Subverting Privacy-Preserving GANs: Hiding Secrets in Sanitized Images

被引:0
|
作者
Liu, Kang [1 ]
Tan, Benjamin [1 ]
Garg, Siddharth [1 ]
机构
[1] NYU, Dept Elect & Comp Engn, New York, NY 10003 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Unprecedented data collection and sharing have exacerbated privacy concerns and led to increasing interest in privacy-preserving tools that remove sensitive attributes from images while maintaining useful information for other tasks. Currently, state-of-the-art approaches use privacy-preserving generative adversarial networks (PP-GANs) for this purpose, for instance, to enable reliable facial expression recognition without leaking users' identity. However, PP-GANs do not offer formal proofs of privacy and instead rely on experimentally measuring information leakage using classification accuracy on the sensitive attributes of deep learning (DL)-based discriminators. In this work, we question the rigor of such checks by subverting existing privacy-preserving GANs for facial expression recognition. We show that it is possible to hide the sensitive identification data in the sanitized output images of such PP-GANs for later extraction, which can even allow for reconstruction of the entire input images, while satisfying privacy checks. We demonstrate our approach via a PP-GAN-based architecture and provide qualitative and quantitative evaluations using two public datasets. Our experimental results raise fundamental questions about the need for more rigorous privacy checks of PP-GANs, and we provide insights into the social impact of these.
引用
收藏
页码:14849 / 14856
页数:8
相关论文
共 50 条
  • [1] CPA-Secure Privacy-Preserving Reversible Data Hiding for JPEG Images
    Sheidani, Sorour
    Mahmoudi-Aznaveh, Ahmad
    Eslami, Ziba
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 3647 - 3661
  • [2] Privacy-Preserving Reversible Data Hiding for Medical Images Employing Local Rotation
    Su, Guo-Dong
    Lin, Chia-Chen
    Chang, Chin-Chen
    JOURNAL OF HEALTHCARE ENGINEERING, 2021, 2021
  • [3] Hiding in the forest: Privacy-preserving process performance indicators
    Kabierski, Martin
    Fahrenkrog-Petersen, Stephan A.
    Weidlich, Matthias
    INFORMATION SYSTEMS, 2023, 112
  • [4] Privacy-preserving quantum federated learning via gradient hiding
    Li, Changhao
    Kumar, Niraj
    Song, Zhixin
    Chakrabarti, Shouvanik
    Pistoia, Marco
    QUANTUM SCIENCE AND TECHNOLOGY, 2024, 9 (03):
  • [5] On the Efficiency of Privacy-Preserving Path Hiding for Mobile Sensing Applications
    Christin, Delphine
    Reinhardt, Andreas
    Hollick, Matthias
    PROCEEDINGS OF THE 2013 38TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2013), 2013, : 818 - +
  • [6] Hiding outliers into crowd: Privacy-preserving data publishing with outliers
    Wang, Hui
    Liu, Ruilin
    DATA & KNOWLEDGE ENGINEERING, 2015, 100 : 94 - 115
  • [7] Learnable Privacy-Preserving Anonymization for Pedestrian Images
    Zhang, Junwu
    Ye, Mang
    Yang, Yao
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2022, 2022, : 7300 - 7308
  • [8] Privacy-Preserving Remote Sensing Image Generation and Classification With Differentially Private GANs
    Huang, Yujian
    Cao, Lei
    IEEE SENSORS JOURNAL, 2023, 23 (18) : 20805 - 20816
  • [9] Attribute-Hiding Fuzzy Encryption for Privacy-Preserving Data Evaluation
    Chen, Zhenhua
    Huang, Luqi
    Yang, Guomin
    Susilo, Willy
    Fu, Xingbing
    Jia, Xingxing
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2024, 17 (03) : 789 - 803
  • [10] Privacy-Preserving Reversible Information Hiding Based on Arithmetic of Quandratic Residues
    Chang, Ching-Chun
    Li, Chang-Tsun
    Chen, Kaimeng
    IEEE ACCESS, 2019, 7 : 54117 - 54132