Privacy-Preserving Deep Neural Networks Using Pixel-Based Image Encryption Without Common Security Keys

Privacy-Preserving Deep Neural Networks Using Pixel-Based Image Encryption Without Common Security Keys
复制标题

DOI:
10.1109/apsipaasc47483.2019.9023091
复制
发表时间:
2019-11
期刊:
2019 Asia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)
影响因子:
--
通讯作者:
Warit Sirichotedumrong;Yuma Kinoshita;H. Kiya
Warit Sirichotedumrong;Yuma Kinoshita;H. Kiya
中科院分区:
其他
文献类型:
--
作者:
Warit Sirichotedumrong;Yuma Kinoshita;H. Kiya

文献摘要

相似文献

我们为深度神经网络(DNN)提出了一种新的隐私保护方案,使我们不仅能够将没有视觉信息的图像应用于DNN,而且还可以考虑使用独立的加密密钥,首次用于训练和测试图像。本文首先提出了一种新的基于像素的图像加密方法,该方法考虑了保持原始图像的属性,用于隐私保护DNN。对于训练,DNN模型在使用独立密钥的情况下使用所提出的方法加密的图像进行训练。为了测试,该模型使我们能够同时应用加密图像和普通图像进行图像分类。因此,不需要管理密钥。在实验中,将所提出的方法应用于众所周知的网络,深度残差网络,用于图像分类。实验结果表明,该方法具有较好的鲁棒性,能够有效抵抗纯密文攻击(COA),且分类性能与使用普通图像的方法相当。此外,结果证实,该方案是能够分类平原图像以及加密图像。
We present a novel privacy-preserving scheme for deep neural networks (DNNs) that enables us not to only apply images without visual information to DNNs but to also consider the use of independent encryption keys, for both training and testing images for the first time. In this paper, a novel pixel-based image encryption method, which considers maintaining the properties of original images, is first proposed for privacy-preserving DNNs. For training, a DNN model is trained with images encrypted by using the proposed method under the use of independent keys. For testing, the model enables us to applied both encrypted images and plain images for image classification. Therefore, there is no need to manage the keys. In an experiment, the proposed method is applied to a well-known network, deep residual networks, for image classification. The experimental results demonstrate that the proposed method with independent encryption keys has robustness against ciphertext-only attack (COA) and can provide almost the same classification performance as that of using plain images. Moreover, the results confirm that the proposed scheme is able to classify plain images as well as encrypted images.