影响因子:
23.6
通讯作者:
Zhenyu Wu;Haotao Wang;Zhaowen Wang;Hailin Jin;Zhangyang Wang
Zhenyu Wu;Haotao Wang;Zhaowen Wang;Hailin Jin;Zhangyang Wang
中科院分区:
计算机科学1区
文献类型:
--
作者:
Zhenyu Wu;Haotao Wang;Zhaowen Wang;Hailin Jin;Zhangyang Wang

文献摘要

相似文献

我们研究了深度学习中具有隐私性的,基于视频的动作识别,这是智能相机应用中越来越重要的问题。制定了一个新颖的对抗训练框架,以学习输入视频的匿名化转换,以便在目标实用性任务绩效和相关的隐私预算之间进行权衡,从而在匿名视频上明确优化。值得注意的是,通常在任务驱动的上下文中定义和衡量的隐私预算无法可靠地使用任何单一模型绩效表明,因为对隐私的强大保护应维持任何试图窃取私人信息的恶意模型。为了解决这个问题,我们提出了两种新的模型重新启动和模型集合的优化策略,以实现对任何攻击者模型的更强大的普遍隐私保护。已经进行了广泛的实验和分析。另一方面,鉴于公用事业和隐私标签几乎没有公共数据集,数据驱动(监督)学习不能在此任务上发挥其全部功能。我们首先讨论了跨数据库培训和评估的创新启发式启发式,从而使我们的问题使用了多个单任务数据集(一个带有目标任务标签,另一个带有隐私标签)。为了进一步解决此数据集挑战,我们构建了一个新的数据集,该数据集称为PA-HMDB51,具有目标任务标签(动作)和所选隐私属性(肤色,面部,性别,性别,裸体和关系)。这种首先的视频数据集和评估协议可以极大地促进视觉隐私研究并开放其他机会。我们的代码,模型和PA-HMDB51数据集可用:https://github.com/vita-group/pa-hmdb51
We investigate privacy-preserving, video-based action recognition in deep learning, a problem with growing importance in smart camera applications. A novel adversarial training framework is formulated to learn an anonymization transform for input videos such that the trade-off between target utility task performance and the associated privacy budgets is explicitly optimized on the anonymized videos. Notably, the privacy budget, often defined and measured in task-driven contexts, cannot be reliably indicated using any single model performance because strong protection of privacy should sustain against any malicious model that tries to steal private information. To tackle this problem, we propose two new optimization strategies of model restarting and model ensemble to achieve stronger universal privacy protection against any attacker models. Extensive experiments have been carried out and analyzed. On the other hand, given few public datasets available with both utility and privacy labels, the data-driven (supervised) learning cannot exert its full power on this task. We first discuss an innovative heuristic of cross-dataset training and evaluation, enabling the use of multiple single-task datasets (one with target task labels and the other with privacy labels) in our problem. To further address this dataset challenge, we have constructed a new dataset, termed PA-HMDB51, with both target task labels (action) and selected privacy attributes (skin color, face, gender, nudity, and relationship) annotated on a per-frame basis. This first-of-its-kind video dataset and evaluation protocol can greatly facilitate visual privacy research and open up other opportunities. Our codes, models, and the PA-HMDB51 dataset are available at: https://github.com/VITA-Group/PA-HMDB51