A pedestrian identity privacy protection method combined with k-anonymity

By combining k-anonymous and anonymous pedestrian generation adversarial network (PPAGAN), as well as cross-identity training strategies, the problem of pedestrian identity privacy protection in the existing technology is solved, and the generation of high-quality anonymous images and the retention of data availability is achieved.

CN114036553BActive Publication Date: 2025-05-13HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111261508.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-28
Publication Date
2025-05-13
Estimated Expiration
2041-10-28

AI Technical Summary

Technical Problem

It is difficult for the existing technology to effectively protect the identity privacy of pedestrians, especially after the development of deep neural networks, traditional visual encryption algorithms and blurred image privacy protection methods such as blurred and mosaic are easily restored, resulting in privacy leakage.

Method used

A method of pedestrian identity privacy protection combining k anonymity is proposed to generate higher quality anonymous images by constructing an anonymous pedestrian generation adversarial network (PPAGAN) and cross-identity training strategy, and to preserve the privacy and availability of pedestrian image data through the designed k anonymous privacy protection method.

Benefits of technology

It realizes effective anonymity of pedestrian identities, improves the quality of generated images, while retaining data availability, and avoiding privacy leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114036553B_ABST
    Figure CN114036553B_ABST
Patent Text Reader

Abstract

The present invention proposes a pedestrian identity privacy protection method combined with k-anonymity. The present invention generates higher quality anonymous images through a cross-identity training strategy; finally, through the designed k-anonymity privacy protection method, the privacy of pedestrian image data is retained while also retaining the availability of data; specific steps: Step 1: Proxy data set acquisition and image preprocessing; Step 2: Establishing a k-anonymity mechanism; Step 3: Constructing an anonymous pedestrian generation adversarial network; Step 4: Anonymous pedestrian generation objective function; Step 5: Using a public data set for training and testing, and outputting the final result. The present invention retains both the identity privacy and the attributes of pedestrians. In terms of anonymous pedestrian generation, on the one hand, the method combines the fusion of attributes and target background into the pedestrian generation process, and on the other hand, the method proposes a cross-identity training strategy to improve the quality of the generated image.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the field of image privacy protection and proposes a pedestrian identity privacy protection method combined with k-anonymity. Background Art

[0002] As more and more cameras are deployed in public places and deep neural networks continue to develop, allowing face and pedestrian recognition algorithms to identify privacy-related information more reliably than ever before, it becomes increasingly challenging to avoid the risk of privacy leakage.

[0003] Most of the current privacy protection methods focus on the anonymity of faces, while ignoring the particularity of pedestrian privacy. Therefore, it is urgent to propose a privacy protection method for pedestrians. In order to address the risk of privacy leakage, it is necessary to provide a reliable identity obfuscation method. Ideally, this method should not only effectively hide identity information, but also preserve data availability. In this method, the goal of pedestrian privacy protection is to avoid leaking personal identities in the data and protect data availability, including attributes, behaviors, etc. Unlike faces, both biological and non-biological characteristics may lead to the leakage of pedestrian information (i.e., identity), so we need to anonymize pedestrians as a whole.

[0004] Although traditional visual encryption algorithms directly applied to images protect identity privacy, they also completely eliminate the area of ​​interest, resulting in a significant reduction in the data availability of the encrypted area. With the continuous development of neural networks, image blur privacy protection methods such as blur and mosaic can also be used by neural networks to restore hidden information, resulting in privacy leakage. Privacy protection methods based on deep learning, such as CIAGAN, an anonymization method based on conditional generative adversarial networks that can be used for images and videos, can eliminate facial and body features, while generating images or videos that can be used for detection or tracking tasks. However, the pedestrian images generated by CIAGAN on pedestrian datasets are less authentic. The pedestrian re-identification model DG-Net that can be used for identity exchange and the pedestrian posture conversion PATN can generate high-quality pedestrian images, but neither is suitable for pedestrian anonymity. Among them, DG-Net cannot make pedestrian clothing textures anonymous, and PATN cannot retain the background. In addition, K-Same-Net combines the k-anonymity method and the generative neural network to generate anonymous faces. Among them, K-Same-Net achieves k-anonymity by mapping the identities of at least k people to the same identity. Summary of the invention

[0005] The purpose of the present invention is to provide a pedestrian identity privacy protection method combined with k-anonymity in view of the shortcomings of the prior art. The present invention first proposes a new pedestrian anonymity model PPAGAN for pedestrian anonymity; secondly, a cross-identity training strategy is used to generate higher quality anonymous images; finally, the designed k-anonymity privacy protection method is used to retain the privacy of pedestrian image data while also retaining the availability of the data; the specific implementation steps are as follows:

[0006] Step 1: Proxy dataset collection and image preprocessing;

[0007] Step 2: Establish k-anonymity mechanism;

[0008] Step 3: Build an anonymous pedestrian generation adversarial network;

[0009] Step 4: Generate objective function for anonymous pedestrians;

[0010] Step 5: Use public data sets for training and testing, and output the final results.

[0011] Furthermore, the step 1 represents the collection of data sets and image preprocessing, and the specific steps are as follows:

[0012] 1-1. Proxy dataset collection,collect privacy-insensitive pedestrian images as proxy dataset.

[0013] 1-2. Image labeling: label the identity and attributes of pedestrian images and generate image labels.

[0014] 1-3. Feature extraction: Use the pre-trained pedestrian re-identification model to extract pedestrian image features.

[0015] 1-4. Use the pedestrian posture parser to parse the image and obtain the pedestrian posture.

[0016] 1-5. Use the instance segmentation model to obtain the pedestrian area mask image.

[0017] Furthermore, the step 2 establishes a k-anonymity mechanism, and the specific steps are as follows:

[0018] 2-1. Calculate pedestrian identity features.

[0019] The average characteristics of pedestrians are used as pedestrian identity features, and the specific formula is as follows:

[0020]

[0021] Among them, F i is the identity feature of the pedestrian with identity i, N i is the number of pedestrian images with identity i, is the image feature of the jth image of the pedestrian with identity i.

[0022] The average feature refers to the average value of multiple image features solved from multiple pedestrian images corresponding to a pedestrian;

[0023] 2-2. Identity clustering grouping.

[0024] Pedestrians are grouped according to their attributes, and then feature grouping is performed under each attribute grouping.

[0025] The feature grouping uses a k-means variant algorithm to cluster pedestrian identity features, and makes the number of pedestrians in each cluster the same to obtain the cluster center. For the k pedestrians in the same group, the same proxy pedestrian is used to implement the k-anonymity theory.

[0026] 2-3. Pedestrian agent identity mapping.

[0027] First, the dataset to be anonymized is grouped by identity clustering. Then, the cluster center of the dataset to be anonymized is mapped to the proxy dataset, and the mapping relationship with the minimum mapping distance is used as the target to obtain the pedestrian proxy identity mapping. The mapping distance is specifically formulated as follows:

[0028]

[0029] Where D M represents the mapping distance, n represents the number of clusters, represents the pedestrian identity feature of the i-th cluster center of the dataset to be anonymized, f i represents the identity of the proxy pedestrian mapped by the i-th cluster center, Represents identity as f i The pedestrian identity characteristics of the proxy pedestrian.

[0030] Furthermore, the step 3 constructs an anonymous pedestrian generation adversarial network (PPAGAN, Pose-preserving Person Anonymous Generative Adversarial Network), and the specific steps are as follows:

[0031] 3-1. Build the generator.

[0032] The goal of the generator is to learn S To generate image I G The mapping, and make the generated graph pose K G and the target pose K TThe features of are the same. Pose-Attention Transfer Block (PATB) is used as the generator in PPAGAN. And multiple pose-attention transfer blocks are cascaded; starting from the initial image features and pose features, multiple PATBs gradually update these two features. The final output of PATB is decoded through multiple deconvolution layers and a convolution layer to obtain the generated image I G , while discarding the final posture features. In PPAGAN, 9 PATBs are used to extract image features and posture features through convolutional layers and fully connected layers and input them into the cascaded PATB generator.

[0033] The initial image feature is the source image I S The image features; the posture features include the generated graph posture K G and the target pose K T characteristics.

[0034] 3-2. Build the discriminator.

[0035] The discriminator includes an image discriminator D I and pose discriminator D K , where D I Identify the authenticity of the input image and the similarity between the input image and the input attribute, D K Determine the similarity between the input image and the input pose. I The input includes the (target image, attribute) binary tuple and the (generated image, attribute) binary tuple, and judges whether the former is true or the latter is false. K The input includes the (target image, pose) binary and the (generated image, pose) binary, and judges whether the former is true or the latter is false. I The image features and attribute features are fused through the convolutional layer and the fully connected layer, and the final image authenticity S I is to transform the image discriminator D I The fused image features in are input into three residual blocks. The features of the pose image and the pedestrian image are input into a downsampling convolution layer and three residual blocks to obtain the pose authenticity S K Finally, the image authenticity S I and posture authenticity S K Combination: S = S I S K .

[0036] Furthermore, the anonymous pedestrian generates an objective function in step 4, and the specific steps are as follows:

[0037] 4-1. Combine all pedestrians to generate the objective function. The specific formula is as follows:

[0038] L=λ1L GAN +λ2LI +λ3L F

[0039] Among them, λ1 is the weight of the objective function of GAN, λ2 is the weight of the reconstruction loss objective function, and λ3 is the weight of the identity cross feature loss function. Among them, λ1=10, λ2=10, λ3=1.

[0040] 4-2. Objective function of GAN.

[0041] The core idea of ​​GAN lies in the adversarial game between the generator and the discriminator. The goal of the generator is to generate real images that the discriminator cannot distinguish. The goal of the discriminator is to determine whether the image is generated by the generator. This process can be expressed by the following equation:

[0042]

[0043] Among them, I S ,I T and I G Denote the source image, target image, and generated image respectively, and B T represents the target background, A represents the attribute, K S and K T denote the source pose and target pose respectively.

[0044] 4-3. Reconstruction loss objective function.

[0045] PPAGAN's reconstruction target loss uses pixel-level loss in the pedestrian area, allowing the network to pay more attention to the generation of the target person and its integration with the background. The specific formula is as follows:

[0046] L I =||M T ⊙(I T -I G )||1 (4)

[0047] Among them, ⊙ represents element-wise multiplication, M T It is the binary pedestrian area mask.

[0048] 4-4. Identity cross-feature loss function.

[0049] In the identity cross-training stage, the inter-feature loss is used to constrain the generation of identity cross-pedestrians. Specifically, the image features of pedestrians in the generated image are extracted through the pre-trained pedestrian re-identification model. Different identity cross-feature loss functions are selected according to whether the identities of pedestrians in the source image and the target image are consistent. The specific formula is as follows:

[0050]

[0051] Among them, F Sis the image feature of pedestrians in the source image, F T is the image feature of pedestrians in the target image, F G It is the image feature of pedestrians in the generated image.

[0052] Furthermore, the step 5 trains the model and tests the data, and the specific steps are as follows:

[0053] 5-1. Prepare a dataset, for example, use a public pedestrian dataset (Market1501) and preprocess it as described in step 1 to obtain image labels, features, postures, and pedestrian area masks. Use its training set as a proxy dataset and the test set as a dataset to be anonymized.

[0054] 5-2. Divide the dataset into a training set and a test set, with no duplicate identities between the two, and perform training on the training set.

[0055] 5-3. Use the pedestrian anonymity network trained in steps 3 and 4, combined with pedestrian proxy identity mapping, to generate anonymous pedestrians.

[0056] 5-4. In order to verify the effectiveness of the proposed method, it is compared with the current excellent methods, and the anonymity rate (including pedestrian re-identification rate) and data availability rate (attribute preservation rate, key point preservation rate and image quality) are calculated.

[0057] The beneficial effects of the present invention are:

[0058] In terms of pedestrian anonymity, this method groups pedestrian attributes and generates pedestrian proxy identity mapping by clustering them according to identity features within each attribute group, and finally realizes the k-anonymity mechanism, which preserves both the pedestrian identity privacy and the attributes. In terms of anonymous pedestrian generation, on the one hand, this method combines the fusion of attributes and target background into the pedestrian generation process, and on the other hand, this method proposes a cross-identity training strategy to improve the quality of generated images. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 It is a graph of k-anonymity mechanisms;

[0060] Figure 2 It is an anonymous flow chart;

[0061] Table 1 shows the ablation experiments of each module of this method;

[0062] Table 2 is the experimental results comparing this method with other methods. DETAILED DESCRIPTION

[0063] The present invention will be further described below in conjunction with the accompanying drawings.

[0064] Pedestrian privacy protection technology based on generative adversarial networks, k-anonymity mechanism such as Figure 1 As shown, Figure 1 The k pedestrians in the input data set are mapped to a proxy pedestrian, where k is 2. An ellipse represents a mapping relationship, and the pedestrian in the dotted box is the proxy pedestrian. Figure 2 Anonymous flowchart, the overall framework flowchart is as follows Figure 2 As shown, I T represents the anonymous target pedestrian, I P Indicates the agent, I A represents anonymous pedestrian, B T represents the target background, K P represents the agent pedestrian pose, K T represents the target pedestrian's posture, A represents the attribute, and F K Indicates posture characteristics, F I represents the image features, F F represents the fused image features, D K represents the posture discriminator, D I Represents an image discriminator. The specific implementation steps of the present invention are as follows:

[0065] Step 1: Proxy dataset collection and image preprocessing;

[0066] Step 2: Establish k-anonymity mechanism;

[0067] Step 3: Build an anonymous pedestrian generation adversarial network;

[0068] Step 4: Generate objective function for anonymous pedestrians;

[0069] Step 5: Use public data sets for training and testing, and output the final results.

[0070] Step 1: Collect the proxy data set and preprocess the images. The specific steps are as follows:

[0071] 1-1. Proxy dataset collection: Privacy-insensitive pedestrian images are collected as proxy datasets. This can be done through public pedestrian datasets (such as Market1501) or by recruiting volunteers.

[0072] 1-2. Image labeling: Label the identity and attributes of pedestrian images to generate image labels. For example, the identity of pedestrians can be labeled with n integers from 1 to n, the gender attribute can be labeled with male 0 and female 1, and the top can be labeled with short sleeves 0 and long sleeves 1.

[0073] 1-3. Feature extraction: A person re-identification model based on ResNet50 is used to extract pedestrian image features. The feature is the input before the last fully connected layer of ResNet50, with a dimension of 2048.

[0074] 1-4. Use a pedestrian pose parser (such as OpenPose) to parse the image and obtain the pedestrian pose, which includes 18 key points, such as nose, ears, shoulders, etc.

[0075] 1-5. Use an instance segmentation model (such as Mask RCNN) to obtain a pedestrian region mask image. The pedestrian region mask image is a binary image with the same length and width as the pedestrian image. 1 represents the pedestrian part and 0 represents the background part.

[0076] Step 2: Establish a k-anonymity mechanism. The specific steps are as follows:

[0077] 2-1. Calculate pedestrian identity features. For all images, use the pre-trained pedestrian re-identification model to calculate features, and then use the average features of pedestrian images as pedestrian identity features. The specific formula is as follows:

[0078]

[0079] Among them, F i is the identity feature of the pedestrian with identity i, N i is the number of pedestrian images with identity i, is the feature of the jth image of the pedestrian with identity i.

[0080] 2-2. Identity clustering grouping. Pedestrians are grouped according to their attributes, and then feature grouping is performed under each attribute grouping. The feature grouping algorithm is implemented using the k-means variant algorithm with the same cluster size proposed in the ELKI open source data mining software. This algorithm maintains the size of each cluster cluster and reduces the overall variance by exchanging elements between clusters, and finally converges to a better clustering grouping.

[0081] 2-3. Pedestrian proxy identity mapping. Pedestrian proxy identity mapping refers to the mapping f from the cluster center of the dataset to be anonymized to the identity of the proxy dataset. The mapping distance is specifically calculated using the following formula:

[0082]

[0083] Where D M represents the mapping distance, n represents the number of clusters, represents the pedestrian identity feature of the i-th cluster center of the dataset to be anonymized, f i represents the identity of the proxy pedestrian mapped by the i-th cluster center, Represents identity as f i The final proxy identity mapping f is solved by Get, and in order to meet the diversity of anonymous images, solve the minimum mapping to meet the requirement that for any i, j, there is f i ≠f jWhen the number of clusters under the same attribute grouping of the anonymized data set is not greater than the number of proxy pedestrian identities under the attribute, this problem can be regarded as a weighted bipartite graph maximum matching problem, where the weight is the Euclidean distance between the pedestrian identity features of the cluster center and the proxy pedestrian. And the above conditions can be met by adjusting the value of k, so we can use the Hungarian algorithm to solve the pedestrian proxy identity mapping f.

[0084] Step 3: Build an anonymous pedestrian generation adversarial network. The specific steps are as follows:

[0085] 3-1. The generator generates pedestrians. The features input to the pose-attention transfer block (PATB) include fused image features and pose features, where the fused image features are obtained by fusing attribute features and image features. In order to obtain image features, we superimpose the source pedestrian and target background on the color channel and input them into the convolution layer. In order to obtain attribute features, we input the attribute labels into 7 fully connected layers. The fused image features are obtained by inputting the features superimposed by attribute features and image features into the convolution layer. We stack the heat maps of the source pose and target pose on the depth channel and input them into the convolution layer to obtain pose features. The above three convolution layers have the same structure, which are all three layers of downsampling convolution layers, including batch normalization layers and ReLU activation functions.

[0086] After obtaining the fused image features and posture features, we input them into the first PATB of the 9 cascaded PATBs, and take the output of the previous PATB as the input of the next PATB in turn. Finally, the image features of the final PATB are decoded through 2 deconvolution layers and 1 convolution layer to obtain the decoded image I o . Generate image I G By M T Fusion I o And target background B T , the formula is as follows:

[0087]

[0088] Among them, M T is a binary pedestrian area mask, 1 represents pedestrians, 0 represents background, ⊙ is element-wise multiplication, Added at the element level.

[0089] 3-2. Construct the discriminator. This method includes an image discriminator and a posture discriminator, and the structures are all based on the residual network. Specifically, it includes 1 downsampling layer and 3 residual blocks, and finally outputs through the sigmoid function. The downsampling layer consists of 3 batch normalization layers, 3 ReLU layers, and 3 convolutional layers. The residual block consists of 2 batch normalization layers, 1 ReLU layer, 2 convolutional layers, and 1 DropOut layer, and uses the same residual connection structure as ResNet.

[0090] Step 4: Generate the target function for anonymous pedestrians. The specific steps are as follows:

[0091] 4-1. Combine all pedestrians to generate the objective function. The specific formula is as follows:

[0092] L=λ1L GAN +λ2L I +λ3L F

[0093] Among them, λ1 is the weight of the objective function of GAN, λ2 is the weight of the reconstruction loss objective function, and λ3 is the weight of the identity cross feature loss function. In training, we take λ1=10, λ2=10, and λ3=1.

[0094] Step 5: Train the model and test the data. The specific steps are as follows:

[0095] 5-1. Select a suitable dataset and then preprocess it as described in step 1. For example, the Market-1501 dataset can be used, which includes 32,668 images of 1,501 pedestrians. The training set is used as a proxy dataset, and the test set is used as an anonymous dataset.

[0096] 5-2. The training set in the dataset uses the objective function of step 4 to train the anonymous pedestrian generation adversarial network in step 3. During training, we use the Adam optimizer and set the learning rate to 0.0002, the β1 coefficient to 0.5, the β2 coefficient to 0.999, and the batch size to 32. The network is trained for 700 rounds in total, the first 300 rounds do not include identity crossover, and the last 400 rounds perform identity crossover with a probability of 0.3.

[0097] 5-3. In order to verify the effectiveness of the proposed method, it is compared with traditional methods such as blurring, pixelation, and face removal. It is also compared with deep learning methods such as conditional identity anonymization generative adversarial network CIAGAN and cross-identity pedestrian generation DG-Net. In order to verify the effectiveness of integrating background and attributes, we conducted ablation experiments. We used the calculation of anonymity rate (including pedestrian re-identification rate) and data availability rate (attribute preservation rate, key point preservation rate and image quality) to evaluate our method. The anonymity rate is evaluated by the pre-trained pedestrian re-identification rate. The higher the re-identification rate, the lower the anonymity rate; the attribute preservation rate is evaluated by the pre-trained attribute predictor; the key point preservation rate uses the pre-trained pose recognition model OpenPose to identify key points and is measured by PCKh. Image quality is measured by the structural similarity (SSIM) between the anonymous dataset and the target dataset.

[0098] Experimental Results

[0099] 1. Table 1 is the ablation experiment of each module of this method on the Market1501 dataset.

[0100] 2. Table 2 shows the experimental results of the comparison between this method and the blurring, pixelation, face removal, DG-Net and CIAGAN methods on the Market1501 dataset in terms of anonymity rate, attribute preservation rate, key point preservation rate and image quality indicators;

[0101] Table 1 Ablation experimental results of each module of this method on the Market1501 dataset, A represents the baseline, B represents the fusion background, C represents the fusion attribute, D represents the cross-identity training, k=10.

[0102]

[0103] Table 2 Experimental results of this method compared with other methods on the Market1501 dataset, k = 10

[0104]

Claims

1. A pedestrian identity privacy protection method combined with k-anonymity, characterized in that Firstly, a pedestrian anonymity model, namely anonymous pedestrian generative adversarial network, is proposed for pedestrian anonymity; secondly, anonymous images are generated through cross-identity training strategy; finally, the designed k-anonymity privacy protection method is used to preserve the privacy of pedestrian image data while also preserving the availability of data; the specific implementation steps are as follows: Step 1: Proxy dataset collection and image preprocessing; Step 2: Establish k-anonymity mechanism; Step 3: Build an anonymous pedestrian generation adversarial network; Step 4: Generate objective function for anonymous pedestrians; Step 5: Use public data sets for training and testing, and output the final results; Step 2: Establish a k-anonymity mechanism. The specific steps are as follows: 2-1. Calculate pedestrian identity features; The average characteristics of pedestrians are used as pedestrian identity features, and the specific formula is as follows: Among them, F i is the identity feature of the pedestrian with identity i, N i is the number of pedestrian images with identity i, is the image feature of the jth image of the pedestrian with identity i; The average feature refers to the average value of multiple image features solved from multiple pedestrian images corresponding to a pedestrian; 2-2. Identity clustering grouping; Group pedestrians according to their attributes, and then perform feature grouping under each attribute grouping; The feature grouping uses a k-means variant algorithm to cluster pedestrian identity features, and makes the number of pedestrians in each cluster the same to obtain the cluster center; for the k pedestrians in the same group, the same proxy pedestrian is used to implement the k-anonymity theory; 2-3. Pedestrian agent identity mapping; First, the dataset to be anonymized is clustered and grouped by identity. Secondly, the cluster center of the dataset to be anonymized is mapped to the proxy dataset, and the mapping relationship with the minimum mapping distance is taken as the target to obtain the pedestrian proxy identity mapping. The mapping distance is specifically formulated as follows: Where D M represents the mapping distance, n represents the number of clusters, represents the pedestrian identity feature of the i-th cluster center of the dataset to be anonymized, f i represents the identity of the proxy pedestrian mapped by the i-th cluster center, Represents identity as f i The pedestrian identity characteristics of the agent pedestrian; Step 3: Build an anonymous pedestrian generation adversarial network. The specific steps are as follows: 3-1. Build the generator; The goal of the generator G is to learn S To generate image I G The mapping, and make the generated graph pose K G and the target pose K T The features of the image are the same; the pose-attention transfer block PATB is used as the generator in the anonymous pedestrian generation adversarial network; and multiple pose-attention transfer blocks are cascaded; starting from the initial image features and pose features, multiple PATBs gradually update these two features; the final output of PATB decodes the final image features through multiple deconvolution layers and a convolution layer to obtain the generated image I G , while discarding the final posture features; using 9 PATBs in the anonymous pedestrian generation adversarial network, extracting image features and posture features through convolutional layers and fully connected layers and inputting the cascaded PATB generator; The initial image feature is the source image I S The image features; the posture features include the generated graph posture K G and the target pose K T Features; 3-2. Build the discriminator; The discriminator includes an image discriminator D I and pose discriminator D K , where D I Identify the authenticity of the input image and the similarity between the input image and the input attribute, D K Determine the similarity between the input image and the input pose; D I The input includes the [target image, attribute] tuple and the [generated image, attribute] tuple, and judges whether the former is true or the latter is false; K The input includes the [target image, pose] binary and the [generated image, pose] binary, and judges whether the former is true or the latter is false; I The image features and attribute features are fused through the convolutional layer and the fully connected layer, and the final image authenticity S I is to transform the image discriminator D I The fused image features in are input into three residual blocks; the features of the posture image and the pedestrian image superimposed are input into a downsampling convolution layer and three residual residual blocks to obtain the posture authenticity S K ; Finally, the image authenticity S I and posture authenticity S K Combination: S = S I S K ; Step 4: Generate the target function for anonymous pedestrians. The specific steps are as follows: 4-1. Combine all pedestrians to generate the objective function. The specific formula is as follows: L=λ1L GAN +λ2L I +λ3L F Among them, λ1 is the weight of the objective function of GAN, λ2 is the weight of the reconstruction loss objective function, and λ3 is the weight of the identity cross feature loss function; where λ1=10, λ2=10, λ3=1; 4-2. GAN objective function L GAN ; The core idea of ​​GAN lies in the adversarial game between the generator and the discriminator; the goal of the generator is to generate real images that the discriminator cannot distinguish; the goal of the discriminator is to determine whether the image is generated by the generator. This process is expressed by the following equation: Among them, I S ,I T and I G Denote the source image, target image, and generated image respectively, and B T represents the target background, A represents the attribute, K S and K T denote the source pose and target pose respectively; 4-3. Reconstruction loss objective function; The reconstruction target loss of the anonymous pedestrian generation adversarial network adopts the pixel-level loss of the pedestrian area, allowing the network to pay more attention to the generation of the target person and the integration with the background. The specific formula is as follows: L I =||M T ⊙(I T -I G )||1 (4) Among them, ⊙ represents element-wise multiplication, MT is the binary pedestrian region mask; 4-4. Identity cross feature loss function; In the identity cross-training stage, the inter-feature loss is used to constrain the generation of identity cross-pedestrians. Specifically, the image features of pedestrians in the generated image are extracted through the pre-trained pedestrian re-identification model. Different identity cross-feature loss functions are selected according to whether the identities of pedestrians in the source image are consistent with those in the target image. The specific formula is as follows: Among them, F S is the image feature of pedestrians in the source image, F T is the image feature of pedestrians in the target image, F G It is the image feature of pedestrians in the generated image.

2. According to claim 1, a pedestrian identity privacy protection method combined with k-anonymity is characterized in that Step 1: Collect the proxy data set and preprocess the images. The specific steps are as follows: 1-1. Collecting privacy-insensitive pedestrian images as proxy datasets; 1-2. Image labeling: label the identity and attributes of pedestrian images and generate image labels; 1-3. Feature extraction: use the pre-trained pedestrian re-identification model to extract pedestrian image features; 1-4. Use the pedestrian posture parser to parse the image and obtain the pedestrian posture; 1-5. Use the instance segmentation model to obtain the pedestrian area mask image.

3. A pedestrian identity privacy protection method combined with k-anonymity according to claim 2, characterized in that Step 5: Train the model and test the data. The specific steps are as follows: 5-1. Prepare the data set. Use the public pedestrian data set Market1501 to preprocess the image according to step 1 to obtain the image labels, features, postures, and pedestrian area masks. The training set is used as the proxy dataset, and the test set is used as the dataset to be anonymized; 5-2. Divide the data set into a training set and a test set, with no duplicate identities between the two, and perform training on the training set; 5-3. Use the pedestrian anonymity network trained in step 3 and step 4, combined with pedestrian proxy identity mapping to generate anonymous pedestrians; 5-4. In order to verify the effectiveness of the proposed method, it is compared with the current method and the anonymity rate and data availability rate are calculated.

Citation Information

Patent Citations

  • Face de-identification generation method based on generative adversarial network

    CN111476200A

  • Multi-source data fusion privacy protection method for multi-privacy policy combination optimization

    CN112765653A