A method, apparatus and device for image data de-sensitization
By performing RAW domain processing and model detection on image data, combined with dynamic ROI and privacy-grading models, pixel-level privacy protection is achieved, solving the problem that image data is easily recovered maliciously in traditional methods, and ensuring security and integrity.
Patent Information
- Application Number
- CN202511261483.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Traditional methods for desensitizing image and video data for privacy purposes are performed at the ISP output or after video encoding, which makes them susceptible to malicious recovery and cannot maximize the security of image data.
By acquiring RAW domain images, performing wide dynamic range processing, Bayer noise reduction, and tone mapping, and combining dynamic ROI detection models and privacy classification models, pixel-level privacy processing is achieved, including desensitization techniques such as mild blurring, pixelation, and undecryptable mosaic overlay.
It achieves end-to-end security and privacy protection, prevents image data from being maliciously recovered in the RAW domain, and ensures the security and integrity of privacy information.
Smart Images

Figure CN120751073B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of image processing, and in particular to a method, device and equipment for image data desensitization. BACKGROUND
[0002] With the popularity of video monitoring, intelligent security and mobile devices, personal privacy information involved in image and video data such as face, license plate, ID card information needs to be protected. Traditional privacy desensitization such as blur, mosaic, color block covering usually adopts manual detection post-processing, that is, after ISP (Image Signal Processor) output RGB image or video encoding, sensitive information is detected and desensitized by workers or algorithms.
[0003] Moreover, the traditional method usually desensitizes at the ISP output end (RGB domain) or after video encoding, and the original image before that can still be stored or transmitted, which is easy to be maliciously restored.
[0004] Therefore, how to desensitize in a way that can maximize the protection of images from being maliciously restored is a technical problem to be solved. SUMMARY
[0005] In view of the above problems, the present application provides a method, device and equipment for image data desensitization which overcomes the above problems or at least partially solves the above problems.
[0006] In a first aspect, the present application provides a method for image data desensitization, comprising:
[0007] obtaining a RAW domain image of a to-be-processed image or a to-be-processed video stream;
[0008] sequentially performing wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image to obtain a first processed image;
[0009] obtaining a dynamic ROI detection model and a privacy classification model;
[0010] outputting a second processed image based on the first processed image and the dynamic ROI detection model, the second processed image being a privacy area labeled on the first processed image;
[0011] obtaining a privacy level comprehensive score of each privacy area based on the second processed image and the privacy classification model;
[0012] determining a corresponding desensitization means based on the privacy level comprehensive score of each privacy area to perform pixel-level privacy processing.
[0013] Preferably, after obtaining the RAW domain image of the to-be-processed image or the to-be-processed video stream, the method further comprises:
[0014] performing ISP preprocessing on the RAW domain image to obtain a preprocessed image.
[0015] Preferably, after performing wide dynamic range processing on the RAW domain image, the method further comprises:
[0016] marking a motion blur region.
[0017] Preferably, the dynamic ROI detection model is obtained by:
[0018] obtaining a first historical RAW domain image marked with a historical privacy region and a second historical RAW domain image marked with a motion blur region;
[0019] inputting the first historical RAW domain image and the second historical RAW domain image into a neural network model for training to obtain a dynamic ROI detection model for marking a privacy region and a motion blur region.
[0020] Preferably, the dynamic ROI detection model is obtained by:
[0021] adjusting parameters of the dynamic ROI detection model so that a motion blur region that cannot be recognized by a human eye is skipped in subsequent processing.
[0022] Preferably, based on the second processed image and the privacy grading model, a comprehensive score of a privacy level of each privacy region is obtained, comprising:
[0023] after performing wide dynamic range processing on the RAW domain image, the method further comprises:
[0024] performing second Bayer noise processing to obtain a third processed image, wherein the second Bayer noise processing has a lower accuracy than the first Bayer noise processing.
[0025] mapping the privacy region marked in the second processed image to the third processed image to obtain a fourth processed image.
[0026] inputting the fourth processed image into a privacy grading model to obtain a comprehensive score of a privacy level of each privacy region.
[0027] Preferably, based on the comprehensive score of the privacy level of each privacy region, a corresponding desensitization means is determined for pixel-level privacy processing, comprising:
[0028] based on the comprehensive score of the privacy level of each privacy region, a corresponding privacy level is determined;
[0029] based on the privacy level, a corresponding desensitization means is determined;
[0030] Based on the corresponding desensitization means, the second processing image is subjected to pixel-level privacy processing.
[0031] Preferably, the desensitization means comprises:
[0032] Light blur, pixelization, non-decipherable mosaic covering and decipherable mosaic covering of the privacy area.
[0033] In a second aspect, the present application further provides a device for image data desensitization, comprising:
[0034] A first acquisition module is configured to acquire a RAW domain image of a to-be-processed image or a to-be-processed video stream;
[0035] An image processing module is configured to sequentially perform wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image to obtain a first processing image;
[0036] A second acquisition module is configured to acquire a dynamic ROI detection model and a privacy grading model;
[0037] A labeling module is configured to output a second processing image based on the first processing image and the dynamic ROI detection model, the second processing image being a privacy area labeled on the first processing image;
[0038] An obtaining module is configured to obtain a privacy level comprehensive score of each privacy area based on the second processing image and the privacy grading model;
[0039] A desensitization processing module is configured to determine a corresponding desensitization means based on the privacy level comprehensive score of each privacy area to perform pixel-level privacy processing.
[0040] In a third aspect, the present application further provides a computer device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to realize the method in the first aspect.
[0041] In a fourth aspect, the present application further provides a computer readable storage medium, which stores a computer program executable by a processor to realize the method in the first aspect.
[0042] One or more technical solutions in the embodiments of the present application have at least the following technical effects or advantages:
[0043] The application provides a method for image data desensitization, comprising: acquiring a RAW domain image of a to-be-processed image or a to-be-processed video stream; sequentially performing wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image to obtain a first processed image; acquiring a dynamic ROI detection model and a privacy classification model; based on the first processed image and the dynamic ROI detection model, outputting a second processed image, the second processed image being a first processed image on which a privacy area is labeled; based on the second processed image and the privacy classification model, obtaining a privacy level comprehensive score of each privacy area; based on the privacy level comprehensive score of each privacy area, determining a corresponding desensitization means to perform pixel-level privacy processing on the second processed image, and through processing of the RAW domain image of the video or the image, end-to-end security privacy protection is realized. BRIEF DESCRIPTION OF DRAWINGS
[0044] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are included to provide a description of the preferred embodiments and are not intended to limit the scope of the application. Moreover, the same reference numerals in different drawings represent the same or similar elements. In the drawings:
[0045] Figure 1 A step flow diagram of the method for image data desensitization in the embodiment of the application is shown;
[0046] Figure 2 A structure diagram of the device for image data desensitization in the embodiment of the application is shown;
[0047] Figure 3 A structure diagram of the computer device for implementing the method for image data desensitization in the embodiment of the application is shown. DETAILED DESCRIPTION
[0048] Exemplary embodiments of the present application will be described herein below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that the present application can be more thoroughly understood and so that the scope of the present application can be accurately conveyed to those skilled in the art.
[0049] Embodiment one:
[0050] The embodiment of the present application provides a method for image data desensitization, as shown in the figure, comprising: Figure 1
[0051] S101, acquiring a RAW domain image of a to-be-processed image or a to-be-processed video stream;
[0052] S102, sequentially performing wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image to obtain a first processed image;
[0053] S103, obtaining a dynamic ROI detection model and a privacy classification model;
[0054] S104, based on the first processed image and the dynamic ROI detection model, outputting a second processed image, the second processed image being a privacy region labeled on the first processed image;
[0055] S105, based on the second processed image and the privacy classification model, obtaining a privacy level comprehensive score of each privacy region;
[0056] S106, based on the privacy level comprehensive score of each privacy region, determining a corresponding desensitization means for pixel-level privacy processing.
[0057] The overall idea of the scheme is to extract a RAW domain image from a to-be-processed image or a to-be-processed video stream, sequentially perform wide dynamic range processing (WDR), first Bayer noise processing and tone mapping processing (Tone Mapping), and then perform dynamic ROI detection model, privacy classification model and pixel-level RAW domain desensitization processing, thereby realizing end-to-end privacy protection and making the original data not leave the device.
[0058] In a specific implementation, S101, a RAW domain image of a to-be-processed image or a to-be-processed video stream is obtained. Specifically, the RAW domain image of the image or the video is specifically the original photoelectric signal captured by the sensor after preliminary processing without deep processing, which is the starting point of the data life cycle and retains the original state when the data is generated, which may contain noise, redundancy, errors or unstructured information.
[0059] After obtaining the RAW domain image, S102 is performed to sequentially perform wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image to obtain a first processed image;
[0060] Before this series of processing, it also includes:
[0061] The RAW domain image is preprocessed by ISP to obtain a preprocessed image. The ISP preprocessing includes black level correction (BLC): eliminating sensor dark current noise, ensuring signal linearity consistency by calibrating offset; lens shadow correction (LSC): compensating for edge brightness attenuation and color deviation caused by lens optical characteristics; bad pixel correction (BPC): detecting and repairing sensor bad pixels or abnormal pixels to avoid fixed noise points in the image. Of course, other processing procedures are not described one by one here.
[0062] Next, S102 is performed, and first, a pre-processed RAW domain image is subjected to wide dynamic range processing (WDR), specifically, a wide dynamic range image is generated by synthesizing multiple frames of dynamic range images (LDR), so that a clear and realistic image can be captured under complex lighting conditions such as strong light sources and backlight, backlight, etc., and the image will not be darkened or damaged due to shadows, glare, reflections and sunlight.
[0063] Next, first Bayer noise processing is performed. Since the RAW domain is mainly Poisson noise and Gaussian noise, the noise pattern is clear and is not affected by other modules in the back end. By setting the RAW domain noise reduction intensity to the maximum, the noise reduction is cleaner, and it is not a problem to lose details.
[0064] Next, tone mapping processing (Tone Mapping) is performed. Specifically, a lightweight Tone Mapping is used to adaptively map the dynamic range of the RAW domain image after noise reduction to a more balanced and more suitable detection distribution, thereby obtaining a first processed image. Tone mapping processing specifically compresses a high dynamic range (HDR) image to a low dynamic range (LDR) device displayable range while preserving details.
[0065] Next, S103 is performed, and a dynamic ROI detection model and a privacy grading model are obtained.
[0066] The dynamic ROI detection model is specifically used to mark the privacy area and the motion blur area of the processed RAW domain image.
[0067] Specifically, a first historical RAW domain image marked with a historical privacy area and a second historical RAW domain image marked with a motion blur area are obtained; the first historical RAW domain image and the second historical RAW domain image are input into a neural network model for training, to obtain a dynamic ROI detection model for marking the privacy area and the motion blur area.
[0068] The dynamic ROI detection model resists the influence of motion blur on dynamic ROI detection accuracy, and fuses a motion blur mark (motion mask). With the image information of the short exposure bright area and the long exposure dark area in the multi-exposure frame output by the wide dynamic range (WDR) processing, a motion blur mark (motion mask) is generated by optical flow estimation or traditional inter-frame difference method, thereby marking the motion blur area.
[0069] When training the dynamic ROI detection model, the motion blur mark (motion mask) is used as an attention weight to force the dynamic ROI detection model to pay attention to the static low motion blur area, and the detection weight of the motion area is reduced. As an attention weight, the dynamic ROI detection model is forced to pay attention to the static low motion blur area, and the detection weight of the motion area is reduced, so that a motion mark weighting is introduced in the loss function:
[0070] wherein, is a motion-aware loss. is a standard loss, is a weighting coefficient for balancing the weight between the motion-aware loss and the standard loss, is a predicted value, is a true value, The value of identifies the motion intensity of different regions, and a low value of motion intensity represents a high motion region, such as a fast-moving object or a blurred part, and a high value of motion intensity represents a static or low motion region, such as a clear and stable region.
[0071] In order to alleviate the motion blur problem, motion blur enhancement data is added in the training process of the dynamic ROI detection model to improve the scene adaptability of the model at a low cost. Motion blur samples simulating camera shaking and fast object movement are added to prompt the model to adapt to motion blur images. The motion blur region is labeled using the motion_mask information.
[0072] By adjusting the parameters of the dynamic ROI detection model, the motion blur region that cannot be recognized by the human eye is skipped for subsequent processing to avoid invalid processing.
[0073] Second, the confidence of the private region output by the dynamic ROI detection model on the first processed image is calculated. For example, the face, license plate, and other private regions on the first processed image are weighted and scored according to the size and number of these private regions, and the score is recorded as obj_score.
[0074] For the privacy classification model, it is also obtained by model training, and is pre-classified into 5 levels according to the image scene privacy level from low to high:
[0075] L1 level public open scene, such as basically no one / car natural scenery.
[0076] L2 level semi-public scene, such as parks, shopping malls, etc.
[0077] L3 level sensitive public scene, such as public transportation, schools, hospitals, etc.
[0078] L4 level high privacy scene, such as changing room, home, etc.
[0079] L5 level secret scene, such as the area where secret targets appear, etc.
[0080] By using a large amount of sample data, the model is trained to obtain a privacy classification model that can identify the privacy level of the image scene.
[0081] Next, S104 is performed, and a second processed image is output based on the first processed image and the dynamic ROI detection model. The second processed image is an image in which a privacy area is labeled on the first processed image.
[0082] Specifically, the first processed image is input into the dynamic ROI detection model, so that the privacy areas in the first processed image can be identified and determined, that is, a second processed image in which the privacy areas are labeled, and each privacy area is labeled with a confidence score obj_score.
[0083] Next, S105 is performed, and a privacy level comprehensive score of each privacy area is obtained based on the second processed image and the privacy classification model.
[0084] Specifically, after the RAW domain image is processed in a wide dynamic range, a second Bayer noise processing is further performed to obtain a third processed image, and the second Bayer noise processing has a lower processing accuracy than the first Bayer processing.
[0085] The privacy areas labeled in the second processed image are mapped to the third processed image to obtain a fourth processed image.
[0086] The fourth processed image is input into the privacy classification model to obtain a privacy level comprehensive score of each privacy area.
[0087] The processing accuracy of the second Bayer noise processing is lower than that of the first Bayer noise processing, so as to ensure that the third processed image retains more information for subsequent processing.
[0088] Since the privacy areas are labeled in the second processed image, but not in the third processed image, however, the third processed image contains more information that is not filtered out by the second Bayer noise processing. Therefore, the labeled privacy areas in the second processed image are mapped to the third processed image to obtain a fourth processed image. The fourth processed image not only contains more information that is not filtered out by the second Bayer noise processing, but also contains labeled privacy areas.
[0089] Next, the fourth processed image is input into the privacy classification model, and thus a privacy level comprehensive score of each privacy area is obtained.
[0090] Specifically, a 5-dimensional probability vector scene_probs=[P1, P2, P3, P4, P5] is output, each type of scene privacy level is assigned a probability weight, and the higher the privacy level, the greater the weight. The weighted score is scene_score.
[0091] By combining the obj_score output by the dynamic ROI detection model, the scene pre-classification is corrected, for example, pre-classified as a public open scene, but a person or a car appears, and the scene is corrected as a semi-public scene. The privacy level comprehensive score combined_score is obtained by weighting, and the score is finally mapped to the scene privacy level L1~L5 level.
[0092] combined_score = scene_score * alpha1 + obj_score * alpha2
[0093] Wherein, alpha1 and alpha2 are adjusted according to user's will.
[0094] The higher the privacy level comprehensive score is, the greater the desensitization strength will be.
[0095] Finally, S106 is executed, and the corresponding desensitization means is determined based on the privacy level comprehensive score of each privacy area, and pixel-level privacy processing is performed.
[0096] Specifically, the privacy level of each privacy area is determined based on the privacy level comprehensive score of each privacy area.
[0097] Based on the privacy level, the corresponding desensitization means is determined;
[0098] Based on the corresponding desensitization means, the second processing image is subjected to pixel-level privacy processing.
[0099] In a specific embodiment, the privacy level comprehensive score of the fourth processing image is obtained, and different desensitization processing methods are adopted according to the privacy level comprehensive score. The desensitization means includes: light blur, pixelization, non-decipherable mosaic covering and decipherable mosaic covering of the privacy area. The desensitization means corresponding to different privacy levels will be introduced as follows:
[0100] First of all, these desensitization means are based on the processing of Bayer array characteristics, which avoids color distortion caused by post-mosaic processing.
[0101] Specifically, L1 level: no desensitization, suitable for public open scene, using original data (RAW domain image), retaining complete Bayer array, outputting original image without processing.
[0102] L2 level: light desensitization, using semi-public scene, using channel-specific Gaussian blur, using 5x5 Gaussian kernel for channel-specific, preserving color consistency after blurring, non-reversible recovery, overall light blur, and the privacy area outline obtained by identification is visible but the real content is indistinguishable.
[0103] L3: moderate desensitization, suitable for sensitive public scenarios, using pixel ratio mean value, 4x4 Bayer block in the same channel, irreversible restoration, making the privacy area pixelated.
[0104] L4: moderate desensitization, suitable for high privacy scenarios, using dynamic mosaic and color block coverage, using 2x2 Bayer block mosaic for privacy areas such as faces / vehicle plates, superimposing black rectangular color blocks, irreversible restoration, privacy area mosaic plus color block coverage, background blur.
[0105] L5: complete shielding, suitable for classified scenarios, using AES encryption metadata marking for classified privacy areas, such as GPS coordinates or military restricted areas, etc., the original data can be restored through the key, and other areas are still covered with 2x2 Bayer irreversible mosaic.
[0106] Thus, image data desensitization is completed to avoid malicious restoration.
[0107] The one or more technical solutions in the embodiments of the present application have at least the following technical effects or advantages:
[0108] The present application provides a kind of image data desensitization method, comprising: obtaining the RAW domain image of image to be processed or video stream to be processed;First Bayer noise processing and tone mapping processing are sequentially carried out to RAW domain image, and first processing image is obtained;Dynamic ROI detection model and privacy classification model are obtained;Based on first processing image and dynamic ROI detection model, second processing image is output, and second processing image is labeled privacy area on first processing image;Based on second processing image and privacy classification model, the privacy level comprehensive score of each privacy area is obtained;Based on the privacy level comprehensive score of each privacy area, corresponding desensitization means is determined to carry out pixel-level privacy processing to second processing image, by processing the RAW domain image of video or image, end-to-end security privacy protection is realized.
[0109] Embodiment two:
[0110] Based on the same inventive concept, the present application also provides an image data desensitization device, as shown in Figure 2 , comprising:
[0111] The first acquisition module 201 is used for acquiring the RAW domain image of image to be processed or video stream to be processed;
[0112] The image processing module 202 is used for sequentially carrying out wide dynamic range processing, first Bayer noise processing and tone mapping processing to the RAW domain image, and obtaining first processing image;
[0113] The second acquisition module 203 is configured to acquire a dynamic ROI detection model and a privacy classification model.
[0114] The labeling module 204 is configured to output a second processing image based on the first processing image and the dynamic ROI detection model, the second processing image being a privacy region labeled on the first processing image.
[0115] The obtaining module 205 is configured to obtain a comprehensive privacy level score of each privacy region based on the second processing image and the privacy classification model.
[0116] The desensitization processing module 206 is configured to determine a corresponding desensitization method based on the comprehensive privacy level score of each privacy region, so as to perform pixel-level privacy processing.
[0117] In an optional implementation, the method further includes a preprocessing module configured to:
[0118] After acquiring the RAW domain image of the to-be-processed image or to-be-processed video stream, performing ISP preprocessing on the RAW domain image to obtain a preprocessed image.
[0119] In an optional implementation, the method further includes a marking module configured to:
[0120] After performing wide dynamic range processing on the RAW domain image, marking a motion blur region.
[0121] In an optional implementation, the second acquisition module 203 is configured to:
[0122] acquire a first historical RAW domain image marked with a historical privacy region and a second historical RAW domain image marked with a motion blur region;
[0123] input the first historical RAW domain image and the second historical RAW domain image into a neural network model to train the dynamic ROI detection model for marking a privacy region and a motion blur region.
[0124] In an optional implementation, the second acquisition module 203 is configured to:
[0125] adjust parameters of the dynamic ROI detection model, so that a motion blur region that cannot be recognized by a human eye is skipped from subsequent processing.
[0126] In an optional implementation, the obtaining module 205 is configured to:
[0127] After performing wide dynamic range processing on the RAW domain image, the method further includes:
[0128] The second Bayer noise processing is used to obtain a third processing image, and the second Bayer noise processing has a lower precision than the first Bayer noise processing.
[0129] The privacy area marked in the second processing image is mapped to the third processing image to obtain a fourth processing image.
[0130] The fourth processing image is input into the privacy grading model to obtain a comprehensive score of the privacy level of each privacy area.
[0131] In an optional embodiment, the desensitization processing module 206 is configured to:
[0132] Based on the comprehensive score of the privacy level of each privacy area, a corresponding privacy level is determined.
[0133] Based on the privacy level, a corresponding desensitization means is determined.
[0134] Based on the corresponding desensitization means, pixel-level privacy processing is performed on the second processing image.
[0135] In an optional embodiment, the desensitization means includes:
[0136] Light blurring, pixelization, non-decipherable mosaic covering, and decipherable mosaic covering of the privacy area.
[0137] Embodiment Three
[0138] Based on the same inventive concept, the embodiments of the present application provide a computer device, as shown in Figure 3 The computer device includes a memory 304, a processor 302, and a computer program stored in the memory 304 and executable on the processor 302, and the processor 302 implements the steps of the image data desensitization method when executing the program.
[0139] In the above embodiments, the image data desensitization method is applied to the image data of a single image. Figure 3In this particularized embodiment, a bus architecture (represented by bus 300) can include any number of interconnected buses and bridges, the bus 300 linking together various circuits including the processor(s) represented by processor 302, and the memory represented by memory 304. The bus 300 can also link various other circuits such as peripheral devices, voltage stabilizers and power management circuits, which are well known in the art, and therefore, will not be further described herein. Bus interface 306 provides an interface between the bus 300 and the receiver 301 and transmitter 303. The receiver 301 and transmitter 303 can be the same device, i.e., a transceiver, providing a means for communicating with various other apparatus over a transmission medium. The processor 302 is responsible for managing the bus 300 and general processing, while the memory 304 can be used for storing data used by the processor 302 in executing operational processes.
[0140] Embodiment Four
[0141] Based on the same inventive concept, the embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to realize the steps of the image data desensitization method.
[0142] The algorithms and displays presented herein are not inherently related to any particular computer, virtual system, or other apparatus. Various general purpose systems can be used with these teachings, with or without accompanying specific hardware. The required structure for a variety of these systems will be apparent from the description above. In addition, the present application is not described with reference to any particular programming language. It will be appreciated that a variety of programming languages can be used to implement the teachings of the application as described herein, and any references above to specific languages are provided for disclosure of enablement of the best mode of the application.
[0143] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order not to obscure the understanding of this description.
[0144] Similarly, it is to be understood that the embodiments of the present application can alternately be phrased or described substantially similarly to what is found in the description of the application set forth above. For example, the steps of any of the methods recited herein, or variations and / or combinations thereof, are optionally implementable by one or more computer programs or program modules. These program modules can include, but are not limited to, applications, program tasks, programs, components, or processes, which perform the functions described herein. It is therefore contemplated to select from the present description a feature or combination of features to implement an embodiment of the application in accordance with the claims. Moreover, while embodiments of the present application have been described above, it is understood that they have been presented by way of example only, and not limitation. Numerous changes to the disclosed embodiments can be made in accordance with the disclosure herein without departing from the spirit or scope of the application. Thus, the breadth and scope of the present application should not be limited by any of the above described embodiments, but should be defined in accordance with the following claims and their equivalents.
[0145] Those skilled in the art will appreciate that the modules in the apparatuses in the embodiments can be adapted and placed in one or more apparatuses other than the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and further can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, all combinations of all features disclosed in the specification (including the accompanying claims, abstract and drawings), and all processes or units of any methods or apparatuses so disclosed can be adopted in any combination. Except explicitly stated otherwise, each feature disclosed in the specification (including the accompanying claims, abstract and drawings) can be replaced by alternative features providing the same, equivalent or similar function.
[0146] Further, those skilled in the art will appreciate that a combination of features of different embodiments means that such combination is within the scope of the application and forms a different embodiment. For example, in the DETAILED DESCRIPTION, any one of the claimed embodiments can be used in any combination.
[0147] The various component embodiments of the present application can be implemented in hardware, or as software modules running in one or more processors, or in combinations thereof. As will be appreciated by one skilled in the art, microprocessors or digital signal processors (DSPs) can be used to implement some or all of the functions of some or all of the components of the image data de-sensitizing apparatus and computer device according to the embodiments of the present application in practice. The present application can also be implemented as a program for executing, in whole or in part, the methods described herein, such as a computer program and a computer program product. Such a program implementing the present application can be stored on a computer readable medium or can be in the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or in any other form.
[0148] It should be noted that the above-mentioned embodiments illustrate rather than limit the application, and that one skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps other than those listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In a unit claim, several devices can be listed with a conjunction like 'or', but it is to be understood that each of these devices can be implemented by its own hardware item. The use of the words 'first','second', and 'third', etc. do not imply any order. These words are to be interpreted as names.
Claims
1. A method of image data de-sensitization, the method comprising: The method comprises the following steps: obtaining a RAW domain image of a to-be-processed image or a to-be-processed video stream; performing wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image in sequence to obtain a first processed image; obtaining a dynamic ROI detection model and a privacy grading model; outputting a second processed image based on the first processed image and the dynamic ROI detection model, wherein the second processed image is a privacy region marked on the first processed image; obtaining a comprehensive score of a privacy level of each privacy region based on the second processed image and the privacy grading model, comprising: after the wide dynamic range processing on the RAW domain image, further comprising: adopting second Bayer noise processing to obtain a third processed image, wherein the second Bayer noise processing has a lower accuracy than the first Bayer noise processing; mapping the privacy region marked in the second processed image to the third processed image to obtain a fourth processed image; inputting the fourth processed image into the privacy grading model to obtain the comprehensive score of the privacy level of each privacy region; determining a corresponding desensitization means based on the comprehensive score of the privacy level of each privacy region to perform pixel-level privacy processing.
2. The method of claim 1, wherein, after obtaining the RAW domain image of the to-be-processed image or the to-be-processed video stream, further comprising: performing ISP preprocessing on the RAW domain image to obtain a preprocessed image.
3. The method of claim 1, wherein, after the wide dynamic range processing on the RAW domain image, further comprising: marking a motion blur region.
4. The method of claim 3, wherein, obtaining a dynamic ROI detection model, comprising: obtaining a first historical RAW domain image marked with a historical privacy region and a second historical RAW domain image marked with a motion blur region; inputting the first historical RAW domain image and the second historical RAW domain image into a neural network model for training to obtain a dynamic ROI detection model for marking a privacy region and a motion blur region.
5. The method of claim 4, wherein, obtaining a dynamic ROI detection model, further comprising: adjusting parameters of the dynamic ROI detection model so that a motion blur region that cannot be recognized by human eyes is skipped in subsequent processing.
6. The method of claim 1, wherein, The desensitization means comprises: slight blurring, pixelization, non-decryptable mosaic covering and decryptable mosaic covering of the privacy region.
7. An apparatus for image data de-sensitization, the apparatus comprising: The method comprises the following steps: a first obtaining module is configured to obtain a RAW domain image of a to-be-processed image or a to-be-processed video stream; an image processing module is configured to perform wide dynamic range processing, first Bayer noise processing and tone mapping processing on the RAW domain image in sequence to obtain a first processed image; a second obtaining module is configured to obtain a dynamic ROI detection model and a privacy grading model; a marking module is configured to output a second processed image based on the first processed image and the dynamic ROI detection model, wherein the second processed image is a privacy region marked on the first processed image; a obtaining module is configured to obtain a comprehensive score of a privacy level of each privacy region based on the second processed image and the privacy grading model, and the obtaining module is configured to: after the wide dynamic range processing on the RAW domain image, further comprising: adopting second Bayer noise processing to obtain a third processed image, wherein the second Bayer noise processing has a lower accuracy than the first Bayer noise processing; mapping the privacy area marked in the second processing image to the third processing image to obtain a fourth processing image; inputting the fourth processing image into the privacy grading model to obtain a privacy level comprehensive score of each privacy area; the desensitization processing module is configured to determine a corresponding desensitization means based on the privacy level comprehensive score of each privacy area to perform pixel-level privacy processing.
8. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the method according to any one of claims 1-6 when executing the program.
Citation Information
Patent Citations
Data desensitization processing method and device
CN113918990A
Live video processing method, device and equipment
CN114428971A
Image privacy protection processing method and system
CN115906173A