A face feature privacy protection method based on single-point differential privacy
By adding Laplacian distribution noise to face images and optimizing the noise scale, the problem of facial feature information leakage in existing technologies is solved, achieving high data utility and visual effect preservation while maximizing privacy protection.
Patent Information
- Application Number
- CN202310825612.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-07
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2043-07-07
AI Technical Summary
Existing methods for protecting facial feature privacy, while preserving visual effects, are insufficient in preventing adversaries from stealing facial feature information and lack adequate privacy protection.
A single-point difference privacy protection method is adopted to add Laplacian distribution noise to the wavelet coefficient vector of the pixel matrix of the face image, and optimize the noise scale parameter by combining inverse wavelet transform and principal component analysis with the Lagrange multiplier method to ensure high data utility is preserved under a given privacy budget.
It effectively prevents adversaries from obtaining facial feature information, while preserving the visual effect of facial images to maximize privacy protection, achieving "visible but unrecognizable" facial images, that is, balancing data availability and privacy protection.
Smart Images

Figure CN116798133B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of computer science, and in particular relates to a method for protecting facial feature privacy based on single-point differential privacy. Background Technology
[0002] Facial features are a type of biometric characteristic, and their uniqueness and resistance to duplication have led to their widespread application in facial recognition algorithms. Therefore, facial features are a primary target for adversaries seeking to steal sensitive facial information, making the application of privacy protection mechanisms to facial features essential. Currently, facial feature privacy protection methods during the distribution of facial images mainly focus on techniques such as mosaicking, data perturbation, and blurring, which significantly degrade the visual quality of facial images. We propose, for the first time, a facial feature privacy protection method based on single-point differential privacy, which preserves optimal visual quality within a given privacy budget.
[0003] Definitions:
[0004] Single-point differential privacy: Add geometrically independent noise to each element of the wavelet coefficient vector of the pixel matrix of the face image, and each noise follows a Laplace distribution; at the same time, after inverse wavelet transform, the noise on each element of the face feature vector also follows a Laplace distribution.
[0005] Privacy budget: a measure of privacy protection; the smaller the value, the greater the level of privacy protection.
[0006] Geometric superposition mechanism: For multiple variables that follow a geometric distribution, summation and other superposition operations are performed on these multiple random variables to generate a new variable that follows a Laplace distribution. Summary of the Invention
[0007] To address the aforementioned issues, this invention provides a face feature privacy protection method based on single-point differential privacy. This method not only effectively prevents adversaries from stealing sensitive information such as face features from face images through methods such as principal component analysis, but also preserves higher data utility under a given level of privacy protection. While effectively hiding sensitive information such as face features in face images, it also ensures the visual quality of the face images.
[0008] To achieve the above-mentioned technical effects, the technical solution of the present invention is as follows:
[0009] A face feature privacy protection method based on single-point differential privacy includes the following steps:
[0010] Step 1: Let M be the number of elements in the equation. P From the pixel matrix P of a face image with 1 element, and using principal component analysis, the facial feature vector of the pixel matrix P can be obtained. in, have Each element.
[0011] Step 2: Perform wavelet transform on the pixel matrix P of the face image to obtain wavelet coefficients representing the face features. Expand the wavelet coefficients into a one-dimensional wavelet coefficient vector. in, have 1 element, and
[0012] Step 3: Calculate the weights between the face feature vector and the one-dimensional wavelet coefficient vector using partial derivative operations. in, This represents the partial derivative operation, where i represents the face feature vector after adding noise. The i-th element The subscript, and j represents the one-dimensional wavelet coefficient vector after adding noise. The j-th element The subscript, and w ij This represents the i-th element in the face feature vector after adding noise. The j-th element in the one-dimensional wavelet coefficient vector after adding noise The weights between them, and the noise added here follows a Laplace distribution with a location parameter of 0 and a scale parameter of arbitrary value.
[0013] Step 4: Use variance calculation to calculate the scale parameter of the noise at the i-th element in the face feature vector.
[0014]
[0015] in, The k-th noise ξ is the weight corresponding to the one-dimensional wavelet coefficient vector, sorted in descending order. k The scale parameter is given by , and 1 ≤ k ≤ K, where K is the mean value. The number of elements in the wavelet coefficient vector does not exceed the total number of elements in the wavelet coefficient vector. The geometric number of , p is the probability parameter greater than 0 and less than 1.
[0016] Step 5: Calculate the privacy budget for the i-th element in the face feature vector.
[0017]
[0018] in, It is the sensitivity related to the i-th element in the facial feature vector, and
[0019] Step Six: Construct the utility function
[0020]
[0021] Set the constraints as follows ε0 is the given total privacy budget; the constrained optimization problem of the scale parameter of noise on the one-dimensional wavelet coefficient vector is transformed into: under the constraints, solving for the minimum value of the utility function, i.e.
[0022]
[0023] The scaling parameter of the noise on the optimized one-dimensional wavelet coefficient vector is calculated using the Lagrange multiplier method.
[0024] Step 7: First, let the function f ε (·) is a function for calculating the total privacy budget, then Represents the scale parameter based on the corrected noise. The total privacy budget is calculated; The first-order Taylor expansion expression is:
[0025]
[0026] The constraints are Where, δ k The deviation value to be calculated is... The scaling parameter for noise on the corrected one-dimensional wavelet coefficient vector.
[0027] Then, the modified utility function expression is:
[0028]
[0029] The constrained optimization problem is
[0030]
[0031] Finally, the deviation value δ is calculated using the Lagrange multiplier method. k The scale parameter of noise on the modified one-dimensional wavelet coefficient vector
[0032] Step 8: Obtaining the pixel matrix and facial features of the face image after adding noise. First, the scale parameter of the corrected noise... Generate a noise set, and obtain the noisy wavelet coefficient vector according to the geometric superposition mechanism. Then, using inverse wavelet transform, the pixel matrix P′ of the face image after adding noise is obtained; subsequently, combining principal component analysis and P′, the face feature vector after adding noise is calculated.
[0033] Preferably, step three specifically involves adding noise to the face feature vector. The i-th element First-order Taylor expansion
[0034]
[0035] in, ξ j It is the noise added to the j-th element of the one-dimensional wavelet coefficient vector. Define the face feature vector after adding noise. The i-th element With the wavelet coefficient vector after adding noise The j-th element weight in, Calculate the weight w using partial derivative operations. ij ;
[0036] Preferably, step four specifically involves, according to the geometric superposition mechanism, adding noise to the one-dimensional wavelet coefficient vector. It has K Laplace noises, where K is the mean of the noise. The geometric number. Therefore, The first-order Taylor expansion is
[0037]
[0038] Where, ξ k It is the kth noise element sorted from largest to smallest according to its corresponding weight, and it satisfies the parameters 0 and 1. The Laplace distribution, i.e. It is ξ k The scale parameter, ξ k The corresponding one-dimensional wavelet coefficient vector is w ik yes and The weights between them, that is, and The corresponding weights. Therefore, The probability distribution of follows a Laplace distribution, that is,
[0039]
[0040] Where Pr[·] is the probability distribution function, The parameter is 0 and The Laplace distribution function. Using variance calculations, variance and
[0041]
[0042] Where Var[·] represents the variance operation, which yields the scale parameter of the noise on the i-th element of the face feature vector. The scale parameter of the noise on the k-th element of the one-dimensional wavelet coefficient vector. The relationship is as follows:
[0043]
[0044] Preferably, step six specifically involves calculating the privacy budget of the i-th element in the face feature vector. This refers to the sensitivity of the facial feature vector. The given total privacy budget is ε0, and the constraints are... Construct the utility function U as follows:
[0045]
[0046] The constrained optimization problem is
[0047]
[0048] According to the Lagrange multiplier method, the Lagrange function is:
[0049]
[0050] Solve The noise ξ was calculated. k scale parameters
[0051] Preferably, step seven specifically involves setting the scale parameter of the corrected noise as follows: Represents the scale parameter based on the corrected noise. The total privacy budget is calculated. The first-order Taylor expansion expression is:
[0052]
[0053] make δ k It is the deviation value. According to the chain rule,
[0054]
[0055] in,
[0056]
[0057] Substitution After a first-order Taylor expansion, we derive the value of the deviation δ. kThe functional expression f for calculating the total privacy budget ε (δ k Therefore, the constraint condition is f. ε (δ k The modified utility function U′ is expressed as follows: )=ε0.
[0058]
[0059] The constrained optimization problem is:
[0060]
[0061] According to the Lagrange multiplier method, the Lagrange function is:
[0062]
[0063] Solve The deviation value δ was calculated. k ; will δ k and the result obtained in step five Substitution The scale parameters of the corrected noise were calculated.
[0064] The beneficial effects of this invention are as follows:
[0065] 1. By adding noise that follows a Laplace distribution to the facial feature vector, it is possible to effectively prevent adversaries from obtaining sensitive information such as facial features in facial images;
[0066] 2. By combining the Lagrange multiplier method, Taylor expansion, and chain rule, the optimal privacy budget can be obtained, maximizing privacy protection while ensuring the visual effect of facial images, thus achieving "visible but unrecognizable" facial image data. Attached Figure Description
[0067] Figure 1 This is a detailed flowchart of the present invention.
[0068] Figure 2 This is a comparison chart of the data usefulness and privacy budget of the three methods: Before Correction, Before Wavelet Transform, and After Wavelet Transform.
[0069] Figure 3 This is a comparison chart of data availability and privacy budget between the method of this invention (After Correction) and other methods (Before Correction). Detailed Implementation
[0070] The present invention will now be further described in conjunction with the accompanying drawings and embodiments.
[0071] This invention was developed using Python 3.7 and runs on Windows 10. The experimental data consists of a dataset of face images from multiple users. The specific steps are as follows:
[0072] 1. Step 1: Preprocess the face image.
[0073] Let M be P From the pixel matrix P of a face image with 1 element, and using principal component analysis, the facial feature vector of the pixel matrix P can be obtained. in, have Each element.
[0074] 2. Step Two: Extract the wavelet coefficient vector of the face image.
[0075] The pixel matrix P of the face image is subjected to wavelet transform to obtain wavelet coefficients representing the face features. These wavelet coefficients are then expanded into a one-dimensional wavelet coefficient vector. in, have Each element.
[0076] 3. Step 3: Calculate the weights between the face feature vector and the wavelet coefficient vector.
[0077] Face feature vector with added noise The i-th element First-order Taylor expansion
[0078]
[0079] in, make ξ j It represents the noise at the j-th element of the one-dimensional wavelet coefficient vector. The face feature vector after adding noise is defined as follows. The i-th element With the one-dimensional wavelet coefficient vector after adding noise The j-th element weight in, Calculate the weight w using partial derivative operations. ij .
[0080] 4. Step Four: Calculate the scale parameter of the noise on the face feature vector.
[0081] Based on the geometric superposition mechanism, the one-dimensional wavelet coefficient vector It has K Laplace noises, where K is the mean of the noise. The geometric number. Therefore, The first-order Taylor expansion is
[0082]
[0083] ξ k It is the k-th noise element after sorting, and it follows a Laplace distribution, i.e., in, It is ξ k The scale parameter, ξ k The corresponding one-dimensional wavelet coefficient vector is w ik yes and The corresponding weights. Therefore, we can obtain The probability distribution function is as follows:
[0084]
[0085] Using variance calculation, variance and
[0086]
[0087] The derivation yields and The relationship is as follows:
[0088]
[0089] 5. Step five: Obtain the privacy budget for each element in the face feature vector.
[0090] The privacy budget ε of the i-th element in the face feature vector is calculated according to the following formula. i ,Right now,
[0091]
[0092] in, yes The sensitivity of, among which,
[0093] 6. Step Six: Optimize the scale parameters of the noise.
[0094] Since privacy protection strength and data availability are the two major performance indicators of privacy protection methods, a utility function representing data availability needs to be constructed to optimize the noise scaling parameter. By solving a constrained optimization problem, the optimal privacy budget that maximizes privacy protection strength can be obtained. The utility function is shown below:
[0095]
[0096] Let the constraints be... Where ε0 is the given total privacy budget, ε i Let be the privacy budget on the i-th element of the face feature vector. Then, the constrained optimization problem is:
[0097]
[0098] According to the Lagrange multiplier method, the Lagrange function is:
[0099]
[0100] Solve The scale parameters of the optimized noise were calculated.
[0101] 7. Step Seven: Correct the scale parameters of the noise.
[0102] First, calculate the k-th noise ξ. k Corrected scale parameters Where δ k It is the deviation value.
[0103] Then, let the function f ε (·) is a function for calculating the total privacy budget, then Indicates based on the modified scale parameter The total privacy budget is calculated; The first-order Taylor expansion expression is:
[0104]
[0105] The constraints are: The revised utility function expression is:
[0106]
[0107] The constrained optimization problem is:
[0108]
[0109] Finally, according to the method of Lagrange multipliers, the Lagrange function is:
[0110]
[0111] Solve The deviation value δ was calculated. k The solution obtained in step five and δ k Substitution The corrected scale parameters were calculated.
[0112] 8. Step 8: Obtain the privacy-preserving face image pixel matrix and face feature vector.
[0113] First, based on the modified scale parameters The generated noise set, based on the geometric superposition mechanism, is a one-dimensional wavelet coefficient vector. Adding noise yields a one-dimensional wavelet coefficient vector with added noise. Then, using inverse wavelet transform, the pixel matrix P′ of the face image with added noise is obtained. Combining principal component analysis and P′, the face feature vector after adding noise is calculated.
[0114] The following is a face feature privacy protection algorithm based on single-point differential privacy:
[0115]
[0116] The above examples are only for the purpose of helping to understand the core idea of the present invention; at the same time, those skilled in the art will know that there will be changes in the specific implementation methods and application scope based on the idea of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A face feature privacy protection method based on single-point differential privacy, characterized in that, Specifically includes the following steps: Step one: for a face image, a face image pixel matrix can be obtained, and by using principal component analysis, a face feature vector with elements can be obtained Step two: after wavelet transform of the face image pixel matrix, a one-dimensional wavelet coefficient vector representing the face feature is obtained wherein, The total number of the elements contained in the array is Step 3 uses partial derivative operations to calculate the weights between the face feature vector and the one-dimensional wavelet coefficient vector. in, This represents the partial derivative operation. This represents the facial feature vector after adding noise. Let represent the one-dimensional wavelet coefficient vector after adding noise. The added noise should satisfy a Laplace distribution with a position parameter of 0 and a scale parameter of arbitrary value; i represents The i-th element The index of i is greater than or equal to 1 and less than or equal to the total number of elements contained in the face feature vector. j represents The j-th element The subscript, at the same time, w ij express and The weights between them; Step four: using variance operation, calculate the scale parameter of noise on the i-th element of the face feature vector in, A one-dimensional wavelet coefficient vector The k-th noise ξ is sorted by its corresponding weights from largest to smallest. k The scale parameter, where 1 ≤ k ≤ K, where K is the mean value. And not exceeding the total number of elements in the wavelet coefficient vector The geometric number, p is a probability parameter greater than 0 and less than 1, w ik express and The weights between them; Step five: calculate the privacy budget of the i-th element of the face feature vector wherein, is the sensitivity of the face feature vector, and Step six: realize the scale parameter optimization of noise; first, construct the utility function The constraint condition is set as: the given total privacy budget ε0 is equal to the sum of the privacy budget corresponding to each element in the face feature vector, i.e., Then, under the constraint condition, the scale parameter of the noise on the one-dimensional wavelet coefficient vector is solved The minimum value of the scale parameter is Finally, according to the Lagrange multiplier method, the scale parameter of noise on the optimized one-dimensional wavelet coefficient vector is calculated; Step seven: the modification of the scale parameter of the noise. First, let f ε (·) be a function to compute the total privacy budget, then denotes the scale parameter of the kth noise according to the modified wavelet coefficient vector The total privacy budget is computed as The first order Taylor expansion expression of f where ε0is a given total privacy budget, δ k is the bias value to be computed; then, the modified constraint is The modified utility function is Finally, the scale parameter optimization problem of noise is transformed into: using the modified constraint condition, finding the minimum value of the modified utility function, that is According to the Lagrange multiplier method, the deviation value δ is calculated k and the modified scale parameter of the kth noise in the one-dimensional wavelet coefficient vector Step eight: revised scale parameter of noise A set of noises is generated, and a one-dimensional wavelet coefficient vector P after adding noise is obtained according to a geometric superposition mechanism An inverse wavelet transform is performed to obtain a pixel matrix P' of the face image after adding noise, and then a principal component analysis is combined with P' to calculate a face feature vector after adding noise 2. The face feature privacy protection method based on single-point differential privacy according to claim 1, characterized in that, The third step is specifically adding noise to the face feature vector The first-order Taylor expansion of the i-th element of is as follows where i is greater than or equal to 1 and less than or equal to the total number of elements contained in the face feature vector ξ j is the noise added to the jth element of the one-dimensional wavelet coefficient vector, ξ j is the difference between the jth element of the one-dimensional wavelet coefficient vector before and after the noise is added, i.e., 3. The face feature privacy protection method based on single differential privacy according to claim 1, characterized in that, The step four is specifically: according to the geometric superposition mechanism, the one-dimensional wavelet coefficient vector has K Laplace noises, wherein K is a geometric number with a mean value of ; therefore, the first-order Taylor expansion of wherein ξ k is the kth noise in descending order of weights corresponding to elements in the one-dimensional wavelet coefficient vector, and ξ k satisfies a Laplace distribution with a location parameter of 0 and a scale parameter of , i.e., ξ k corresponding to the one-dimensional wavelet coefficient vector after adding noise is w ik is the weight between and , i.e., the weight corresponding to and ; therefore, the probability distribution function of the ith element in the face feature vector after adding noise is as follows: where Pr[·] denotes a probability distribution function, is a Laplace distribution function with location parameter 0 and scale parameter ; and applying a variance operation, the variance of Pr[·] is and where Var[·] denotes the variance operation, and the scale parameter of the noise on the i-th element of the face feature vector is given by and the scale parameter of the noise on the k-th element of the one-dimensional wavelet coefficient vector is given by The relationship is given by 4. The face feature privacy protection method based on single differential privacy according to claim 1, characterized in that, The step seven is specifically, assuming the revised scale parameter is represents the first order Taylor expansion expression of the revised scale parameter The total privacy budget is calculated, The first order Taylor expansion expression of Let δ k be the bias value; according to the chain rule, we have Where, Substituting the first-order Taylor expansion, we obtain the expression for the total privacy budget f k (δ ε ) in terms of δ k ; thus, the constraint is f ε (δ k ) = ε0.
Citation Information
Patent Citations
Deep learning-based facial recognition system with privacy-preserving features
US20250285467A1