Pedestrian re-identification anonymization privacy protection method capable of keeping identity invariance
By building an anonymization framework and joint training mechanism, the generator and the ReID model are optimized in collaboratively, solving the problem of balance between privacy protection and data utility in pedestrian re-identification, achieving efficient anonymous image recognition, meeting privacy protection requirements and improving ReID performance.
Patent Information
- Application Number
- CN202510582457.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Existing pedestrian re-identification technology is difficult to balance between privacy protection and data utility. Traditional methods oversacrifice semantic information, and deep learning methods destroy identity characteristics, resulting in the inability to effectively identify anonymous images.
Build an anonymization framework, including anonymized image generation module and identity retention module, generate anonymized images through conditional adversarial networks, and jointly train anonymization generator and ReID model, introducing multiple loss functions to ensure identity invariance and privacy protection.
It realizes the maintenance of data utility while protecting privacy, significantly improves the ReID performance of anonymous images, meets GDPR requirements, and has a highly consistent feature spatial distribution, supporting cross-modal re-identification in complex scenarios.
Smart Images

Figure CN120544285A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of computer vision and privacy protection, face recognition and other related technical fields. Specifically, it provides a privacy protection method suitable for person re-identification (ReID). By using anonymization technology, the privacy of pedestrian images is protected while maintaining data utility, thereby meeting the identity recognition needs in scenarios such as intelligent transportation systems and public safety monitoring. Background Art
[0002] Person Re-ID (Pedestrian Re-ID) aims to identify the same person across multiple cameras using appearance features (such as clothing, gait, and body shape). It is a core technology for smart cities and public safety. With the development of deep learning (such as convolutional neural networks and Transformers), Re-ID performance has significantly improved, achieving advanced results on benchmark datasets such as Market-1501 and DukeMTMC. However, raw pedestrian images contain sensitive biometric information such as facial features and body posture, which poses the risk of being misused to track individuals or reconstruct their identities. This poses challenges to complying with strict privacy regulations, such as the EU's GDPR.
[0003] Traditional anonymization methods (such as blurring, cropping, and pixelation) protect privacy by removing personally identifiable information (PII), but inevitably lead to loss of semantic information, severely reducing the data's usability for downstream ReID tasks. For example, facial blurring destroys subtle identity-related features, leading to degraded recognition model performance. In recent years, deep learning-based anonymization techniques (such as generative adversarial networks (GANs)) have attempted to achieve privacy protection while maintaining image quality. However, by introducing artificial distortion or perturbations, they unintentionally alter pedestrian identity characteristics (such as the continuity of walking patterns), making the anonymized data incompatible with ReID models and unable to meet the identity consistency requirements of recognition tasks.
[0004] Existing technologies currently suffer from two major flaws. The first is the imbalance between privacy protection and data utility. Traditional methods excessively sacrifice semantic information, while deep learning methods destroy identity features. Neither approach can achieve a balance between privacy protection and recognition performance in ReID. The second is the unintended alteration of identity features. Existing anonymization techniques fail to consider the unique requirement of identity immutability in ReID, resulting in anonymized images being ineffectively recognized by existing ReID models.
[0005] In addition, existing ReID research focuses on performance improvement and ignores privacy protection; while general data de-identification (DeID) methods overemphasize privacy and sacrifice the data utility required for ReID, creating a technological gap. Summary of the Invention
[0006] In order to solve the technical problems existing in the above background technology, the present invention provides a pedestrian re-identification anonymization privacy protection method with identity invariance preservation.
[0007] Based on the first main aspect of the present invention, a method for anonymizing and protecting privacy in person re-identification while preserving identity invariance is provided, comprising the following steps:
[0008] constructing an anonymization framework, the framework comprising an anonymized image generation module and an identity preservation module;
[0009] Using the desensitized image generated by traditional methods as the initial privacy-preserving supervision, the original pedestrian image is converted into a full-body anonymous image through an anonymization generator;
[0010] The identity preservation module mines the intrinsic relationships between images of the same identity, retains identity-invariant features during the anonymization process, and jointly trains the anonymization generator and the person re-identification (ReID) model to minimize the impact of anonymization on ReID performance.
[0011] Among them, the anonymized image generation module is constructed based on the conditional adversarial network (GAN), and learns the mapping relationship between the original image and the anonymized image through adversarial training. The identity preservation module ensures that the identity characteristics of the anonymized image are consistent with the original image by jointly optimizing the identity-related loss of the ReID model.
[0012] As a further preferred solution, in the aforementioned identity-invariant person re-identification anonymization privacy protection method, the anonymized image generation module adopts the pix2pix framework, including the generator H X and the discriminator D Y , the generator H X Configured to convert the original image x i ∈X p Mapped to the anonymized image H X (x i ), the discriminator D Y Configured to distinguish the real supervised image y i ∈Y and the generated anonymized image H X (x i ), and trained with the following adversarial loss function:
[0013]
[0014] Where n is the number of batch training samples.
[0015] As a further preferred solution, in the aforementioned identity-invariant person re-identification anonymization privacy protection method, the anonymized image generation module further introduces L1 loss to constrain the pixel-level difference between the generated image and the supervision image. The total loss function is:
[0016]
[0017] Among them, λ1 is a hyperparameter used to adjust the pixel loss weight.
[0018] As a further preferred solution, in the aforementioned identity-invariant person re-identification anonymization privacy protection method, the identity preservation module adopts the AGW baseline model as the ReID model, and the loss function of the ReID model integrates the identity classification loss L id , center loss L c and weighted regularized triplet loss L wrt , and jointly train by mixing the original input image and the anonymized image, the total loss function is:
[0019]
[0020] in, is the AGW loss of the original image, is the AGW loss for anonymizing images.
[0021] As a further preferred solution, in the aforementioned identity invariance-preserving pedestrian re-identification anonymization privacy protection method, the traditional desensitization method includes blurring, pixelation or noise enhancement processing, and the generated initial supervision image Y includes the desensitized image after the above processing, which is used to guide the initial training of the anonymization image generation module.
[0022] As a further preferred solution, in the aforementioned identity-invariance-preserving pedestrian re-identification anonymization and privacy protection method, the original pedestrian image preprocessing step includes: adjusting the image size to 256×128 pixels and generating training samples through a data augmentation method, and the data augmentation method includes but is not limited to random cropping, flipping or color jittering.
[0023] As a further preferred solution, in the aforementioned identity-invariant person re-identification anonymization privacy protection method, during the joint training process, the image generation loss of the anonymization generator and the identity recognition loss of the ReID model are optimized simultaneously. The overall objective function is:
[0024]
[0025] in, is the total loss of the anonymized generator, is the total loss of the ReID model.
[0026] As a further preferred solution, in the aforementioned identity-invariance-preserving pedestrian re-identification anonymization privacy protection method, the method evaluates performance through the following indicators: the peak signal-to-noise ratio (PSNR) and structural similarity (SSIM) are used to measure the privacy protection effect, and the cumulative matching characteristic (CMC) and mean average precision (mAP) are used to measure the pedestrian re-identification performance, ensuring that the anonymized image achieves a balance between privacy protection and data utility.
[0027] Based on the second main aspect of the present invention, an electronic device is provided, comprising: at least one processor; a memory communicatively connected to the at least one processor; the memory storing a computer program which, when executed by the at least one processor, enables the at least one processor to implement the aforementioned identity-invariance-preserving pedestrian re-identification anonymization privacy protection method.
[0028] Based on the third main aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed, implements the aforementioned identity-invariance-preserving pedestrian re-identification anonymization and privacy protection method.
[0029] Advantages and beneficial effects of the present invention:
[0030] First, the present invention breaks through the limitations of the traditional separation of anonymization and re-identification technologies, and constructs an integrated framework that collaborates with an anonymized image generation module and an identity preservation module. By using the desensitized image generated by the traditional desensitization method as the initial supervision signal, the conditional adversarial network (GAN) is driven to learn the privacy-preserving mapping relationship. At the same time, the identity preservation module is introduced to mine the intrinsic feature associations of the same identity image to ensure the visual invariance of the pedestrian identity during the anonymization process. This framework has achieved the systematic unification of privacy protection and data utility for the first time, solving the core contradiction between the loss of semantic information caused by privacy protection in traditional methods and the destruction of identity features by deep learning methods.
[0031] Secondly, unlike the defects of the existing technology in which anonymization and re-identification models are designed independently, the present invention proposes a cross-modal joint training mechanism, that is, by inputting the original image and the anonymized image into the ReID model at the same time, integrating the identity classification loss, center loss and weighted regularization triple loss, forcing the model to learn cross-modal consistent identity feature representation. Combining the adversarial training of conditional GAN and the L1 pixel loss constraint, while generating visually privacy-compliant images, it ensures that the feature vector of the anonymized image remains similar to the original image in the identity subspace. This technology breaks through the unconscious changes to identity features caused by traditional anonymization methods and provides an underlying guarantee of identity invariance for the ReID task.
[0032] Thirdly, the present invention designs a dynamic optimization mechanism based on the dual indicators of privacy and performance. During the training process, the privacy protection effect is quantified by the peak signal-to-noise ratio (PSNR) and structural similarity (SSIM), and the ReID performance is evaluated by the cumulative matching accuracy (CMC) and mean average precision (mAP), forming a two-way supervision of the anonymization generator and the ReID model. By iteratively updating the desensitization strength and model parameters of the supervised image, the optimal balance point between privacy protection and data utility is gradually approached, avoiding the performance degradation problem caused by the "one-size-fits-all" desensitization in traditional methods, and realizing adaptive adjustment for different application scenarios.
[0033] From the perspective of privacy protection effectiveness, the full-body anonymized images generated by this invention effectively remove sensitive biometric features such as face and body (PSNR≤20, SSIM≤0.15), meet the requirements of strict privacy protection regulations such as GDPR, and block the risk of identity reconstruction from the source.
[0034] Furthermore, this method achieves breakthrough improvements in data utility. On benchmark datasets such as Market-1501, the ReID performance of anonymized images (rank-1 accuracy improved by 7.2%-14.2%, and mAP improved by 4.6%-24.8%) significantly outperforms traditional desensitization methods, even approaching the original image recognition performance, demonstrating that semantic features related to identity, such as clothing and body shape, are effectively preserved.
[0035] In addition, the model of the present invention has strong compatibility with mixed inputs (original images and anonymized images), highly consistent feature space distribution, supports cross-modal re-identification tasks in complex scenarios, and provides a practical solution that balances privacy and efficiency for fields such as intelligent transportation and public safety.
[0036] In summary, this invention, through technical architecture innovation and joint optimization mechanism, has achieved a "win-win" situation of privacy protection and data value in the field of pedestrian re-identification for the first time, and has significant technological advancement and practical application value. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, without paying any creative work, other drawings obtained based on these drawings still fall within the scope of the present invention.
[0038] Figure 1 The following is a diagram showing an anonymized image generation process in one embodiment of the present invention;
[0039] Figure 2 FIG. 4 shows a schematic diagram of an identity protection process in an embodiment of the present invention. DETAILED DESCRIPTION
[0040] The preferred embodiments of the present invention will be described in detail below so that the purpose, features and advantages of the present invention can be more clearly understood. It should be understood that the following embodiments are not intended to limit the scope of the present invention, but are only intended to illustrate the essential spirit of the technical solution of the present invention.
[0041] In the following description, for the purpose of illustrating the various disclosed embodiments, certain specific details are set forth in order to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the relevant art will recognize that the embodiments may be practiced without one or more of these specific details. In other cases, well-known techniques associated with this application may not be shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.
[0042] Reference throughout this specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, the appearances of "in one embodiment" or "in an embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any manner in one or more embodiments.
[0043] Person re-identification (ReID) is a specialized retrieval task aimed at identifying the same individual across non-overlapping camera views or different time instances of the same camera. Building a ReID system involves five key steps: raw data acquisition, bounding box generation, training data annotation, model training, and re-ID inference. However, privacy risks exist throughout these stages. For example, during data acquisition, ReID data can be stolen from centralized storage systems; in distributed learning frameworks, attackers can reconstruct private training data through shared gradients.
[0044] This invention, specifically for ReID scenarios, integrates encryption and decryption architectures with customized cryptographic protocols to address privacy concerns at the infrastructure level while enabling seamless access to protected data. Its innovation lies in overcoming the privacy-utility dilemma and achieving synergistic optimization through technological integration, providing a viable solution for ReID applications in privacy-critical scenarios.
[0045] The following will describe in detail the anonymized image generation method for person re-identification (ReID) of the present invention. Figure 1 and Figure 2 As shown, the framework of the present invention comprises two key components.
[0046] Part I Figure 1) focuses on anonymized image generation: leveraging the image-to-image translation capabilities of conditional adversarial networks to generate anonymized images in a learnable manner. Furthermore, to improve ReID performance, the supervised image is progressively optimized based on the dual metrics of privacy protection of the anonymized output and ReID effectiveness.
[0047] Part II Figure 2 ) Solve the identity preservation problem: mine the intrinsic relationship between all images of the same identity, so that images of the same identity maintain consistent visual features and similar appearance characteristics while protecting privacy.
[0048] The above framework is modularly arranged, that is, the present invention constructs an anonymization framework, which includes an anonymized image generation module and an identity preservation module.
[0049] Our approach to generating privacy-compliant images is limited to image-to-image translation techniques, which transform an input image into a specific output form through a learnable mapping. Our approach aims to convert the original input image into a protected format, using a blurred, pixelated, or noise-enhanced image as an initial supervisory signal to guide the generation of privacy-preserving images.
[0050] Specifically, the present invention adopts the image translation framework pix2pix based on generative adversarial network (GAN) to achieve this goal.
[0051] The training samples contain labels The original image collection The supervised image set is denoted as (Subject to further updates).
[0052] Anonymization generator H X The goal is to learn the mapping H:X p → Y. To this end, the generator H X and the discriminator D Y Conduct adversarial training: H X Committed to generating an approximation y i Image H X (x i ), and D Y We try to distinguish the real supervised image y i and generate image H X (x i ).
[0053] The adversarial loss function is defined as:
[0054]
[0055] Where n is the number of batch training samples, H X Minimize this objective, and the discriminator D Y Then maximize it.
[0056] In addition, in H X (x i ) and y i Introduce L1 loss between to ensure that the learned mapping will input x i Convert to the desired output y i .
[0057] The total loss function of the anonymized generator combines the above components:
[0058]
[0059] Where λ1 is a hyperparameter used to reduce artifacts in the generated images.
[0060] In the above scheme, the core design of the framework of the present invention is to achieve privacy-utility balance through the collaboration of two components. Figure 1 The anonymized image generation module of the present invention is demonstrated in [1]. Based on image translation technology (e.g., pix2pix) using a conditional adversarial network (GAN), the present invention maps the original image into an anonymized image. The core of the invention is to replace traditional "physical perturbations" (e.g., fixed blur kernels) with "learnable privacy transformations," enabling the anonymization process to achieve both privacy protection and semantic preservation.
[0061] The initial supervision image is generated using traditional desensitization methods (blurring, pixelation, and noise enhancement processing) as a "baseline signal" for privacy protection, guiding the generator to learn image transformations that meet the minimum privacy requirements. At the same time, the supervision signal is dynamically adjusted through subsequent iterative optimization (based on privacy and ReID dual indicators) to avoid excessive desensitization or information loss.
[0062] The generator training mechanism of the present invention adopts the joint constraint of adversarial loss and pixel loss.
[0063] Formula (1) reflects the method of the present invention in terms of adversarial loss, the discriminator D Y Forcing the generator H X This loss embodies the core principle of adversarial learning: the game between the generator and the discriminator forces the generated image to be visually close to the privacy-compliant "real sample," avoiding unnatural artifacts caused by artificial perturbations.
[0064] Formula (2) reflects the L1 pixel loss. By constraining the difference between the generated image and the supervised image at the pixel level, we reduce the loss of high-frequency information (such as clothing texture and body shape) caused by adversarial training during the generation process, ensuring that the anonymized image retains sufficient structural information and provides usable semantic features for the subsequent ReID model. The λ1 hyperparameter balances the weights of the adversarial loss and the pixel loss, avoiding excessive pursuit of visual realism at the expense of structural similarity, or vice versa.
[0065] Compared with existing technologies, the above scheme uses a "one-size-fits-all" approach in traditional desensitization (such as a fixed blur kernel). It cannot adapt to the importance of features in different images (for example, the front image of a pedestrian requires stronger blurring, while the side image can retain more contour information), resulting in the accidental deletion of key identity features (such as clothing color and items carried).
[0066] Through end-to-end learning of conditional GAN, the generator can dynamically adjust the anonymization strategy according to the specific features of the input image (such as posture and perspective), while protecting sensitive areas (such as the face) while retaining non-sensitive but identity-related features (such as shirt stripes and backpack shape).
[0067] On the other hand, the "updatability" of the supervised image is the core design, that is: the initial supervisory signal provides the bottom line constraint for privacy protection, and subsequently through ReID performance feedback (such as reducing the desensitization intensity when the recognition accuracy decreases), a dynamic balance between privacy protection and data utility is achieved, breaking through the fixed "privacy-utility" trade-off in traditional methods.
[0068] In addition, the above solution differs from existing technologies in the following key ways: existing image translation technologies (such as CycleGAN) are primarily used for style transfer or cross-domain image generation. They do not explicitly incorporate privacy protection metrics and identity invariance constraints. Generated images may alter a person's identity (for example, by changing clothing color), making them unsuitable for ReID tasks.
[0069] The supervisory signal of the present invention anchors the privacy protection target (initially the traditional desensitized image) to ensure that the privacy compliance of the generated image is quantifiable (such as the PSNR and SSIM indicators are controllable); subsequently, the identity preservation module ( Figure 2 ), namely “jointly training the anonymization generator and the ReID model”), reversely constraining the generator through the ReID loss function to avoid destroying identity-related features during the generation process and achieve “identity invariance under privacy protection”.
[0070] The anonymized image generation method proposed in this solution achieves the key capabilities of "controllable privacy protection strength and adjustable semantic information retention" through the learnable mapping of conditional GANs, dual loss function constraints, and dynamic supervisory signal optimization. Its core value lies in breaking the "rigid processing" limitations of traditional desensitization methods and providing high-quality anonymized image input for subsequent identity preservation modules, forming the technical cornerstone of the privacy-utility balance.
[0071] Furthermore, the present invention strictly analyzes the intrinsic correlation between all images of the same identity. From the perspective of human vision, subset X p The images in have similar contour features; from a machine vision perspective, these images should produce the same recognition output. This dual intuitive observation motivates us to construct an approximate identity-specific feature subspace for image generation.
[0072] The framework of this paper embeds the ReID model into a joint learning architecture and adopts the advanced method AGW in ReID research as the baseline model. Although anonymization is a privacy protection scheme in ReID systems, directly applying traditional blurring methods to desensitized images will severely degrade recognition performance.
[0073] To this end, this paper proposes a mixed image batch (combining original images and anonymized images) to jointly train the ReID model and the anonymized generator. Loss function It integrates three commonly used losses in ReID tasks, namely identity classification loss (L id ), center loss (L c ) and weighted regularized triplet loss (L wrt ) for optimization.
[0074] To ensure the compatibility of the ReID model for both the original and privacy-preserving scenarios, this paper takes both the original image and the anonymized image as input. Therefore, the total loss function of the ReID model is defined as:
[0075]
[0076] In summary, the final objective function of the ReID anonymization model for mixed images is:
[0077]
[0078] Compared with the existing technology, the core design of the above scheme lies in the identity retention mechanism from "visual similarity" to "feature invariance". From the perspective of human vision, pedestrian images of the same identity have consistent global features such as outline and body shape (such as the same height and clothing style). These features are the key clues for ReID. From the perspective of machine vision, ideally, images of the same identity should be mapped to the same feature vector by the ReID model to ensure recognition consistency. Based on this, the present invention constructs an "identity-specific feature subspace", requiring that the feature vector of the anonymized image remains close to the original image in this subspace, that is, identity invariance.
[0079] The core of the specific technical implementation of this invention lies in the joint training and hybrid input strategy. First, the advanced model AGW in the field of ReID is adopted, which integrates three loss functions. Among them, the identity classification loss (L id ) forces the feature vector to correctly classify the identity and ensure class separability; the center loss (L c ) shortens the distance between the same identity feature vector and the class center, enhancing the compactness within the class; the weighted regularized triplet loss (L wrt ) Through difficult sample mining, the inter-class distance of different identity feature vectors is expanded and the discriminative power is improved.
[0080] When performing mixed batch training, the original images and anonymized images are mixed into a batch and input into the ReID model, forcing the model to learn consistent feature representations across modalities. At the same time, the feature extraction of the original image and the anonymized image is constrained to ensure that the anonymization operation does not destroy identity-related features (such as clothing color and shape of carried objects).
[0081] The physical meaning of formula (3) is to require the ReID model to calculate the original image x and the anonymized image H X The feature extraction results of (x) all meet the requirements of identity classification, intra-class compactness and inter-class separability, that is, the feature vectors of the two are highly similar in the identity subspace. If the features of the anonymized image deviate from the original features, Will increase, back propagation promotes the anonymization generator H X Adjust generation strategies to avoid destroying identity features.
[0082] The physical meaning of formula (4) is to integrate the anonymized generator loss into the total objective function (Privacy protection oriented) and ReID model loss (identity preservation orientation), forming a two-way constraint to Ensure that anonymized images meet privacy visual requirements (e.g. blurring faces); Ensure that the features of the anonymized image are compatible with the original image to maintain the ReID performance.
[0083] Therefore, this paper "binds" the ReID model with the anonymization generator for training, enabling the generator to "perceive" the importance of identity features while protecting privacy (for example, automatically retaining clothing patterns and blurring only faces). By mixing inputs, the model is forced to adapt to the differences in feature distribution between the original and anonymized images, avoiding "domain shift" and improving model robustness.
[0084] This paper explicitly introduces "identity preservation constraints" and uses the ReID loss function to reversely guide the anonymization process, forming a closed-loop optimization of "privacy protection-feature preservation"; and uses the inherent correlation of images of the same identity to construct feature subspace constraints, so that the anonymization operation has "identity awareness" capabilities rather than blind perturbations.
[0085] The identity-preserving module is a key pillar of this invention's "privacy-utility trade-off." By jointly training the ReID model and anonymization generator, combined with the coordinated optimization of multiple loss functions, we ensure that the anonymized image maintains visual privacy while maintaining a high degree of consistency between its feature vectors and the original image in the identity subspace. This design overcomes the limitations of traditional anonymization methods, which prioritize privacy over identification, and provides a practical anonymization solution for ReID tasks, particularly suitable for public safety scenarios with strict requirements on both privacy and identification accuracy.
[0086] We conducted experiments on a widely used person re-identification (ReID) dataset. The Market-1501 (Liang Zheng, Liyue Shen, Lu Tian, Shengjin Wang, Jingdong Wang, and Qi Tian. 2015. Scalable person re-identification: A benchmark. In ICCV. 1116–1124.) dataset contains 32,668 annotated bounding boxes captured by six cameras. The dataset consists of 12,936 training images (750 identities), 3,368 query images (750 identities), and 15,913 gallery images (751 identities). We evaluated our models using image quality metrics and re-identification metrics. For privacy protection and restoration, we employed two widely used metrics: peak signal-to-noise ratio (PSNR) and structural similarity index (SSIM). For ReID performance, we measured the cumulative matching characteristic (CMC, i.e., Rank-k matching accuracy) and mean average precision (mAP).
[0087] The specific implementation details are as follows:
[0088] First, the original training set was split into a new training set and a validation set in a 4:1 ratio. Subsequently, the validation set was further split into a gallery set and a query set in the same ratio. All performance metrics during training were evaluated on the validation set.
[0089] In all experiments, we jointly trained the three models for 120 epochs with a batch size of 64. All input images were resized to 256 × 128 pixels and desensitized by blurring (12 × 12 kernel), pixelation (24 × 24 blocks), and adding noise augmentation N(0, 0.5) with a mean of 0 and a variance of 0.5. The results are shown in Table 1.
[0090] Table 1. Comparison of ReID performance of common AGW models on protected images: “BASE” represents traditional desensitized images.
[0091]
[0092] The results demonstrate that our anonymization framework is adaptable to privacy-preserving mechanisms. Furthermore, our model performs comparably to baseline configurations, confirming its suitability for person re-ID tasks involving mixed image sets (containing both original and processed images). This indicates that the feature space distribution of anonymized images maintains significant similarity to that of unmodified images. Notably, our approach outperforms in privacy-preserving scenarios compared to cross-domain evaluations, likely due to the residual domain differences between the original and anonymized image modalities.
[0093] Table 1 shows that the SSIM value between the original image and the protected image generated using the desensitized image is higher than that of the image generated by the proposed method, while the PSNR value is lower. This suggests that the identity feature subspace assigns weight coefficients to the identity feature vectors, so the constructed mask can more effectively change the structure of the original image.
[0094] As shown in Table 2, compared to the baseline method of blurring, pixelation, and adding noise, in terms of blur robustness, the Rank-1 accuracy is improved by 7.2% and the mAP is improved by 15.6%, indicating that retrieval consistency is enhanced. In terms of pixelation resistance, the Rank-1 accuracy is improved by a modest 3.6% and the mAP is improved by 4.6%, indicating that the ranking matching is stable even under coarse spatial quantization.
[0095] In terms of noise immunity, the Rank-1 accuracy jumps significantly by 14.2%, and mAP surges by 24.8% (from 50.6% to 75.4%), which is the largest absolute improvement among all indicators.
[0096] Table 2. ReID performance evaluation on three ReID datasets: “BASE” represents the AGW model trained on desensitized images. The table mainly shows the Rank-r accuracy (%) and mean average precision (mAP) (%).
[0097]
[0098] In summary, we propose a reversible method that balances privacy and data utility for person re-identification (ReID) of pedestrian images. This method creates anonymized full-body images with minimal impact on ReID accuracy, and employs a stepwise training process to improve performance. Comprehensive testing demonstrates that our method effectively meets three key requirements: preserving privacy, recovering the original identity, and maintaining reliable ReID results even in the presence of a mixture of normal and anonymized images.
[0099] It should be noted that the above content involves the specific implementation of the present invention, and the parts not described in detail in the above content are all well-known technologies for those skilled in the art.
[0100] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.
Claims
1. A privacy-preserving anonymization method for person re-identification with identity preservation, characterized by: The steps include: constructing an anonymization framework, the framework comprising an anonymized image generation module and an identity preservation module; Using the desensitized image generated by traditional methods as the initial privacy-preserving supervision, the original pedestrian image is converted into a full-body anonymous image through an anonymization generator; The identity preservation module mines the intrinsic relationships between images of the same identity, retains identity-invariant features during the anonymization process, and jointly trains the anonymization generator and the person re-identification (ReID) model to minimize the impact of anonymization on ReID performance. Among them, the anonymized image generation module is constructed based on the conditional adversarial network (GAN), and learns the mapping relationship between the original image and the anonymized image through adversarial training. The identity preservation module ensures that the identity characteristics of the anonymized image are consistent with the original image by jointly optimizing the identity-related loss of the ReID model.
2. The identity-invariant-preserving person re-identification anonymization privacy protection method according to claim 1 is characterized in that: The anonymized image generation module adopts the pix2pix framework, including the generator H X and the discriminator D Y , the generator H X Configured to convert the original image x i ∈X p Mapped to the anonymized image H X (x i ), the discriminator D Y Configured to distinguish the real supervised image y i ∈Y and the generated anonymized image H X (x i ), and trained with the following adversarial loss function: Where n is the number of batch training samples.
3. The anonymization and privacy protection method for person re-identification with identity invariance preservation according to claim 1 is characterized in that: The anonymized image generation module also introduces L1 loss to constrain the pixel-level difference between the generated image and the supervised image. The total loss function is: Among them, λ1 is a hyperparameter used to adjust the pixel loss weight.
4. The anonymization and privacy protection method for person re-identification with identity invariance preservation according to claim 1 is characterized in that: The identity preservation module adopts the AGW baseline model as the ReID model, and the loss function of the ReID model integrates the identity classification loss L id , center loss L c and weighted regularized triplet loss L wrt , and jointly train by mixing the original input image and the anonymized image, the total loss function is: in, is the AGW loss of the original image, is the AGW loss for anonymizing images.
5. The identity-invariant-preserving person re-identification anonymization privacy protection method according to claim 1 is characterized in that: The traditional desensitization method includes blurring, pixelation or noise enhancement processing, and the generated initial supervision image Y includes the desensitized image after the above processing, which is used to guide the initial training of the anonymized image generation module.
6. The identity-invariant-preserving person re-identification anonymization privacy protection method according to claim 1, characterized in that: The original pedestrian image preprocessing step includes: adjusting the image size to 256×128 pixels and generating training samples through a data enhancement method, wherein the data enhancement method includes but is not limited to random cropping, flipping or color jittering.
7. The anonymization and privacy protection method for person re-identification with identity invariance preservation according to claim 1 is characterized in that: During the joint training process, the image generation loss of the anonymization generator and the identity recognition loss of the ReID model are optimized simultaneously. The overall objective function is: in, is the total loss of the anonymized generator, is the total loss of the ReID model.
8. The identity-invariant-preserving person re-identification anonymization privacy protection method according to claim 1, characterized in that: The method described above evaluates performance through the following indicators: Peak Signal-to-Noise Ratio (PSNR) and Structural Similarity (SSIM) are used to measure the privacy protection effect, and Cumulative Matching Characteristic (CMC) and Mean Average Precision (mAP) are used to measure the pedestrian re-identification performance, ensuring that the anonymized image achieves a balance between privacy protection and data utility.
9. An electronic device, characterized in that: include: at least one processor; a memory communicatively coupled to the at least one processor; The memory stores a computer program, which, when executed by the at least one processor, enables the at least one processor to implement the identity-invariance-preserving pedestrian re-identification anonymization and privacy protection method according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed, the identity-invariance-preserving pedestrian re-identification anonymization and privacy protection method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Adversarial sample defense method based on feature remapping and application
CN111401407A
Pedestrian identity privacy protection method in combination with k anonymity
CN114036553A
Identity privacy protection method and system based on sample isolation mechanism for pedestrian re-identification
CN115641609A
Cross-modal pedestrian re-identification method and device based on intermediate modal and representation learning
CN116311384A
Apparatus and method for anonymizing image content
EP3451209A1