Subverting Privacy-Preserving GANs: Hiding Secrets in Sanitized Images

被引:0
|
作者
Liu, Kang [1 ]
Tan, Benjamin [1 ]
Garg, Siddharth [1 ]
机构
[1] NYU, Dept Elect & Comp Engn, New York, NY 10003 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Unprecedented data collection and sharing have exacerbated privacy concerns and led to increasing interest in privacy-preserving tools that remove sensitive attributes from images while maintaining useful information for other tasks. Currently, state-of-the-art approaches use privacy-preserving generative adversarial networks (PP-GANs) for this purpose, for instance, to enable reliable facial expression recognition without leaking users' identity. However, PP-GANs do not offer formal proofs of privacy and instead rely on experimentally measuring information leakage using classification accuracy on the sensitive attributes of deep learning (DL)-based discriminators. In this work, we question the rigor of such checks by subverting existing privacy-preserving GANs for facial expression recognition. We show that it is possible to hide the sensitive identification data in the sanitized output images of such PP-GANs for later extraction, which can even allow for reconstruction of the entire input images, while satisfying privacy checks. We demonstrate our approach via a PP-GAN-based architecture and provide qualitative and quantitative evaluations using two public datasets. Our experimental results raise fundamental questions about the need for more rigorous privacy checks of PP-GANs, and we provide insights into the social impact of these.
引用
收藏
页码:14849 / 14856
页数:8
相关论文
共 50 条
  • [41] Privacy-preserving email forensics
    Armknecht, Frederik
    Dewald, Andreas
    DIGITAL INVESTIGATION, 2015, 14 : S127 - S136
  • [42] Privacy-Preserving PayString Service
    de Cristo, Flaviene Scheidt
    Shbair, Wazen M.
    Trestioreanu, Lucian
    Malhotra, Aanchal
    State, Radu
    2021 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2021,
  • [43] Privacy-preserving linear programming
    O. L. Mangasarian
    Optimization Letters, 2011, 5 : 165 - 172
  • [44] Privacy-preserving data mining
    Agrawal, R
    Srikant, R
    SIGMOD RECORD, 2000, 29 (02) : 439 - 450
  • [45] Privacy-preserving webshopping with attributes
    Hampiholi, Brinda
    Alpar, Gergely
    2017 1ST IEEE SYMPOSIUM ON PRIVACY-AWARE COMPUTING (PAC), 2017, : 25 - 36
  • [46] PrivatePool: Privacy-Preserving Ridesharing
    Hallgren, Per
    Orlandi, Claudio
    Sabelfeld, Andrei
    2017 IEEE 30TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF), 2017, : 276 - 291
  • [47] Privacy-preserving set union
    Frikken, Keith
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PROCEEDINGS, 2007, 4521 : 237 - 252
  • [48] Privacy-preserving distributed clustering
    Erkin, Zekeriya
    Veugen, Thijs
    Toft, Tomas
    Lagendijk, Reginald L.
    EURASIP JOURNAL ON INFORMATION SECURITY, 2013, (01):
  • [49] Privacy-Preserving Remote Diagnostics
    Brickell, Justin
    Porter, Donald E.
    Shmatikov, Vitaly
    Witchel, Emmett
    CCS'07: PROCEEDINGS OF THE 14TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2007, : 498 - 507
  • [50] Privacy-Preserving Portrait Matting
    Li, Jizhizi
    Ma, Sihan
    Zhang, Jing
    Tao, Dacheng
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 3501 - 3509