Enabling training of an ML model to monitor an individual

DE602022016860T2Active Publication Date: 2025-07-02ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602022016860
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-01-26
Filing Date
2022-01-25
Publication Date
2025-07-02
Estimated Expiration
2042-01-25

AI Technical Summary

Technical Problem

Existing video surveillance technologies for monitoring individuals face challenges in balancing privacy concerns with the need for training data, as manual processing of video data for machine learning models raises privacy issues.

Method used

A method and system for dynamically selecting levels of anonymization in training data feeds, including blurring faces, replacing them with computer-generated images, or using similar-gender faces, to create processed data feeds for training ML models while maintaining privacy.

Benefits of technology

Achieves a balance between privacy preservation and effective training by adjusting anonymization levels based on feedback, ensuring sufficient detail for model training without excessive exposure of personal information.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of enabling training of a machine learning (ML) model, for monitoring a person and in particular to providing a data feed for training, where the level of anonymisation is dynamically selected.BACKGROUND

[0002] New technology opens up new opportunities. For instance, the evolution of digital cameras and communication technologies enable monitoring of people to be provided using video surveillance at relatively low cost. This can be particularly useful for elderly people or disabled people, who in this way can enjoy greatly improved quality of life by living in their own home instead of being in a staffed care facility. Video data can also be used e.g. for people counting.

[0003] Video surveillance is certainly useful, but privacy issues arise. Hardly anyone enjoys being continuously monitored using video surveillance, for monitoring of when the person needs help.

[0004] One way to reduce the privacy concern is to, instead of manual monitoring, use machine learning (ML) models to determine the state of a monitored person. However, also the video-data based ML models need to be trained, which requires video data to be provided to the ML models. Such video data for training sometimes needs to be manually processed as part of the training process, which is a privacy concern for the person captured in the video data.

[0005] US 2017 / 289504 A1 discloses privacy supporting computer vision systems, methods, apparatuses and associated computer executable code. US 2020 / 205697 A1 discloses a video-based fall risk assessment system. US 2019 / 042851 A1 discloses protection and recovery of identities in surveillance camera environments. Senavirathne Navoda et al: published for IEEE 19th International conference on trust, security and privacy in computing and communications (Trustcom), IEEE, pages 664-675, DOI: 10.1109 / TRUSTCOM50675.2020.00093 an article entitled "On the Role of Data Anonymization in Machine Learning Privacy", discusses how data controllers may anonymize data before releasing them for any data analysis task such as machine learning. Wong Kok-Seng Wong Ks@Vinuni Edu Vn et al: published for THE 10th International conference on communication and network security, ACMPUB27, New York, NY, USA, 27 November 2020, pages 91-98 an article entitled "A Privacy-Preserving Framework for Surveillance Systems", is a paper proposing dynamic masking to ensure that an individual remains anonymous in a group.SUMMARY

[0006] One object is to provide an improved balance between privacy and training data requirements when providing training data based on a data feed capable of depicting people.

[0007] According to a first aspect, it is provided a method for enabling training of a machine learning, ML, model, for monitoring a person based on a data feed capable of depicting a person. The method is performed by a training data provider comprising a processor; and a memory storing instructions to be executed by the processor. The method comprises: obtaining a data feed capable of depicting the person; selecting a level of anonymisation, from a plurality of levels of anonymisation; anonymising the data feed according to the selected level of anonymisation, resulting in a processed data feed; transmitting the processed data feed as training data for training a central ML model in a central node; receiving an indication to increase or reduce the level of anonymisation from the central node. The method is repeated, wherein the next iteration of the selecting is based on the indication to increase or reduce the level of anonymisation.

[0008] The levels of anonymisation may include in, in order of increasing anonymisation: blurring of face, replacing face with a computer-generated face image, replacing face with a picture of someone else's face, blurring of entire body.

[0009] The anonymising may comprise selecting another face of the same gender as the person in the data feed.

[0010] The method may further comprise: determining a label associated with the data feed; and including the label in association with the processed data feed.

[0011] The label may indicate a near-fall event of the person.

[0012] The determining a label may be based on an inferred result by a local ML model, the local ML model being provided at the same site as the training data provider.

[0013] According to a second aspect, it is provided a training data provider for enabling training of a machine learning, ML, model, for monitoring a person based on a data feed capable of depicting a person. The training data provider comprises: a processor; and a memory storing instructions that, when executed by the processor, cause the training data provider to: obtain a data feed capable of depicting the person; select a level of anonymisation, from a plurality of levels of anonymisation; anonymise the data feed according to the selected level of anonymisation, resulting in a processed data feed; transmit the processed data feed as training data for training a central ML model in a central node; and receive an indication to increase or reduce the level of anonymisation from the central node; in which case said instructions are repeated, wherein the next iteration of the instructions to selecting is based on the indication to increase or reduce the level of anonymisation.

[0014] The levels of anonymisation may include in, in order of increasing anonymisation: blurring of face, replacing face with a computer-generated face image, replacing face with a picture of someone else's face, blurring of entire body.

[0015] The instructions to anonymise may comprise instructions that, when executed by the processor, cause the training data provider to select another face of the same gender as the person in the data feed.

[0016] The training data provider may further comprise instructions that, when executed by the processor, cause the training data provider to: determine a label associated with the data feed; and include the label in association with the processed data feed.

[0017] The label may indicate a near-fall event of the person.

[0018] The instructions to determine may comprise instructions that, when executed by the processor, cause the training data provider to determine the label is based on an inferred result by a local ML model, the local ML model being provided at the same site as the training data provider.

[0019] According to a third aspect, it is provided a computer program for enabling training of a machine learning, ML, model, for monitoring a person based on a data feed capable of depicting a person. The computer program comprises computer program code which, when executed on a training data provider causes the training data provider to: obtain a data feed capable of depicting the person; select a level of anonymisation, from a plurality levels of anonymisation; anonymise the data feed according to the selected level of anonymisation, resulting in a processed data feed; transmit the processed data feed as training data for training a central ML model in a central node; and receive an indication to increase or reduce the level of anonymisation from the central node; and repeat said computer program code, wherein the next iteration of the computer program code to select is based on the indication to increase or reduce the level of anonymisation.

[0020] According to a fourth aspect, it is provided a computer program product comprising a computer program according to the third aspect and a computer readable means on which the computer program is stored.

[0021] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Aspects and embodiments are now described, by way of example, with reference to the accompanying drawings, in which: Fig 1 is a schematic diagram illustrating an environment in which embodiments presented herein can be applied; Fig 2 is a flow chart illustrating embodiments of methods for enabling training of an ML model for monitoring a person based on a data feed capable of depicting a person; Fig 3 is a schematic diagram illustrating components of the training data provider of Fig 1; and Fig 4 shows one example of a computer program product comprising computer readable means. DETAILED DESCRIPTION

[0023] The aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of invention to those skilled in the art. Like numbers refer to like elements throughout the description.

[0024] Embodiments presented herein provide an improved way of anonymising a data feed for use as training data for an ML model. Specifically, one of a plurality levels of anonymisation is selected. In this way, the amount anonymisation can be tailored to the specific purpose, such that the anonymisation is not excessive to prevent training, while the anonymisation is as aggressive as possible to improve privacy of the person being depicted in the data feed.

[0025] Fig 1 is a schematic diagram illustrating an environment in which embodiments presented herein can be applied. A person 5 to be monitored is at least part of the time present in a physical space 14. The physical space 14 can e.g. be a room, a flat, a house, an office etc. A monitoring device 2 is configured to monitor the person 5 based on a sensor device 3 forming part of the monitoring device 2 or locally connected to the monitoring device 2. The monitoring device 2 is also used for capturing data of the person 5 for purposes of training a local ML model 4 and a central ML model 9. The sensor device 3 provides a data feed capable of depicting the person 5, e.g. as a sequence of images (i.e. a video sequence). The sensor device 3 can be implemented as an infrared (IR) camera, a video camera, a lidar, a radar or any other suitable imaging technology. Additional sensor devices (not shown) can also be provided, providing respective data feeds. A training data provider 1 is used to provide training data for training the central ML model 9 as described in more detail below. The training data provider 1 can be provided as part of the monitoring device 2 or separately. In any case, the training data provider 1 is provided at the same site as the sensor device 3. In this way, sensitive data feeds from the sensor device 3 are anonymised by the training data provider 1 to prevent privacy-sensitive sections of the data feed having to be communicated remotely.

[0026] The monitoring device 2 comprises the local ML model 4. There may be one or more monitoring devices 2 working in parallel on the same or complementing scene. The monitoring device 2 can be connected to a network 6, which can be an Internet protocol (IP) based network. The network 6 can e.g. comprise any one or more of a local wireless network, a cellular network, a wired local area network, a wide area network (such as the Internet), etc. Optionally, a central node 7, containing the central ML model 9, is also connected to the network 6.

[0027] The local ML model 4 of the monitoring device 2 is used to predict current or future monitored states or events based on the data feed from the sensor device 3. Specifically, the local ML model 4 is used to infer a result of monitoring states or events of the person 5 that can be used as labels in the training data. Non-limiting examples of monitoring states or events, all relating to the person, are: absent, present, lying in bed, lying on floor, breathing, near-fall event, fall event, distress, etc.

[0028] Fig 2 is a flow chart illustrating embodiments of methods for enabling training of an ML model (e.g. the central ML model 9), for monitoring a person based on a data feed capable of depicting a person.

[0029] In an obtain data feed step 40, the training data provider 1 obtains a data feed capable of depicting the person. As explained above, the data feed can e.g. be based on data from one or more sensors such as infrared (IR) camera, a video camera, a lidar, a radar or any other suitable imaging technology. At this stage, the data feed has not been anonymised, and e.g. faces can potentially be seen in the data feed.

[0030] In a select level of anonymisation step 42, the training data provider 1 selects a level of anonymisation, from a plurality of levels of anonymisation. The levels of anonymisation can e.g. include in, in order of increasing anonymisation: blurring of face, replacing face with a computer-generated face image, replacing face with a picture of someone else's face, blurring of entire body.

[0031] In an anonymise step 44, the training data provider 1 anonymises the data feed according to the selected level of anonymisation, resulting in a processed data feed.

[0032] The anonymising can comprise, when a picture of someone else's face is used, selecting another face of the same gender as the person in the data feed. Alternatively or additionally, the face selection can be performed to achieve similar characteristics in terms as facial expression, which can be a valuable indicator to have in the training data. Alternatively or additionally, the face selection can be based on selecting another face of similar characteristics as the person in the data feed in terms of, hair colour, hair length, skin colour, etc.

[0033] Optionally, the original data feed (without anonymisation) is stored to allow training data with reduced anonymisation to be transmitted at a later stage if needed.

[0034] In an optional determine label step 45, the training data provider 1 determines a label associated with the data feed. For instance, the label can indicate something that occurs relatively rarely, such as a near-fall event of the person. This type of event can be anonymised in the training data and still be valuable, since the training can e.g. be based on the movement characteristics of the body of the person, and may be determined without great dependence on facial expressions. Since such events happen rarely, any way that makes it possible to provide large amounts of data, such as provided by embodiments presented herein, is greatly valuable.

[0035] The determining of the label can e.g. be based on an inferred result by a local ML model, where the local ML model is provided at the same site as the training data provider 1.

[0036] In an optional include label step 46, the training data provider 1 includes the label (from step 45) in association with the processed data feed.

[0037] In a transmit processed data step 47, the training data provider 1 transmits the processed (i.e. anonymised and optionally labelled) data feed, to be used as training data for training a central ML model in a central node.

[0038] In an optional, receive adjustment indication step 48, the training data provider 1 receives an indication to increase or reduce the level of anonymisation from the central node.

[0039] The method is then repeated, and when step 48 is performed, in the next iteration of step 42, the selecting is based on the indication to increase or reduce the level of anonymisation, i.e. implementing a feedback loop. In this way, the level of optimisation is dynamically adjusted in accordance with the need of the central node.

[0040] Using embodiments presented herein, the level of anonymisation can be adjusted to achieve a balance between the level of detail required in the training and the impact on privacy for the person depicted in the data feed. In other words, the amount of privacy sensitive data forming part of the training data is reduced compared to if the training data should be useable for all types of ML model training. On the other hand, the level of detail provided in the training data is improved in cases where this is needed for successful training.

[0041] For instance, people counting, detecting absence / presence of people, or detecting near-fall events do not need a great amount of privacy-sensitive data, such as face data.

[0042] Fig 3 is a schematic diagram illustrating components of the training data provider 1 of Fig 1. It is to be noted that, when the training data provider 1 is implemented in a host device such as the monitoring device 2, one or more of the mentioned components can be shared with the host device. A processor 60 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions 67 stored in a memory 64, which can thus be a computer program product. The processor 60 could alternatively be implemented using an application specific integrated circuit (ASIC), field programmable gate array (FPGA), etc. The processor 60 can be configured to execute the method described with reference to Fig 2 above.

[0043] The memory 64 can be any combination of random-access memory (RAM) and / or read-only memory (ROM). The memory 64 also comprises persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid-state memory or even remotely mounted memory.

[0044] A data memory 66 is also provided for reading and / or storing data during execution of software instructions in the processor 60. The data memory 66 can be any combination of RAM and / or ROM.

[0045] The training data provider 1 further comprises an I / O interface 62 for communicating with external and / or internal entities. For instance, the I / O interface 62 allows the training data provider 1 to communicate the network 6. Optionally, the I / O interface 62 also includes a user interface.

[0046] Other components of the training data provider 1 are omitted in order not to obscure the concepts presented herein.

[0047] Fig 4 shows one example of a computer program product 90 comprising computer readable means. On this computer readable means, a computer program 91 can be stored, which computer program can cause a processor to execute a method according to embodiments described herein. In this example, the computer program product is in the form of a removable solid-state memory, e.g. a Universal Serial Bus (USB) drive. As explained above, the computer program product could also be embodied in a memory of a device, such as the computer program product 64 of Fig 3. While the computer program 91 is here schematically shown as a section of the removable solid-state memory, the computer program can be stored in any way which is suitable for the computer program product, such as another type of removable solid-state memory, or an optical disc, such as a CD (compact disc), a DVD (digital versatile disc) or a Blu-Ray disc.

[0048] The aspects of the present disclosure have mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims. Thus, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope being defined by the following claims.

Claims

1. A method for enabling training of a machine learning, ML, model, for monitoring a person based on a data feed capable of depicting a person, the method being performed by a training data provider (1) comprising a processor (60); and a memory (64) storing instructions to be executed by the processor (60), the method comprising: obtaining (40) a data feed capable of depicting the person; selecting (42) a level of anonymisation, from a plurality of levels of anonymisation; anonymising (44) the data feed according to the selected level of anonymisation, resulting in a processed data feed; transmitting (47) the processed data feed as training data for training a central ML model in a central node; and receiving (48) an indication to increase or reduce the level of anonymisation from the central node; and wherein the method is repeated, wherein the next iteration of the selecting (42) is based on the indication to increase or reduce the level of anonymisation.

2. The method according to claim 1, wherein the levels of anonymisation include in, in order of increasing anonymisation: blurring of face, replacing face with a computer-generated face image, replacing face with a picture of someone else's face, blurring of entire body.

3. The method according to any one of the preceding claims, wherein the anonymising (44) comprises selecting another face of the same gender as the person in the data feed.

4. The method according to one of the preceding claims, further comprising: determining (45) a label associated with the data feed, the label identifying a monitoring state or an event inferred by the ML model; and including (46) the label in association with the processed data feed.

5. The method according to claim 4, wherein the label indicates a near-fall event of the person.

6. The method according to claim 4 or 5, wherein the determining (45) a label is based on an inferred result by a local ML model, the local ML model being provided at the same site as the training data provider (1).

7. A training data provider (1) for enabling training of a machine learning, ML, model, for monitoring a person based on a data feed capable of depicting a person, the training data provider (1) comprising: a processor (60); and a memory (64) storing instructions (67) that, when executed by the processor, cause the training data provider (1) to: obtain a data feed capable of depicting the person; select a level of anonymisation, from a plurality of levels of anonymisation; anonymise the data feed according to the selected level of anonymisation, resulting in a processed data feed; transmit the processed data feed as training data for training a central ML model in a central node: and receive an indication to increase or reduce the level of anonymisation from the central node; and repeat said instructions, wherein the next iteration of the instructions to select is based on the indication to increase or reduce the level of anonymisation.

8. The training data provider (1) according to claim 7, wherein the levels of anonymisation include in, in order of increasing anonymisation: blurring of face, replacing face with a computer-generated face image, replacing face with a picture of someone else's face, blurring of entire body.

9. The training data provider (1) according to any one of claims 7 to 8, wherein the instructions to anonymise comprise instructions (67) that, when executed by the processor, cause the training data provider (1) to select another face of the same gender as the person in the data feed.

10. The training data provider (1) according to one of claims 7 to 9, further comprising instructions (67) that, when executed by the processor, cause the training data provider (1) to: determine a label associated with the data feed; and include the label in association with the processed data feed.

11. The training data provider (1) according to claim 10, wherein the label indicates a near-fall event of the person.

12. The training data provider (1) according to claim 10 or 11, wherein the instructions to determine comprise instructions (67) that, when executed by the processor, cause the training data provider (1) to determine the label is based on an inferred result by a local ML model, the local ML model being provided at the same site as the training data provider (1).

13. A computer program (67, 91) for enabling training of a machine learning, ML, model, for monitoring a person based on a data feed capable of depicting a person, the computer program comprising computer program code which, when executed on a training data provider (1) causes the training data provider (1) to: obtain a data feed capable of depicting the person; select a level of anonymisation, from a plurality of levels of anonymisation; anonymise the data feed according to the selected level of anonymisation, resulting in a processed data feed; transmit the processed data feed as training data for training a central ML model in a central node; and receive an indication to increase or reduce the level of anonymisation from the central node; and repeat said computer program code, wherein the next iteration of the computer program code to select is based on the indication to increase or reduce the level of anonymisation.

14. A computer program product (64, 90) comprising a computer program according to claim 13 and a computer readable means on which the computer program is stored.