Image privacy data forgetting method driven by image attention mechanism
Through the method driven by the graph attention mechanism, the ResNet101, YOLOv8 and VGG16 models are used to automatically identify image privacy areas, and combined with GGNN and class activation graph optimization models, the accuracy and targeted problems of image privacy data recognition and removal in the existing technology are solved, and fine-grained privacy data forgetting is achieved, and data availability is improved.
Patent Information
- Application Number
- CN202510579712.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-29
AI Technical Summary
The existing data forgetting technology cannot effectively identify and accurately remove private data in images without retraining, and is prone to accidentally damage non-private data, resulting in reduced data availability.
Using a graph attention mechanism-driven method, by extracting the structured features of the image, using ResNet101, YOLOv8 and VGG16 models, the object attention coefficient is calculated, combined with the gated graph neural network GGNN and the class activation diagram, the privacy areas in the image are automatically identified and pruned, and the total loss function optimization model is calculated to achieve fine-grained privacy data forgetting.
It realizes automated and accurate image privacy data identification and removal, improves the targeted nature of data forgetting, retains the prediction contribution of non-private areas, and adapts to the needs of privacy data forgetting in different scenarios.
Smart Images

Figure CN120563995A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of artificial intelligence privacy protection and relates to an image privacy data forgetting method driven by a graph attention mechanism. Background Art
[0002] The development of artificial intelligence technology has benefited from tremendous progress in data storage and data computing. The resulting artificial intelligence models are trained based on the explosive growth of user personal data, setting off a wave of widespread integration with multiple fields.
[0003] Personal data reflects users' behavior in the real world. The privacy information carried in the data is embedded in the parameters of the artificial intelligence model after complex training iterations, resulting in an increasing risk of privacy leakage.
[0004] In recent years, problems with data leakage of artificial intelligence models have emerged one after another. When artificial intelligence company A cooperates with data owner B and uses data owner B's data for model training, when the data authorization expires or involves some sensitive information such as privacy, according to the law, data owner B has the right to require artificial intelligence company A to remove the data information from the model.
[0005] However, AI company A cannot delete the entire model as requested by data owner B, as the cost of retraining is prohibitive. To mitigate privacy risks, AI company A will change its data authorization policy. The only way to delete data owner B's data is to not retrain the model. However, model parameters don't show any clear connection to the training data, making it extremely difficult to remove information associated with a specific piece of data from the model. This is especially true for deep neural networks, which lack interpretability and, for optimal performance, randomly inactivate neurons during training, making it impossible to determine how the training data has affected the neurons.
[0006] Therefore, how to effectively remove model privacy information without retraining has become a research problem that needs to be solved urgently.
[0007] Although existing data forgetting technologies can remove specified data information without retraining, they have many problems in applying private data forgetting:
[0008] On the one hand, existing data forgetting technologies require users to first traverse the image dataset to determine which images are private and manually specify the data to be removed. This is cumbersome and impractical for large-scale datasets, especially data without privacy labels.
[0009] On the other hand, existing data forgetting technology is a coarse-grained general removal based on samples, which lacks specificity in the processing of privacy information. It also removes non-privacy information in the samples, reducing data availability. Summary of the Invention
[0010] To address the problems of tedious manual labeling and coarse-grained deletion of non-private data in existing data forgetting technologies, the present invention provides an image privacy data forgetting method driven by a graph attention mechanism, which realizes automatic identification and fine-grained image privacy data deletion.
[0011] The specific steps of the image privacy data forgetting method driven by the graph attention mechanism are as follows:
[0012] Step 1: Select an original image from the privacy dataset, extract the structured image features from it and arrange them into a node feature matrix;
[0013] The structured image features of each original image include the following three types:
[0014] 1) Use the ResNet101 residual neural network model to extract full-image pixel features;
[0015] 2) Using the YOLOv8 object detection model to scan 81 common objects that may exist in the image, the object category features are obtained;
[0016] 3) The original image is cropped according to the location of the object area to obtain the corresponding object pixel data, which is input into the VGG16 convolutional neural network model to extract the object area pixel features.
[0017] The node feature matrix in the original graph includes two attribute nodes representing private or public {c i |i=1,2} and 81 types of common object nodes {o j |j=1,2,…,81}.
[0018] Step 2: Calculate the attention coefficient of each object in the original image based on the hidden layer states of the attribute nodes and object nodes in the node feature matrix;
[0019] The hidden layer states of attribute nodes and object nodes are represented as and
[0020] For attribute node c i and object node o j , first use the low-rank bilinear pooling method to fuse its hidden states:
[0021]
[0022] Among them U a and V a is the parameter matrix to be learned.
[0023] Then, the attention coefficient is calculated using the fused hidden state:
[0024] e ij =att(h ij )
[0025] α ij =σ(e ij )
[0026] Where att(·) is the attention calculation function, e ij Represents the object node o j For attribute node c i The influence weight of is normalized to (0,1) to form the attention coefficient α ij , when a certain type of object has never appeared in the entire image privacy dataset, its attention coefficient α ij Take it as 0.
[0027] Step 3: Sort the object nodes in the image in descending order according to the attention coefficient, and use the gated graph neural network (GGNN) to determine the privacy area positions corresponding to all object nodes in the image through the attention coefficient sequential pruning method.
[0028] Specifically:
[0029] Step 301: Select the first object node from the object nodes sorted by attention coefficient and delete it, rearrange the remaining node feature matrix, and input it into the GGNN to infer privacy attributes;
[0030] The node feature matrix is input into the gated graph neural network (GGNN). The gated recurrent unit (GRU) in the GGNN continuously updates the node hidden layer state based on historical information, ultimately learning the optimal feature encoding for each node in the node feature matrix. After flattening, it is passed through a fully connected neural network for dimensionality reduction. An attention mechanism is added before the fully connected layer of the GGNN to authenticate the object node based on its contribution to the prediction result. The node features are then passed through a binary classifier to output the privacy attribute prediction result of the original image, which is either private or public.
[0031] Step 302: Determine whether the predicted result of the privacy attribute is public. If so, proceed to step 303; otherwise, the predicted result is private. Continue to remove the second object node and re-infer the privacy attribute. Continue in this way until the GGNN prediction result is public.
[0032] Step 303: All object nodes removed during the pruning process are all privacy objects in the image, thereby determining the positions of all privacy areas in the image.
[0033] Step 4: Select an image classification model as the to-be-forgotten model M. The user inputs training set image samples, determines the location of the privacy area for each image sample, and calculates the total loss of the model M to optimize the model.
[0034] The specific steps are:
[0035] First, the user inputs the training set image samples, extracts the structured image features of each image sample and arranges them into a node feature matrix, and calculates the object attention coefficient in each image sample. Using the gated graph neural network (GGNN), the privacy area positions corresponding to all object nodes in the image sample are determined through sequential pruning, thereby obtaining the privacy attributes of each image sample and all privacy object nodes.
[0036] Then, the total loss function of the to-be-forgotten model M is calculated based on the privacy attribute;
[0037] If the privacy attribute prediction result of the image sample is public, its privacy risk loss is 0, then the binary cross entropy performance loss is That is the total loss.
[0038] θ is the parameter of the model to be forgotten M, x (n) is the image sample input by the user; y (n) Assign business attributes to image samples for users.
[0039] If the privacy attribute prediction result of the image sample is private, the total loss is the sum of performance loss and privacy risk loss. The calculation formula is:
[0040] loss over =λloss perform +(1-λ)loss privacy +r||θ|| 2
[0041] Among them, loss over is the overall loss, loss perform is the performance loss, loss privacy is the privacy risk loss, the privacy risk coefficient λ∈[0,1), and r is the regularization coefficient.
[0042] Step 5: Use batch gradient descent to continuously update the parameters θ of the to-be-forgotten model M until the total loss reaches a minimum, and obtain the optimal parameters θ of the to-be-forgotten model M u ;
[0043] Step 6: The user uses the optimal parameter θ u The to-be-forgotten model M automatically locates the privacy areas of various objects in the input image.
[0044] The advantages of the present invention are:
[0045] 1) A graph attention-driven forgetting method for image privacy data automatically infers image privacy attributes (private / public) and locates privacy-related areas in the image without manual user specification. Compared to traditional deep neural network privacy detection, this method can model the semantic structure of images and more accurately locate private areas in images.
[0046] 2) A graph-attention-driven method for forgetting private image data. This method uses class activation maps to guide fine-grained forgetting of private image data. The forgetting units are broken down into individual object regions within the image. Data forgetting is specifically targeted at private regions, improving the forgetting effect while retaining the prediction contribution of other regions, enhancing model performance after forgetting. The method also supports adjusting the forgetting strength of private data to suit different scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 This is a schematic diagram of a method for forgetting image privacy data driven by a graph attention mechanism in the present invention;
[0048] Figure 2 This is a flowchart of a method for forgetting image privacy data driven by a graph attention mechanism of the present invention;
[0049] Figure 3 This is the image structured feature extraction graph of the present invention;
[0050] Figure 4 This is a schematic diagram of the image privacy feature detection principle of the present invention; DETAILED DESCRIPTION
[0051] To facilitate understanding and implementation of the present invention by those skilled in the art, the present invention is further described below in detail with reference to the accompanying drawings and embodiments. It is apparent that the embodiments described are merely partial embodiments of the present invention, not all embodiments. All other embodiments derived by those skilled in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.
[0052] To address the lack of specificity in general data forgetting methods for private data, ensure the controllable flow of privacy within the model lifecycle, and meet privacy removal requirements, this paper proposes a graph attention mechanism-driven image private data forgetting method. This method consists of two parts: privacy feature detection and private data forgetting. First, privacy detection locates private objects in the image dataset. Then, the to-be-forgotten model is guided to perform incremental learning, informing it that the private content is no longer important for the reasoning task. This ensures that the model no longer retains associated information during iteration, thus achieving private data forgetting.
[0053] The specific principle is as follows Figure 1 As shown in the figure, the image objects are first decomposed through privacy feature detection to extract the structural features of each object in the image. This is then input into the constructed privacy detection model, which uses a gated graph neural network to infer the image's privacy attributes. Sequential pruning of attention coefficients is used to accurately locate the location of private areas. Finally, the class activation map is used to calculate the model's privacy risk loss, guiding the model's incremental learning and achieving private information removal.
[0054] like Figure 2 The specific steps are as follows:
[0055] Step 1: Select an original image from the privacy dataset, extract the structured image features from it and arrange them into a node feature matrix;
[0056] The image structured feature extraction process is as follows Figure 3 As shown:
[0057] Traditional neural networks, such as convolutional neural networks, struggle to directly capture structured features and must rely on limited pixel data for inference. While image pixel data contains basic visual information, it lacks the ability to model the relationships between objects within the image, effectively failing to fully express the semantics of the objects. Privacy lies in the high-dimensional semantic features within an image, not in isolated pixel regions. Furthermore, due to legal and regulatory restrictions, private data cannot be expanded and collected in the same large quantities as other public data. Therefore, it is essential to mine richer feature information from image privacy datasets with limited size and imbalanced categories.
[0058] This paper uses an existing mature visual analysis model to extract high-dimensional structured features that can reflect the connections between objects from low-dimensional pixel data. The structured image features of each original image include the following three types:
[0059] The ResNet101 residual neural network model was used to extract full-image pixel features. The YOLOv8 object detection model was used to scan for 81 common objects that might be present in the image and obtain object category features. The original image was cropped based on the object's location to obtain the corresponding object pixel data, which was then input into the VGG16 convolutional neural network model to extract the object region pixel features.
[0060] The two pixel features have the same dimensions but come from neural networks with different structures. This makes the features of the full image and the object area more distinguishable rather than a simple subset relationship, which helps improve the effectiveness of the privacy detector.
[0061] The image privacy feature detection process is as follows: Figure 4 As shown:
[0062] For each original image in the privacy dataset, the structured image features are extracted and arranged into a node feature matrix;
[0063] The node set includes two attribute nodes representing private or public {c i |i=1,2} and 81 types of common object nodes {o j |j=1,2,…,81}.
[0064] One-hot encoding is implemented for two types of nodes to distinguish them: for attribute nodes c i Corresponding features All pixel features are assigned to the entire image; object node o j Corresponding features There are two cases: if object o j Exists in the original image, Assign pixel features to the corresponding object area, otherwise the value is a 0 vector of the same dimension.
[0065] To leverage prior node knowledge, track the connection between object categories and privacy attributes, and construct an object privacy knowledge graph, guiding information transfer and feature aggregation in the initial state of the graph neural network, the correlation between objects and privacy classes is described by the weight of the edge between the two types of nodes. The frequency of each type of object appearing in the two privacy classes is counted, normalized, and assigned to the corresponding edge weight.
[0066] Step 2: Calculate the attention coefficient of each object in the original image based on the hidden layer states of the attribute nodes and object nodes in the node feature matrix;
[0067] The hidden layer states of attribute nodes and object nodes are represented as and
[0068] For attribute node c i and object node o j , first use the low-rank bilinear pooling method to fuse its hidden states:
[0069]
[0070] Among them U a and V a is the parameter matrix to be learned.
[0071] Then, the attention coefficient is calculated using the fused hidden state:
[0072] e ij =att(h ij )
[0073] α ij =σ(e ij )
[0074] Where att(·) is the attention calculation function, e ij Represents the object node o j For attribute node c i The influence weight of is normalized to (0,1) to form the attention coefficient α ij , when a certain type of object has never appeared in the entire image privacy dataset, its attention coefficient α ij Take it as 0.
[0075] Step 3: Sort the object nodes in the image in descending order according to the attention coefficient, and use the gated graph neural network (GGNN) to determine the privacy area positions corresponding to all object nodes in the image through the attention coefficient sequential pruning method.
[0076] The attention coefficient represents the impact of each object on the inference of privacy attributes. By sequentially pruning the attention coefficient, privacy detection can specifically locate objects inside the image, paving the way for forgetting private data.
[0077] Specifically:
[0078] Step 301: Select the first object node from the object nodes sorted by attention coefficient and delete it, rearrange the remaining node feature matrix, and input it into the GGNN to infer privacy attributes;
[0079] This paper uses Gated Graph Neural Networks (GGNNs) to perform graph-level classification tasks and infer the privacy attributes of the original image. The node feature matrix is input into the Gated Graph Neural Network (GGNN). The Gated Recurrent Units (GRUs) in the GGNN continuously update the node hidden layer states based on historical information, removing redundancy while retaining as much important information as possible. Ultimately, the optimal feature encoding for each node in the node feature matrix is learned. After flattening, the matrix is subjected to dimensionality reduction through a fully connected neural network. An attention mechanism is added before the fully connected layer of the GGNN to authenticate the object node based on its contribution to the prediction result. The node features are then passed through a binary classifier to output the predicted image privacy attribute of the original image as either private or public.
[0080] In order to enable the detection model to accurately locate object nodes with significant privacy features in the image, adaptive learning is used to adjust the weights of the edges, and an attention mechanism is added. This allows the GGNN model to authenticate the object nodes according to their contribution to the prediction results during iteration, fully modeling the privacy level of each object in the image to facilitate the subsequent implementation of privacy data forgetting.
[0081] Step 302: Determine whether the predicted result of the privacy attribute is public. If so, proceed to step 303; otherwise, the predicted result is private. Continue to remove the second object node and re-infer the privacy attribute. Continue in this way until the GGNN prediction result is public.
[0082] Step 303: All object nodes removed during the pruning process are all privacy objects in the image, thereby determining the positions of all privacy areas in the image.
[0083] Step 4: Select an image classification model as the to-be-forgotten model M. The user inputs training set image samples and determines the location of the privacy area of each image sample. The class activation map is used to calculate the total loss of the model M and optimize the model.
[0084] The "to-be-forgotten model" refers to a model waiting to be forgotten for privacy reasons, and its ultimate task is to remove the privacy information it contains. It is a convolutional structure model (such as classic CNN, VGG, ResNet, etc.) that uses images as training data. The present invention adopts a class activation map visualization analysis method to calculate the privacy risk loss and guide the target model to perform a special forgetting operation on the privacy area identified by the detector. The key role of the class activation map guidance strategy is to calculate the decision contribution of the privacy area in the image and impose a privacy risk penalty on it, so that the model gradually reduces its dependence on privacy features during the incremental training process, while trying to maintain the original classification function to avoid the forgetting operation from causing too much negative impact on the model performance.
[0085] The specific steps are:
[0086] First, the user inputs the training set image samples, extracts the structured image features of each image sample and arranges them into a node feature matrix, and calculates the object attention coefficient in each image sample. Using the gated graph neural network (GGNN), the privacy area positions corresponding to all object nodes in the image sample are determined through sequential pruning, thereby obtaining the privacy attributes of each image sample and all privacy object nodes.
[0087] Then, the total loss function of the to-be-forgotten model M is calculated based on the privacy attributes, guiding the model’s incremental learning to achieve private information removal.
[0088] The total loss of the to-be-forgotten model on the training set is composed of two components: performance loss and privacy risk loss. The performance loss forces the model to maintain its original classification function as much as possible while mitigating privacy risks, thus preventing degradation of classification accuracy that could affect usability. Assuming the to-be-forgotten model is for image classification, the classification loss is a standard image classification loss function, such as cross-entropy loss, which forces the model to maintain correctness across all image category predictions.
[0089] Privacy risk loss is the additional risk loss introduced by private objects in an image. This loss is specifically used to remove the model's reliance on private regions. The Class Activation Map method is used to assess the contribution of private object regions to model decisions. The contribution value represents the impact of the private region on the model output. Using the lowest contribution value in the image as a benchmark, the contribution is normalized using the range method to represent the risk loss for each private region. The risk losses for all private regions are then summed to obtain the model's privacy risk loss for the entire image, which is then added to the overall loss function.
[0090] For images with a privacy attribute of public, the privacy risk loss is 0, and the total loss is the loss in classification performance.
[0091] For images with a private attribute, a privacy risk coefficient λ is set to balance the removal of private information with maintaining model performance. Sequential pruning is first performed based on the attention coefficient to locate the private object regions in the image. The class activation map method is then used to calculate the decision contribution of the private regions as an additional privacy risk penalty.
[0092] The privacy forgetting process is completed after the forgetting model performs incremental learning.
[0093] If the privacy attribute prediction result of the image sample is public, its privacy risk loss is 0, then the binary cross entropy performance loss is That is the total loss.
[0094] θ is the parameter of the model to be forgotten M, x (n) is the image sample input by the user; y (n) Assign business attributes to image samples for users.
[0095] If the privacy attribute prediction result of the image sample is private, the total loss is composed of the performance loss and the privacy risk loss. The calculation formula is:
[0096] loss over =λloss perform +(1-λ)loss privacy +r||θ|| 2
[0097] Among them, loss over is the overall loss, loss perform is the performance loss, loss privacy is the privacy risk loss, the privacy risk coefficient λ∈[0,1), and r is the regularization coefficient. By controlling the regularization strength, the model is prevented from overfitting.
[0098] Step 5: Use batch gradient descent to continuously update the parameters θ of the to-be-forgotten model M until the total loss reaches a minimum, and obtain the optimal parameters θ of the to-be-forgotten model M u ;
[0099] Step 6: The user uses the optimal parameter θ u The to-be-forgotten model M automatically locates the privacy areas of various objects in the input image.
[0100] The embodiments of the method for forgetting private data in the present invention are as follows:
[0101] The parameter of the to-be-forgotten model M is θ o , the loss function is YOLO is an object detector that scans and obtains the category and location of each object in the image; CAM is an interpretable feature analyzer that outputs the contribution of each small area in the original image to the model decision; P is a privacy feature detection model, the output label is the image privacy attribute prediction, and the output att_co is the attention coefficient of each object in the image; θ u are the model parameters after forgetting.
[0102]
[0103] Initialization phase: θ u Take the initial value θ o , the forgotten model M starts from the original parameters and performs incremental learning at the learning rate α, gradually traversing the training set of M The loss is recalculated taking into account privacy risks. To highlight the key points of the algorithm and simplify the influence of other factors, it is assumed that the batch size of each iteration is the full training sample capacity.
[0104] Loss synthesis process: First, the original image is input into the trained privacy feature detection model P, and the privacy attribute of the image and the attention coefficient of each object in it are output. If the privacy attribute of the predicted image is public, the additional privacy risk penalty generated by this image is not calculated, and the binary cross entropy performance loss That is the total loss.
[0105] Otherwise, for images with a privacy attribute of private, each object is sorted in descending order according to the attention coefficient, removed from the original image successively from high to low, and re-entered into the privacy detection model P for prediction until the privacy attribute is predicted to be public, thus obtaining all the private objects in the original image.
[0106] Next, the interpretable feature analyzer (CAM) is used to calculate the contribution of each privacy object's region to the decision-making of model M. The difference relative to the lowest contribution in the image is normalized and summed to obtain the privacy risk loss of the to-be-forgotten model M on the original image. The algorithm controls the aggregation ratio of the two losses by setting the privacy risk coefficient λ. A larger λ indicates a greater privacy risk penalty imposed on the model and stronger privacy protection. A smaller λ improves model performance. When λ is 0, the algorithm degenerates into a standard neural network model training algorithm. In the algorithm, r is the regularization coefficient, which flattens the model parameters to prevent overfitting.
[0107] Termination condition. Use batch gradient descent to continuously update the parameters of the forgetting model M, stop after the specified number of iterations T, and output the forgotten model parameters θ u .
[0108] The performance loss is the ordinary binary cross entropy loss, which maintains the business capabilities of the model to be forgotten. For example, the image classification model is the classification capability to avoid unusability due to poor performance after privacy is forgotten.
[0109] Privacy risk loss is complex. First, using Class Activation Map (CAM) technology, we output the contribution of each region in the image to the model's decision-making. This can be understood as the model's focus. For example, if the model performs well in a picture of a cat, the contribution of the region containing the cat will be significantly higher, while the contribution of the background region will be lower. Privacy risk loss is essentially a penalty for the model's focus. If the contribution of a private region is high, it indicates that the model relies on it to make decisions and is focused on privacy. The training goal is to reduce the contribution of the private region to the same level as the background region, eliminating the model's reliance on the private region. In the eyes of the model, the private region gradually becomes completely unimportant.
[0110] The core idea of this invention is to separate private objects from images through a sequential pruning method. Assuming the model's generalization performance is good enough, it will pay less attention to factors in the image that are not relevant to classification and focus on objects that match the label with lower loss. Therefore, the model's attention can be diverted from private objects by controlling loss and imposing privacy risk penalties. To avoid privacy risk loss, the model will minimize its decision-making reliance on private areas during training. The status of private objects in decision-making gradually decreases, approaching the lowest background image, thereby achieving forgetting of private data.
Claims
1. A method for forgetting image privacy data driven by a graph attention mechanism, characterized by: The specific steps are as follows: Step 1: Select an image classification model as the to-be-forgotten model M. The user inputs a training set of image samples, extracts the structured image features of each image sample, and arranges them into a node feature matrix. The node feature matrix includes two attribute nodes representing private or public {c i |i=1,2} and 81 types of common object nodes {o j |j=1,2,…,81}; Step 2: Calculate the attention coefficient of each object in the image sample and sort the object nodes in the image in descending order according to the attention coefficient; Step 3: Using the gated graph neural network (GGNN), we determine the privacy region locations corresponding to all object nodes in the image sample through a sequential pruning method, thereby obtaining the privacy attributes of each image sample and all privacy object nodes. The method of sequential pruning is specifically as follows: Step 301: Select the first object node from the object nodes sorted by attention coefficient and delete it. Rearrange the remaining node feature matrix and input it into the GGNN to infer the privacy attribute as private or public. Step 302: Determine whether the predicted result of the privacy attribute is public. If so, proceed to step 303; otherwise, the predicted result is private. Continue to remove the second object node and re-infer the privacy attribute. Continue in this way until the GGNN prediction result is public. Step 303: All object nodes removed during the pruning process are all private objects in the image, thereby determining the locations of all private areas in the image. Step 4: Calculate the total loss function of the to-be-forgotten model M based on the privacy attribute; If the privacy attribute prediction result of the image sample is public, its privacy risk loss is 0, then the binary cross entropy performance loss is That is the total loss; θ is the parameter of the model to be forgotten M, x (n) is the image sample input by the user; y (n) Assign business attributes to image samples for users; If the privacy attribute prediction result of the image sample is private, the total loss is the sum of performance loss and privacy risk loss. The calculation formula is: loss over =λloss perform +(1-λ)loss privacy +r||θ|| 2 Among them, loss over is the overall loss, loss perform is the performance loss, loss privacy is the privacy risk loss, the privacy risk coefficient λ∈[0,1), and r is the regularization coefficient; Step 5: Use batch gradient descent to continuously update the parameters θ of the to-be-forgotten model M until the total loss reaches a minimum, and obtain the optimal parameters θ of the to-be-forgotten model M u The data is returned to the user, enabling the automatic location of privacy areas of various objects in the input image.
2. The image privacy data forgetting method driven by a graph attention mechanism as claimed in claim 1, characterized in that: The structured image features of the image sample in step 1 include the following three types: 1) Use the ResNet101 residual neural network model to extract full-image pixel features; 2) Using the YOLOv8 object detection model to scan 81 common objects that may exist in the image, the object category features are obtained; 3) The original image is cropped according to the location of the object area to obtain the corresponding object pixel data, which is input into the VGG16 convolutional neural network model to extract the object area pixel features.
3. The image privacy data forgetting method driven by a graph attention mechanism as claimed in claim 1, characterized in that: The calculation of the attention coefficient in step 2 is specifically as follows: The hidden layer states of attribute nodes and object nodes are represented as: and For attribute node c i and object node o j , first use the low-rank bilinear pooling method to fuse its hidden states: Among them U a and V a is the parameter matrix to be learned; Then, the attention coefficient is calculated using the fused hidden state: e ij =that(h ij ) a ij =σ(e ij ) Where att(·) is the attention calculation function, e ij Represents the object node o j For attribute node c i The influence weight of is normalized to (0,1) to form the attention coefficient α ij , when a certain type of object has never appeared in the entire image privacy dataset, its attention coefficient α ij Take it as 0.
4. The image privacy data forgetting method driven by a graph attention mechanism as claimed in claim 1, characterized in that: In step 301, the node feature matrix is input into the gated graph neural network (GGNN). The gated recurrent unit (GRU) in the GGNN continuously updates the node hidden layer state based on historical information, and ultimately learns the optimal feature encoding for each node in the node feature matrix. After flattening, the matrix is subjected to dimensionality reduction through a fully connected neural network. An attention mechanism is added before the fully connected layer of the GGNN to authenticate the object node based on its contribution to the prediction result. The node features are then passed through a binary classifier to output the privacy attribute prediction result of the original image, which is either private or public.