Adversarial Image Perturbation for Privacy Protection A Game Theory Perspective

Adversarial Image Perturbation for Privacy Protection A Game Theory Perspective
复制标题

DOI:
10.1109/iccv.2017.165
复制
发表时间:
2017-03
期刊:
2017 IEEE International Conference on Computer Vision (ICCV)
影响因子:
--
通讯作者:
Seong Joon Oh;Mario Fritz;B. Schiele
Seong Joon Oh;Mario Fritz;B. Schiele
中科院分区:
其他
文献类型:
--
作者:
Seong Joon Oh;Mario Fritz;B. Schiele

文献摘要

被引文献

相似文献

用户喜欢通过社交媒体与他人分享个人照片。与此同时,他们可能想让这些照片中的自动识别变得困难甚至不可能。经典的模糊方法,如模糊,不仅令人不快,而且不如预期的那样有效[28,37,18]。对抗性图像扰动(AIP)的最新研究表明,它是可能的,没有令人不快的伪影,有效地混淆识别系统。然而,在存在针对AIP的对抗措施的情况下[7],尚不清楚AIP的有效性,特别是在对抗措施的选择未知的情况下。博弈论提供了工具来研究代理之间的相互作用与不确定性的战略。我们介绍了一个一般的游戏理论框架的用户识别器的动态,并提出了一个案例研究,涉及目前最先进的AIP和个人识别技术。我们推导出最佳的策略,为用户,确保上界的识别率独立的识别器的反措施。代码可在https://goo.gl/hgvbNK上获得。
Users like sharing personal photos with others through social media. At the same time, they might want to make automatic identification in such photos difficult or even impossible. Classic obfuscation methods such as blurring are not only unpleasant but also not as effective as one would expect [28, 37, 18]. Recent studies on adversarial image perturbations (AIP) suggest that it is possible to confuse recognition systems effectively without unpleasant artifacts. However, in the presence of counter measures against AIPs [7], it is unclear how effective AIP would be in particular when the choice of counter measure is unknown. Game theory provides tools for studying the interaction between agents with uncertainties in the strategies. We introduce a general game theoretical framework for the user-recogniser dynamics, and present a case study that involves current state of the art AIP and person recognition techniques. We derive the optimal strategy for the user that assures an upper bound on the recognition rate independent of the recogniser’s counter measure. Code is available at https://goo.gl/hgvbNK.