Privacy-Preserving Mechanisms for Multi-Label Image Recognition

Privacy-Preserving Mechanisms for Multi-Label Image Recognition
复制标题

DOI:
10.1145/3491231
复制
发表时间:
2022
期刊:
ACM Trans. Knowl. Discov. Data
影响因子:
--
通讯作者:
Honghui Xu;Zhipeng Cai;Wei Li
Honghui Xu;Zhipeng Cai;Wei Li
中科院分区:
其他
文献类型:
--
作者:
Honghui Xu;Zhipeng Cai;Wei Li

文献摘要

相似文献

多标签图像识别是许多真实的计算机视觉应用的必不可少的基本组成部分。在本文中开发了隐私保护多标签图卷积网络(P2-ML-GCN)和强大的P2-ML-GCN(RP2-ML-GCN),在本文中开发了,其中模型的输出在模型的输出上实现了不同的隐私机制捍卫黑框攻击,尤其是避免使用大的噪声,在RP2-ML-GCN的损失功能中探索了一个受监管的术语,以提高模型的预测准确性和鲁棒性。在P2-ML-GCN中降低损失函数的偏见并提高了预测精度,我们分析了有界的全局灵敏度可以减轻多余的噪声的副作用,并在我们的模型中获得多标签图像识别的性能。理论证明表明,我们的两个模型可以保证模型的输出,权重和输入功能的差异性隐私,同时保留模型鲁棒性。将调节项纳入损失函数,并采用有限的全局灵敏度来识别多标签图像识别。
Multi-label image recognition has been an indispensable fundamental component for many real computer vision applications. However, a severe threat of privacy leakage in multi-label image recognition has been overlooked by existing studies. To fill this gap, two privacy-preserving models, Privacy-Preserving Multi-label Graph Convolutional Networks (P2-ML-GCN) and Robust P2-ML-GCN (RP2-ML-GCN), are developed in this article, where differential privacy mechanism is implemented on the model’s outputs so as to defend black-box attack and avoid large aggregated noise simultaneously. In particular, a regularization term is exploited in the loss function of RP2-ML-GCN to increase the model prediction accuracy and robustness. After that, a proper differential privacy mechanism is designed with the intention of decreasing the bias of loss function in P2-ML-GCN and increasing prediction accuracy. Besides, we analyze that a bounded global sensitivity can mitigate excessive noise’s side effect and obtain a performance improvement for multi-label image recognition in our models. Theoretical proof shows that our two models can guarantee differential privacy for model’s outputs, weights and input features while preserving model robustness. Finally, comprehensive experiments are conducted to validate the advantages of our proposed models, including the implementation of differential privacy on model’s outputs, the incorporation of regularization term into loss function, and the adoption of bounded global sensitivity for multi-label image recognition.