A Deep Learning Model Bias Removal Method and Device Based on Sensitive Feature Noise Addition

By defining bias index functions in the deep learning model and building a sensitive feature extraction model, and performing sensitive feature noise processing, the problem of lack of image data set debias in the existing technology is solved, and the debias and performance improvement of the deep learning model is achieved.

CN114445868BActive Publication Date: 2025-06-27ZHEJIANG UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210176604.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-25
Publication Date
2025-06-27
Estimated Expiration
2042-02-25

AI Technical Summary

Technical Problem

The lack of deep learning model debiasing methods for image data sets in the prior art, resulting in a degradation of the model's performance in fairness-related application scenarios.

Method used

A deep learning model debiasing method based on sensitive feature noise is proposed. By defining the bias index function, constructing a sensitive feature extraction model and main task classification model, and data augmentation in the noise-added area is carried out to reduce the bias of the model.

Benefits of technology

This method enhances image data through pixel scale, overcomes the problem of difficulty in modifying image data sets, realizes debiasing of deep learning models, and improves the performance of the model in fairness-related application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114445868B_ABST
    Figure CN114445868B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for debiasing a deep learning model based on adding noise to sensitive features. First, the CelebA dataset is used as the initial sample set and data preprocessing is performed; then, a bias metric function is defined based on the metrics of differential impact, demographic parity, and equality of opportunity; then, a sensitive feature extraction model is constructed and trained using a warm-up learning rate strategy; then, the noise-adding regions are divided and random noise is added to the sensitive features; finally, a deep learning model is constructed and the deep learning model is trained according to the defined bias metric function until the preset accuracy and bias metric are reached, at which point the training is ended and the debiasing is completed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and device for removing bias from a deep learning model based on adding noise to sensitive features for the problem of bias in deep learning models. Background Art

[0002] Artificial intelligence is the product of social development and technological innovation and an important technological form for promoting human progress. Since its development to date, artificial intelligence has become the core driving force of a new round of scientific and technological revolution and industrial transformation, and is having an extremely profound impact on the world economy, social progress, and people's lives. It provides the general public with more extensive, better-experienced, and more convenient life services. As an important field of artificial intelligence, deep learning has also achieved quite remarkable development results in recent years. Deep learning models have the ability to learn the internal function laws of large learning sample data sets and analyze abstract features, and assist people in making decisions in many fields and provide solutions to many complex recognition and classification problems. Deep learning technology has been widely applied in many fields, among which the field of image recognition was the earliest and most maturely applied. Alex Krizhevsky et al. designed a large convolutional neural network called "AlexNet" in 2012, and this neural network won the ILSVRC competition held that year with excellent performance. In 2013, the proposal of OverFeat enabled the sharing of a network structure for recognition, localization, and detection, and won the championship of the 2013 ILSVRC competition. From 2014 to 2017, with the proposal of networks such as GoogLeNet, ResNet, and SENet, the ability of deep learning networks to analyze and understand images has been comparable to or even surpassed that of humans.

[0003] The fairness of deep learning algorithms has received extensive attention in recent years. The academic community has put forward many ideas for studying the fairness of learning models. Although researchers have paid attention, so far, machine learning models may still be subject to various attacks, thereby reducing the performance of machine learning models. Most of the research on adversarial machine learning focuses on the accuracy of deep learning models. However, like accuracy, fairness measures can also become the target of malicious attacks by opponents. When deep learning models are applied in contexts related to fairness, such as medical measures, court judgments, etc., the fairness of the models becomes very important.

[0004] The existing debiasing methods in patents mainly target text table data sets. In view of the fact that the bias of deep learning models will cause the above problems, and there is a lack of debiasing methods for image data sets in the related fields, it is of extremely important theoretical and practical significance to study an unbiased model training method based on retraining the model to alleviate the degree of bias of the model. Summary of the Invention

[0005] In view of the deficiencies of the prior art, the present invention proposes a method and device for debiasing a deep learning model based on adding noise to sensitive features.

[0006] To achieve the above object, the technical solution of the present invention is as follows:

[0007] The first aspect of the embodiment of the present invention provides a method for debiasing a deep learning model based on adding noise to sensitive features, specifically including the following steps:

[0008] S1, taking the CelebA dataset as the initial sample set and performing data preprocessing;

[0009] S2, defining a bias metric function based on the disparate impact, demographic parity, and equality of opportunity metrics;

[0010] S3, constructing and training a sensitive feature extraction model using a warm-up learning rate strategy;

[0011] S4, dividing the noise-adding region, reconstructing the facial features of the image according to the sensitive feature extraction model, randomly adding noise to the sensitive features, and performing data augmentation;

[0012] S5, constructing a deep learning model, training the deep learning model according to the defined bias metric function until the preset accuracy and bias metric are reached, and ending the training to complete debiasing.

[0013] Further, all images in the CelebA dataset have feature labels, and the feature labels include a face bounding box annotation box, face feature point coordinates, and attribute labels;

[0014] Further, the attribute labels include a gender label and a curly hair label.

[0015] Further, the data preprocessing is specifically: normalizing the size and pixel values of the images in the CelebA dataset, and binding each picture with its gender label, whether curly hair label, and bounding box label; wherein, the gender label is used as a sensitive attribute, and the bounding box label is used for data augmentation.

[0016] Further, the input and output of the sensitive feature extraction model are images with normalized size and pixel values.

[0017] Further, the sensitive feature noise-adding framework model includes two parts: a feature extractor and a classifier; wherein the feature extractor adopts 5 convolutional layers, the classifier adopts a network composed of 2 fully connected layers, and the activation function adopts the Relu function.

[0018] Further, the step S4 is specifically:

[0019] (4.1) Construct a biased main task classification model M and train it:

[0020] (4.2) Use the bounding box labels to divide the noisy regions;

[0021] (4.3) Reconstruct the facial features of the image according to the sensitive feature extraction model, and add noise to the regions with more sensitive attribute information according to the sensitive attribute extraction model.

[0022] Further, the step (4.3) specifically includes the following sub-steps:

[0023] (4.3.1) Construct a suspicious dataset D’ and a clean dataset D c , put all images into the suspicious dataset D’, and the clean dataset D c is initially an empty set; sequentially input the pictures in the suspicious dataset D’ into the sensitive feature extraction model and the main task classification model M to obtain the sensitive attribute prediction confidence matrix and the main task classification labels;

[0024] (4.3.2) Set a threshold ε, calculate the confidence matrix distance. If the distance between the confidence matrix and the gender-neutral matrix [0.5, 0.5] is less than ε, the current image noise addition process is completed, and the processed image is added from the suspicious dataset D’ to the clean dataset D c ;

[0025] (4.3.3) Use the bias metric function defined in step S2 to calculate the bias of all images in the current suspicious dataset D’ according to the classification results in step (4.3.1), calculate the bias metric function, and retain the value F(D′, M) of the bias function as the bias degree value;

[0026] (4.3.5) Add noise to the images in the suspicious dataset D’ according to the value of the bias degree F(D′, M), that is, use μ = θ × F(D′, M) as the mean and σ as the variance to perform noise addition processing on the pixel points in the noise addition area divided in step (4.2.1) according to the probability p;

[0027] (4.3.6) Selectively retain the noise addition result: Re-input the noise-added picture into the sensitive attribute extraction model. If the predicted confidence matrix output by the model is closer to the decision boundary, retain the noise addition result; otherwise, do not retain the noise addition result, and repeat steps (4.3.2) to (4.3.5); when the preset number of iterations is reached or all samples in the suspicious dataset D’ are moved into the clean dataset D c , the noise addition is completed, that is, the data augmentation is completed.

[0028] The second aspect of the embodiments of the present invention provides a bias removal device for a deep learning model based on adding noise to sensitive features, including one or more processors for implementing the above-mentioned bias removal method for a deep learning model based on adding noise to sensitive features.

[0029] The third aspect of the embodiments of the present invention provides a computer-readable storage medium with a program stored thereon, which is used to implement the above-mentioned bias removal method for a deep learning model based on adding noise to sensitive features when executed by a processor.

[0030] The beneficial effects of the present invention are as follows: The bias removal method for a deep learning model based on adding noise to sensitive features disclosed in the present invention overcomes the problem of fewer bias removal methods for image classification models in the prior art. A more general bias metric function is proposed, overcoming the defect that existing evaluation metrics are not functionally universal for different data sets. The bias metric function disclosed in the present invention has stronger universality. The present invention enhances image data at the pixel scale, overcoming the problem of difficulty in modifying image data sets. The present invention solves the problem of large sample size and difficult modification of image data sets through a noise addition modification method based on the normal distribution. Description of the Drawings

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0032] Figure 1 It is a flowchart of the bias removal method for a deep learning model based on adding noise to sensitive features provided by an example of the present invention;

[0033] Figure 2 It is a block diagram of the algorithm for implementing data enhancement by a sensitive feature addition noise framework model provided by an example of the present invention;

[0034] Figure 3 It is a schematic diagram of the device of the present invention. Detailed Embodiments

[0035] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the following further details the present invention in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and do not limit the protection scope of the present invention.

[0036] There are biases in deep learning models, specifically: for classification tasks, the phenomenon where the classification model is influenced by irrelevant but sensitive features when making decisions, and its decisions may rely on such incorrect feature associations, is defined as the bias behavior of the deep learning model. The embodiments of the present invention mainly focus on gender bias. Among them, the sensitive feature is the bias feature, which may be race, region, gender, etc. For example, when the bias feature is gender, when using a deep learning model to classify an individual's expected income, the elimination rate of women is often relatively high, resulting in discrimination against women under the classification decision and the unfairness of the model decision. Therefore, the present invention reduces the bias of the model by alleviating the influence of sensitive features.

[0037] To solve the problem of inaccurate classification results caused by the bias problem of deep learning models. This embodiment provides a bias removal method and device for a deep learning model based on adding noise to sensitive features, as Figure 1 shown, the bias removal method for a deep learning model based on adding noise to sensitive features includes the following steps:

[0038] (1) Dataset preparation and preprocessing.

[0039] (1.1) Use the CelebA dataset as the initial sample set:

[0040] In this embodiment, a dataset with sensitive features is selected as the initial sample set, and one of the bias labels B is used as the bias feature, such as the gender feature. The present invention uses the cele b dataset as the target domain dataset for the bias removal method based on adding noise to sensitive features. The CelebA dataset (CelebFaces Attribute, a dataset of celebrity face attributes) contains 202,599 face images of 10,177 celebrity identities, and each image has feature markings, including a face bounding box annotation box, the coordinates of 5 face feature points, and 40 attribute markings. In this example, the gender attribute in the CelebA dataset is mainly used as the sensitive attribute, and whether the hair is curly is used as the prediction target of the main task.

[0041] However, through research, it is found that there is a bias in the CelebA dataset for the sensitive attribute of gender, and men are more likely to be classified as non-curly hair compared to women.

[0042] (1.2) Dataset preprocessing:

[0043] The CelebA dataset is a face image dataset without any cropping or scaling operations. To ensure that the model can fully extract the features of the image data while retaining as much information as possible to ensure the accuracy of the model's prediction of the main task, the images in the CelebA dataset are normalized in terms of size and pixel values. By scaling, the size of all images is changed to 128*128, and the pixel values of each scaled image are normalized to exclude the influence of shooting brightness and darkness on the model's prediction. Each image is bound to its gender label, whether curly hair label, and bounding box label. Among them, gender is a sensitive attribute, whether curly hair is a label, and the bounding box is used for the subsequent data augmentation process. In this example, the processed dataset is denoted as D. D is divided into a training set and a test set.

[0044] (2) Define the bias metric function

[0045] In the present invention, a bias metric is used to evaluate the bias degree of the model and samples. A new bias metric function F(d) is designed according to three commonly used bias metric functions in related fields, where the dataset d is used as the independent variable of the function. F(d) has the advantage of being useful for different datasets, overcoming the defect that existing evaluation metrics are not generally applicable to different datasets, that is, the measurement results of using a single bias metric for multiple different datasets may not be judgmental. The existing commonly used bias metrics are as follows:

[0046] (2.1) Disparate impact

[0047] This definition mathematically represents the legal concept of disparate impact. This requires a relatively high ratio between the positive prediction rates of two groups. This ensures that the ratios of positive predictions in each group are similar. For example, if a positive prediction represents a higher income, this condition requires that the acceptance rates of the applicants in different groups are similar. Its mathematical calculation formula is as follows:

[0048]

[0049] Where S represents the protected attribute (such as gender), S = 1 is the privileged group, and S ≠ 1 is the non-privileged group. Represents a positive prediction. Note that, If represents acceptance (for example, for a job), then this condition requires that the acceptance rates of different groups are similar. The higher the value of this metric, the more similar the ratios of different groups are, and thus the fairer it is.

[0050] (2.2) Demographic parity

[0051] The measurement method of demographic parity is similar to the disparate impact method, but this method uses differences instead of ratios. This method is usually also called statistical parity. Its mathematical calculation formula is as follows:

[0052]

[0053] The lower this metric value, the more similar the acceptance rates are, and thus the better the fairness.

[0054] (2.3) Equal opportunity

[0055] Equal opportunity requires that the true positive rates (TPRs) be similar across different groups (meaning that an individual with a positive outcome is likely to correspond to a positive prediction). This method is similar to equal odds but only focuses on the true positive rate. Its mathematical calculation formula is as follows:

[0056]

[0057] A predictor is considered to satisfy equal opportunity when the following is met:

[0058] P{H(x i ) = 1|y i = 1, x i ∈S} = P{H(x j ) = 1|y j = 1, x j ∈X\S} (4)

[0059] Let X represent a group of individuals and S represent a subgroup. For an individual x i ∈X, let it be the true outcome (or label) to be predicted. A predictor can be represented by a mapping H: X → Y from the population X to the set of outcomes Y, such that H(x i ) is the predicted outcome of the individual x i . i and j represent two individuals.

[0060] (2.4) Define the bias function F(d)

[0061] Improve and fuse the above 3 bias metrics to synthesize the statistical probability bias function F(d), and the specific expression is:

[0062]

[0063] The smaller F(d) is, the better the fairness of the data. The present invention will use F(d) as an indicator to measure the bias degree of the data set.

[0064] If F(d) is used to measure the bias indicator of the deep learning model, then change y in the formula to

[0065]

[0066] Use the predicted value of the model as the classification for fairness analysis.

[0067] (3) Construct a sensitive feature extraction model:

[0068] (3.1) Construct a sensitive feature extraction model

[0069] The input and output of the sensitive feature noise-adding framework model are both pictures of size 128*128. In this embodiment, the constructed sensitive feature noise-adding framework model includes two parts: a feature extractor and a classifier. Among them, the feature extractor uses 5 convolutional layers, the classifier uses a network composed of 2 fully connected layers, and the activation function uses the Relu function.

[0070] (3.2) Train the sensitive feature extraction model M s for training

[0071] Use the training set of the CelebA original dataset D to train the deep learning model. Divide the dataset D into a training set and a test set, and use the training set to train M s for training. Set the size of the training batch to 100. Adopt a warm-up learning rate strategy in the training stage, and use Adam as the optimizer for optimization. The loss function adopts the form of cross-entropy, and the formula is as follows:

[0072] L1 = -[y·log(p) + (1 - y)·log(1 - p)]

[0073] where y represents the label of the sample, 1 if the gender attribute is male, otherwise 0. P represents the probability that the sample is predicted to be male.

[0074] After training, use the test set to verify whether the model reaches the target accuracy. If the preset accuracy is reached, the sensitive feature extraction model M s is trained.

[0075] (4) Perform sensitive feature noise-adding

[0076] (4.1) Construct a biased main task classification model M and train it:

[0077] The input of the classification model is a picture of size 128*128, and the output is the class label of whether the picture is curly hair. In this embodiment, the constructed classification model includes two parts: a feature extractor and a classifier. Among them, the feature extractor uses 5 convolutional layers, the classifier uses a network composed of 2 fully connected layers, and the activation function uses the Relu function.

[0078] The deep learning model is trained using the training set of the original data set D. The data set D is divided into a training set and a test set. The training set is used to train M. The size of the training batch is set to 100. The warm-up learning rate strategy is used in the training phase, and the optimizer is optimized using Adam. The loss function is in the form of cross entropy, and the formula is as follows:

[0079] L1=-[y·log(p)+(1-y)·log(1-p)]

[0080] Where y represents the label of the sample, which is 1 if the hair is curly, otherwise it is 0. P represents the probability that the sample is predicted to be curly.

[0081] (4.2) Noise area division

[0082] Considering that the main task of prediction in this example is to distinguish whether it is curly hair, when the entire image is denoised, it is very likely that the curly hair features in the image will be destroyed, thus affecting the accuracy of the main task. To avoid the above situation, this example uses the bounding box that comes with the dataset to first divide the noisy area, so as to denoise the area with more sensitive attribute information and protect the area required for the main task to the greatest extent.

[0083] (4.3) Add noise according to the sensitive attribute extraction model. The steps are as follows:

[0084] By adding noise to the gender attribute feature, the gender feature is weakened. If the noisy image is s The classification becomes blurred, that is, the confidence matrix is ​​close to the gender neutral matrix [0.5, 0.5]. This shows that the features related to sensitive attributes have been weakened and the noise addition of sensitive attribute features has been completed.

[0085] (4.3.1) Input image

[0086] Construct suspicious data set D' and clean data set D respectively c , all images are classified into the suspicious dataset D', the clean dataset D c Initially, it is empty. The images in the suspicious dataset D' are input into the sensitive feature extraction model M in sequence. s And the sensitive attribute prediction confidence matrix and the main task classification label are obtained in the main task classification model M.

[0087] (4.3.2) Calculate the confidence matrix distance

[0088] Set the threshold ε. If the distance between the confidence matrix and the gender neutral matrix [0.5, 0.5] is less than ε, the current image noise processing is completed, and the processed image is added from the suspicious data set D' to the clean data set D c middle.

[0089] (4.3.3) Bias Index Function Calculation

[0090] Calculate the bias of all images in the current suspicious dataset D′ according to the bias index function defined in step S2 based on the classification result in step (4.3.1), and retain the value F(D′, M) of the bias function as the bias degree value.

[0091] (4.3.5) Adding Noise According to the Bias Degree Value

[0092] Add noise to the images in the suspicious dataset D′ according to the value F(D′, M) of the bias degree, that is, with μ = θ × F(D′, M) as the mean and σ as the variance, add noise to the pixel points in the noise-adding area divided in step (4.2.1) according to the probability p (that is, add a normally distributed noise). Among them, θ, σ, and p are all hyperparameters, and their values are determined by specific situations.

[0093] (4.3.6) Selectively Retaining the Noise-Adding Result

[0094] Re-input the noise-added picture into the model M s If the predicted confidence matrix output by the model is closer to the decision boundary, retain the noise-adding result; otherwise, do not retain the noise-adding result, and repeat steps (4.3.2) - (4.3.5).

[0095] When the algorithm reaches the preset number of iterations or all samples in the suspicious dataset D′ are moved into the clean dataset D c then the noise addition is completed, that is, the data augmentation is completed.

[0096] (5) Constructing a Deep Learning Model

[0097] The deep learning model is a supervised model. The input of the model is a picture with a size of 128*128, and whether it is curly hair is used as the label. In this embodiment, the constructed deep learning model includes two parts: a feature extractor and a classifier. Among them, the feature extractor uses 5 convolutional layers, and the classifier uses a network composed of 3 fully connected layers, and the activation function uses the Relu function.

[0098] The size of the training batch is set to 100. In the training stage, a warm-up learning rate strategy is adopted, and the optimizer uses Adam for optimization. Use the training set of the dataset ED_D to train the deep learning model. Among them, cross-entropy is used as the loss function. The formula is as follows:[[]]

[0099] L1 = -[y·log(p) + (1 - y)·log(1 - p)]

[0100] Among them, y represents the label of the sample, where curly hair is 1 and non-curly hair is 0. P represents the probability that the sample is predicted to be curly hair. The validation set is used to evaluate the model, and the training is terminated when the accuracy of the validation set meets the requirements.

[0101] Detect the bias degree of the model: Select 100 males from the sample set D, with 50 having curly hair and 50 having non-curly hair, and 100 females, with 50 having curly hair and 50 having non-curly hair. A validation set V_D is formed. The validation set V_D is input into the model, and the bias index F(d) defined in step 3 is used to determine the bias degree of the model.

[0102] Corresponding to the foregoing embodiments of the debiasing method for a deep learning model based on adding noise to sensitive features, the present invention also provides embodiments of a debiasing device for a deep learning model based on adding noise to sensitive features.

[0103] See Figure 3 , a debiasing device for a deep learning model based on adding noise to sensitive features provided by an embodiment of the present invention includes one or more processors for implementing the debiasing method for a deep learning model based on adding noise to sensitive features in the foregoing embodiments.

[0104] Embodiments of the debiasing device for a deep learning model based on adding noise to sensitive features of the present invention can be applied to any device with data processing capabilities, and such a device with data processing capabilities can be a device or apparatus such as a computer. The device embodiments can be implemented by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor of any device with data processing capabilities reading the corresponding computer program instructions in the non-volatile memory into the memory for operation. From a hardware level, as Figure 3 shown, it is a hardware structure diagram of any device with data processing capabilities where the debiasing device for a deep learning model based on adding noise to sensitive features of the present invention is located. In addition to Figure 3 the processors, memory, network interfaces, and non-volatile memories shown, any device with data processing capabilities where the device in the embodiments is located usually also includes other hardware according to the actual functions of the device with data processing capabilities, which will not be elaborated here.

[0105] The implementation processes of the functions and roles of each unit in the above device are specifically detailed in the implementation processes of the corresponding steps in the above method, which will not be elaborated here.

[0106] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present invention. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0107] The embodiments of the present invention also provide a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, the method for debiasing a deep learning model based on adding noise to sensitive features in the above embodiments is implemented.

[0108] The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the foregoing embodiments, such as a hard disk or a memory. The computer-readable storage medium may also be any device with data processing capabilities, such as a plug-in hard disk, a Smart Media Card (SMC), an SD card, a Flash Card, etc. equipped on the device. Further, the computer-readable storage medium may also include both an internal storage unit of any device with data processing capabilities and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and can also be used to temporarily store the data that has been output or will be output.

[0109] The content described in the embodiments of this specification is only a list of the implementation forms of the inventive concept. The protection scope of the present invention should not be regarded as limited to the specific forms stated in the embodiments. The protection scope of the present invention also covers equivalent technical means that those skilled in the art can think of based on the inventive concept of the present invention.

Claims

1. A deep learning model debiasing method based on adding noise to sensitive features, characterized in that, Specifically, it includes the following steps: S1. Use the CelebA dataset as the initial sample set and perform data preprocessing; S2. Define a bias metric function based on the metrics of differential impact, demographic parity, and equality of opportunity; S3. Construct and adopt a warm-up learning rate strategy to train the sensitive feature extraction model; S4. Divide the noise-added regions, reconstruct the facial features of the images according to the sensitive feature extraction model, randomly add noise to the sensitive features, and perform data augmentation; Specifically, step S4 is as follows: (4.1) Construct a biased main task classification model M and train it: (4.2) Use the bounding box labels to divide the noise-added regions; (4.3) Reconstruct the facial features of the images according to the sensitive feature extraction model, and add noise to the regions with more sensitive attribute information according to the sensitive attribute extraction model; Specifically, step (4.3) includes the following sub-steps: (4.3.1) Construct the suspicious dataset D' and the clean dataset D respectively c , and classify all images into the suspicious dataset D' and the clean dataset D c which are initially empty sets; then input the images in the suspicious dataset D' into the sensitive feature extraction model and the main task classification model M in turn to obtain the sensitive attribute prediction confidence matrix and the main task classification labels; (4.3.2) Set the threshold ε and calculate the confidence matrix distance. If the distance between the confidence matrix and the gender-neutral matrix [0.5, 0.5] is less than ε, the noise addition process for the current image is completed, and the processed image is added from the suspicious dataset D' to the clean dataset D. c into; (4.3.3) Use the bias metric function defined in step S2 to calculate the bias of all images in the current suspicious dataset D' according to the classification results in step (4.3.1), calculate the bias metric function, and retain the value of the bias function F(D′, M) as the degree of bias value; (4.3.5) Add noise to the images in the suspicious dataset D' according to the value of the degree of bias F(D′, M), that is, μ = θ × F(D′, M) as the mean, and σ as the variance, and perform noise addition processing on the pixel points in the noise-added area divided in step (4.2.1) according to the probability p; (4.3.6) Selective retention of the noise-added result: Re-enter the noise-added image into the sensitive attribute extraction model. If the predicted confidence matrix output by the model is closer to the decision boundary, then retain the noise-added result; otherwise, do not retain the noise-added result, and repeat steps (4.3.2) to (4.3.5); When the preset number of iterations is reached or all samples in the suspicious dataset D’ have been moved into the clean dataset D c , the noise addition is completed, that is, the data augmentation is completed; S5. Construct a deep learning model, train the deep learning model according to the defined bias metric function until the preset accuracy and bias metric are reached, and end the training to complete debiasing.

2. The debiasing method for a deep learning model based on adding noise to sensitive features according to claim 1, wherein, All images in the CelebA dataset have feature markings, and the feature markings include a face bounding box annotation frame, face feature point coordinates, and attribute markings.

3. The method for debiasing a deep learning model based on adding noise to sensitive features according to claim 2, wherein The attribute markings include a gender label and a curly hair label.

4. The debiasing method for a deep learning model based on adding noise to sensitive features according to claim 1, characterized in that Specifically, the data preprocessing is as follows: perform size and pixel value normalization processing on the images of the CelebA dataset, and bind each picture with its gender label, whether it has curly hair label, and bounding box label; among them, the gender label is used as the sensitive attribute, and the bounding box label is used for data augmentation.

5. The method for debiasing a deep learning model based on adding noise to sensitive features according to claim 1, wherein The input and output of the sensitive feature extraction model are images with normalized size and pixel values.

6. The method for debiasing a deep learning model based on adding noise to sensitive features according to claim 1, wherein The constructed sensitive feature noise-adding framework model includes two parts: a feature extractor and a classifier; Among them, the feature extractor adopts 5 convolutional layers, the classifier adopts a network composed of 2 fully connected layers, and the activation function adopts the Relu function.

7. A deep learning model debiasing device based on adding noise to sensitive features, characterized in that, It includes one or more processors for implementing the debiasing method of the deep learning model based on sensitive feature noise addition according to any one of claims 1-6.

8. A computer-readable storage medium having a program stored thereon, characterized in that, When the program is executed by the processor, it is used to implement the debiasing method of the deep learning model based on sensitive feature noise addition according to any one of claims 1-6.

Citation Information

Patent Citations

  • Method for generating unbiased deep learning model based on transfer learning

    CN112115963A

  • Deep learning model depolarization method and device based on data sample enhancement

    CN113361653A