Method for anonymising an input image of an observation scene, anonymising arrangement, and application
By dividing images into cells and generating descriptors that exclude identification information, the method ensures reliable anonymization within cameras, maintaining functional image content and adhering to data protection standards.
Patent Information
- Application Number
- PCT/EP2025/050457
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2025-01-09
- Publication Date
- 2025-08-14
AI Technical Summary
Existing image anonymization methods, such as facial recognition followed by obscuring or low-resolution imaging, are either unreliable or impractical, and storing original images for post-processing poses data security risks.
Anonymization is achieved by dividing input images into non-overlapping cells, generating descriptors for each cell that exclude identification information, and reconstructing the image using these descriptors, ensuring data security through in-camera processing.
The method guarantees robust anonymization, compliant with data protection regulations, by maintaining application-relevant information while preventing identification of sensitive features like faces or license plates.
Smart Images

Figure EP2025050457_14082025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] title
[0003] Method for anonymizing an input image of an observation scene, anonymization arrangement and application
[0004] The invention relates to a method for anonymizing an input image of an observation scene. The invention also relates to an anonymization system and an application.
[0005] State of the art
[0006] Cameras are essential sensors for environmental perception in robotics, (automated) vehicles, and a variety of other applications. They are used for functions such as obstacle detection, self-localization, and environmental mapping. However, the many advantages of cameras (relatively low cost, high temporal and spatial resolution, etc.) are offset by a potential invasion of privacy in many applications. For example, household robots are used in private homes, which can pose a perceived, but also a real, risk for users that images will be shared with third parties or accessed through a hacking attack.
[0007] The use of camera systems in public spaces is subject to strict regulations. In particular, complex precautions must be taken when storing and processing data to comply with legal regulations. Overall, the potential invasion of privacy thus impairs the acceptance and potential use of cameras.The document DE 10 2020 203 473 A1 discloses an anonymization device for generating anonymized images, wherein surveillance images are provided by video surveillance of a surveillance area by means of at least one camera, with a recognition module, wherein the surveillance images are provided to the recognition module, wherein the recognition module is designed to recognize persons included in the surveillance images, with a processing module, wherein the processing module is designed to process the surveillance images to form the anonymized images, wherein at least one person or section of a person included in the surveillance images is anonymized in the anonymized images, wherein the processing module is designed to replace the recognized person or section of a person with an animated person model for anonymization.
[0008] Disclosure of the invention
[0009] The invention relates to a method for anonymizing an input image of an observation scene having the features of claim 1. The invention also relates to an anonymization arrangement and an application.
[0010] The invention relates to a method for anonymizing an input image which may represent an observation scene.
[0011] The input image is, in particular, captured by a camera. Alternatively, the input image is provided by a data source. The input image can be a black-and-white image, a color image, or an image with any coding. The input image preferably comprises a matrix of pixels.
[0012] The input image can depict an observation scene. The observation scene can be a view of a private or public environment. For example, the observation scene can depict a shop, a government office, a public square, a street, etc. Anonymization is particularly designed as a filtering out of identification information from identification objects in the input image. The identification objects can be people, for example, whereby the identification information can be designed as a head region of the people or the complete representation of the people or other parts of the people. If the identification objects are designed as vehicles, for example, the identification information can be designed as the license plates or an overall representation of the vehicle.It is also possible that the identification objects are designed as other private, moving objects, such as pets.
[0013] The aim of the procedure is to remove the identification information from the input image and / or to make it unrecognizable.
[0014] In a descriptor generation step, the input image is divided into image cells. The image cells are thus subregions of the input image; in particular, the image cells are arranged non-overlapping. The totality of the image cells preferably forms the entire input image. A descriptor is generated for each image cell, wherein the descriptor is designed such that the descriptor comprises application information for an application. Identification information of identification objects, however, is filtered out. The descriptor is designed, in particular, as a non-pictorial representation of the image cell. In particular, the descriptor cannot be converted into the image content of the image cell by a human observer. The descriptor is thus free of identification information of the identification objects.Filtered out and / or "free of" refers in particular to a degree of filtering in which the identifying information is reduced to such an extent that the object of identification can no longer be identified. In particular, the identifying information is completely filtered out.
[0015] The descriptors can be used in an application, for example, to map the observation scene. In an optional reconstruction step, an output image is reconstructed based on the descriptors. The reconstruction is performed without using the original input image. This prevents identification information from the input image from entering the output image. The descriptors are used as the information source or basis for the output image, with the identification information filtered out, so that the output image contains the application information but lacks the identification information. Thus, the output image, as an anonymized output image, forms an anonymized input image.
[0016] Various approaches for the anonymization of images are conceivable, which can be differentiated according to the type of anonymization as well as the location and time of anonymization.
[0017] Detection-based anonymization: This type of anonymization involves identifying the relevant image area (e.g., faces) and then blackening, blurring, or replacing it with a generic face. Detection can be performed using both traditional algorithms and deep learning methods. Deep learning methods in particular have made facial recognition quite reliable. However, both traditional and deep learning methods may fail to recognize faces at all or only recognize them late. Methods that rely on prior face detection therefore cannot guarantee successful anonymization.
[0018] Naive information reduction: A conceivable alternative form of anonymization would be the use of a sensor with a very low spatial resolution (only a few pixels). This would be technically straightforward to implement, but is impractical in practice due to the significant degradation of the function.
[0019] Anonymization as post-processing: Image anonymization is also conceivable as post-processing, i.e., in image processing software after the original image has been saved. However, since the original image, including sensitive information, must be saved and shared, there is a risk that the data could be shared, for example, through hacker attacks. Anonymization within the camera: A more secure alternative would be to perform anonymization using a hardware implementation of the anonymization algorithm, so that the original image does not need to be saved or shared. For example, a face is first recognized, and then the corresponding image area is encrypted. The process could be implemented on special hardware.
[0020] According to the invention, the anonymization reduces the image information in the entire input image, instead of relying on a potentially error-prone recognition of relevant image areas. The anonymization is therefore particularly certifiable and can be implemented, for example, in accordance with data protection guidelines or the requirements of an independent institute. Overall, the invention ensures that any use of the recorded image information is harmless from a data protection perspective, since the corresponding anonymization is carried out by an intelligent information reduction in the entire image, instead of relying on a recognition of relevant image areas (e.g., facial recognition), which can fail. Since anonymization is fundamentally accompanied by a loss of image information, the anonymization proposed here is implemented in such a way that the information content is available in the form of application information for a subsequent application (e.g.,self-localization, mapping or obstacle detection) remains optimal or at least largely intact.
[0021] In a preferred development of the invention, the image is regularly divided by the image cells. In particular, image columns and image rows are formed with the image cells. The image cells are designed in particular as rectangles, especially as squares. The image cells fill the image columns and / or image rows seamlessly and / or non-overlapping. The size of the image cell can be adapted to the requirements of anonymization. For example, these requirements could stipulate that one of the image cells in the input image may represent a y by y area with a maximum of x bytes at a specified distance in the observation scene. To meet this requirement, one can determine the maximum number of image cells that can cover such an area at the corresponding distance.
[0022] In one possible embodiment of the invention, the output image contains areas of information loss resulting from the filtering out of the identification information. This can result in blind spots or biurrings, so that the position of the objects to be identified may still be derived, but not the identification information.
[0023] Alternatively, it can be provided that image areas with filtered out identification information are supplemented with artificial image content in the reconstruction step. In this way, the resulting output images can be more easily understood and perceived intuitively by a human observer. In the reconstruction step, an image reconstruction method is used to create a representation of the observed scene of the world that is recognizable to humans. Since this reconstruction can only contain a fraction of the originally recorded information due to the filtering out of the identification information, the resulting image would, for example, have a significantly lower resolution or only represent the original image incompletely. Alternatively, the reconstruction method in the reconstruction step could add missing details, e.g.supplemented by fantasized / hallucinated image content, so that humans see a particularly high-resolution image, but which lacks the relevant information for object or, in particular, person identification. Diffusion models could be used for implementation.
[0024] In a preferred development of the invention, the descriptor is designed as an N-dimensional, in particular real-valued or binary output vector. This descriptor describes the image content of the image cell in a compact and / or abstract way. For example, the descriptor and / or the output vector is designed as a feature vector and / or feature vector. The dimension (i.e. the information content) of the descriptor should be chosen such that the required degree of anonymization is ensured. For example, such that a face cannot be identified at a distance of > 1 m. In a possible development, a keypoint and an associated descriptor, which is also assigned to the image cell, are generated for each image cell in the descriptor generation step, wherein the output image is reconstructed on the basis of the keypoints and the descriptors of the image cells. The keypoint represents, in particular, a point of interest with regard to the application.If spatial orientation is to be carried out based on the source images, the keypoints are edges or corners in the observation scene. Digital image processing can be used to detect keypoints, among other things, which can capture the keypoints through edge detection. Further possibilities will be revealed below. By using the keypoints and the descriptors assigned to the keypoint and / or the image cell, the source image can be reconstructed in the subsequent reconstruction step in such a way that the points of interest detected via the keypoints are given special consideration, thus highlighting them for subsequent applications. The keypoints form a focal point in the image cell for generating the descriptor. If no keypoint can be found, one can also be placed artificially, for example in the center of the image cell.
[0025] In a preferred development of the invention, a first CL is used in the descriptor generation step, which is configured to generate the descriptors as the output vectors based on image data in the image cells of the input image. Optionally, the first CL can generate the keypoints for each image cell. A CL is understood, in particular, to be a machine learning and / or deep learning arrangement. In particular, the first CL has at least one neural network, in particular a deep neural network and / or convolutional neural network, and / or at least one transformer network.
[0026] The first class can also have more than one neural network and / or transformer network. To generate the descriptors, a neural network can be used which provides the descriptor and / or the output vector at the output. The neural network of the first class has, in particular, a digital neural network, wherein the descriptors and / or the output vectors are digitally implemented. The digital neural network can receive the image cells at the input and provide the descriptors at the output. Alternatively, the digital neural network can receive only one image cell at the input and provide only one descriptor and / or output vector at the output, wherein the image cells are processed serially. The neural network of the first class can be multi-layered.
[0027] Alternatively, the descriptors could be determined using information reduction (e.g., principal component analysis) from feature vectors of a high-performance deeper neural network (e.g., foundation model). By using only the first n principal components, any desired information reduction can be achieved.
[0028] The keypoints can be determined using the same neural network of the first class or using another neural network of the first class. Neural networks for detecting keypoints as interest points are well known. A particularly advantageous method is described in the scientific article "SuperPoint: Self-Supervised Interest Point Detection and Description" by Daniel DeTone, Tomasz Malisiewicz, and Andrew Rabinovich, the disclosure of which is incorporated into this description by reference.
[0029] Alternatively, the first class can comprise an optical neural network, wherein in the descriptor generation step, the descriptors are first optically represented and recorded by one or more image sensors. A particularly advantageous method is described in the scientific article: "All-optical machine learning using diffractive deep neural networks" by Xing Lin, Yair Rivenson, Nezih T. Yardimci, Muhammed Veli, Yi Luo, Mona Jarrahi, and Aydogan Ozcan in Science, 361 (6406):1004-1008, 2018, the disclosure of which is incorporated into the present description by way of reference. Thus, unlike previously described, the method used for anonymization can be applied not only after the digital imaging of the light rays on the optical image sensor, but can already be integrated into the optical structure of the lenses.For this purpose, diffractive optical elements could be used, which are designed to achieve the described information reduction.
[0030] The image points extracted in the process as keypoints with associated descriptors can be determined by a digital deep neural network (see, for example, DeTone, Daniel, Tomasz Malisiewicz, and Andrew Rabinovich. „Superpoint: Self-supervised interest point detection and description.“).
[0031] Optionally, the neural network of the first class for the descriptors and optionally additionally for the keypoints can consist of eight consecutive convolutional layers, with a downsampling layer after the second, fourth and sixth convolutional layers. The dimension is thereby reduced to one eighth of the original dimension. The mentioned layers are referred to below as Descriptor Encoder N DEOptionally, the descriptor encoder can be followed by one or more further convolutional layers, which supply the descriptors as output variables; we refer to these as descriptor decoders. In addition to the descriptor decoder, the descriptor encoder can be followed by one or more further convolutional layers, which supply the coordinates of the keypoints as output variables. If keypoints are calculated, it can also be advantageous to integrate one or more upsampling layers into the descriptor decoder so that the descriptors are calculated on a finer grid than the keypoints. To determine the appropriate descriptor for a given keypoint, this can be interpolated from the output variable of the descriptor decoder for any sub-pixel accurate points. There can also be skip connections between the layers, e.g. between the 6 layer of the descriptor encoder and a layer of the descriptor decoder.
[0032] The neural network of the first class can be pre-trained for the descriptors and optionally additionally for the keypoints and / or trained in such a way that the extracted data is particularly well suited for a specific task, such as self-localization / pose determination of the camera, or the recognition of a pedestrian's movement intentions. In particular, the corresponding neural network can be trained using a training method that, in each training step, performs the corresponding application task (e.g., pose determination) based on the output images as anonymized images, and uses an error measure of the task (e.g., pose error) in the application as a loss function and, optionally, additionally, an error measure of the anonymization of the input images.Through backpropagation, the respective network can then be adapted so that the anonymized image (despite information reduction) is optimally suited to fulfilling the task in the application, optionally with sufficient anonymization. The source images, as described above, are thus used as training data.
[0033] In particular, the AI should be trained so that the descriptors are optimally suited for a target application. For example, if the target application is visual localization, the AI should be trained so that the descriptors contain information about prominent static objects that serve for localization.
[0034] In a preferred embodiment of the invention, the reconstruction step is implemented by a second class. In particular, the second class comprises at least one neural network, in particular a deep neural network and / or convolutional neural network, and / or at least one transformer network. The second class can also comprise more than one neural network and / or transformer network.
[0035] In particular, the first class is configured as an encoder and the second class as a decoder, whereby the descriptors can have a representation created with the encoder in the form of the output vector. The meaning of the various entries of the output vector(s) can be interpreted exclusively by the class, in particular the trained network, so that they form a representation in a latent space. In particular, the first class and the second class form an autoencoder, which filters out the identification information.
[0036] Optionally, the neural network of the second class for reconstruction can consist of a plurality of convolutional layers, with one or more upsampling layers optionally located between the convolutional layers, which increase the dimension back to the size of the original input image.
[0037] A further subject matter of the invention relates to an anonymization system for implementing the method as described above. The anonymization system comprises a descriptor generation module for implementing the descriptor generation step and, optionally, a reconstruction module for implementing the reconstruction step. The descriptor generation module is formed, in particular, by the first class, and the reconstruction module is formed, in particular, by the second class.
[0038] In particular, the anonymization device is designed as a camera, with the anonymization method being carried out in the camera. Optionally, the descriptor generation step is performed optically, as previously described, so that the input image is not stored and is therefore data secure. Alternatively, the camera has an image sensor for recording the input image, with the descriptor generation step being performed on the output data of the image sensor. Preferably, the input image is not stored, so that this alternative is also data secure.
[0039] Anonymization thus occurs at the hardware level, before the input image is saved or can be forwarded. This invention therefore also relates to an anonymizing camera, i.e., a camera that anonymizes sensitive information, such as faces. The invention thus provides an optical sensor that enables environmental perception without violating people's privacy.
[0040] In addition to faces, or people in general, this invention can also be used to anonymize license plates or other unique objects suitable for personal identification.
[0041] The anonymizing camera can be used, in particular, for mapping, with the anonymized images being saved as a map. Since these images are not subject to data protection concerns, the map can be stored on an external server and used across multiple users.
[0042] A key advantage of a camera equipped with this technology is that it can guarantee anonymization (and could thus, for example, be certified as compliant with data protection laws by an independent body). For other anonymization methods not covered by the invention, one could, of course, conduct a statistical analysis of how often anonymization worked successfully using a test set of sample images, but this does not guarantee that it will work in every case. A customer who purchases a product equipped with such a certified data protection-compliant camera, e.g., a robot vacuum cleaner, would no longer have to trust the product manufacturer to handle the captured images responsibly, but could instead rely on the certifying institute.Compared to a conceivable simple reduction in image resolution through blurring or a low-dimensional image sensor, this invention has the advantage that the remaining information can be specifically selected to make it suitable for a specific application. General blurring, for example, would result in a non-specific loss of image information and degrade the camera's functionality. In direct comparison with other methods not according to the invention, the invention differs as follows: • For methods that first recognize faces and then obscure the corresponding image region, it cannot be guaranteed that the anonymization requirements have been successfully implemented in every case.- With methods implemented as post-processing, the original images must first be saved / passed on, which leads to vulnerability. - With general blurring / a low-dimensional image sensor, the information is reduced in a non-specific way, which degrades the function of the camera.
[0043] A further optional subject matter of the invention relates to a computer program which is designed to implement the method as described above when implemented and / or executed on a digital data processing device, such as a computer and / or on the anonymization arrangement, in particular on a camera with a digital data processing device.
[0044] A further optional subject matter of the invention relates to a digital storage medium on which the computer program is stored.
[0045] A further subject matter of the invention relates to an application based on the anonymized source images generated by the method as described above and / or by the anonymization arrangement as described above, wherein the application is designed as a mapping of the observation scene, a navigation through the observation scene, for example, by a mobile object such as a vehicle or a robot vacuum cleaner or another mobile robot. The mapping and / or navigation is implemented based on the anonymized source images.
[0046] The application could involve autonomous driving functions, where images of observation scenes are captured, which must be taken into account in compliance with data protection guidelines. The anonymization of people and license plates also plays a major role in cameras that are to be embedded in traffic infrastructure, for example, at intersections, so one application concerns traffic monitoring. Finally, a future application of anonymizing cameras would be possible in household robots, such as robot vacuum cleaners or robot lawnmowers, especially since customers consider privacy concerns in their purchasing decisions.
[0047] Further features, advantages, and effects of the invention will become apparent from the following description of a preferred embodiment of the invention and the accompanying figures. These show:
[0048] Figure 1 is a schematic block diagram of a camera as an embodiment of the invention;
[0049] Figure 2 shows various representations of images to illustrate the method; Figure 3 shows a schematic block diagram of a camera as a modified embodiment of the invention;
[0050] Figure 1 shows a schematic block diagram of a camera 1 configured as an anonymization device 2, which implements a method for anonymizing an input image 6 of an observation scene 3. The observation scene 3 may, in particular, show a public or private area and, in particular, include persons.
[0051] The camera 1 has a lens 4, wherein the observation scene 3 is imaged onto an image sensor 5 of the camera 1 via the lens 4.
[0052] The camera 1 and / or the anonymization device 2 is configured to anonymize the input image 6 and convert it into an anonymized output image 7 (Figure 2b). For this purpose, in the exemplary embodiment in Figure 1, the input image 6 is first converted into a digital input image via the image sensor 5.
[0053] Subsequently, a descriptor generation step is carried out in a descriptor generation module 8, as shown schematically in Figure 2a. In Figure 2a, the input image 6 can be seen again in the top row. First, the input image 6 is divided into image cells 9, wherein the image cells 9 are regularly arranged in the input image 6, do not overlap, and as a whole represent the complete input image 6. For each of the image cells 9, a descriptor is created, wherein the descriptor is represented as an N-dimensional output vector di ER NOptionally, a keypoint 11 is determined for each image cell, where the keypoint 11 represents a point of interest, such as an edge or a corner. The keypoints 11 are selected depending on a subsequent application 12.
[0054] Returning to Figure 1, it is shown that, starting from the descriptor generation module 8, the descriptors and, optionally, additionally, the keypoints 11 are transferred to an optional reconstruction module 13 for implementing a reconstruction step. The reconstruction module 13 is configured to reconstruct the output image 7 based on the descriptors and, optionally, additionally, the keypoints 11. The output image 7 is subsequently output via an interface 14.
[0055] In this embodiment, the descriptor generation module 8 is configured as a deep neural network and / or a CNN. The descriptor is created such that it includes application information of the respective image cell 9 for the application 12, while filtering out identification information of identification objects 15. Identification information in the displayed input image 6 is understood to mean, for example, a face of the person depicted or the entire person.
[0056] The reconstruction module 13 is configured to create the output image 7 based on the descriptors and optionally the keypoints 11. By filtering out the identification information, the output image 7 is configured as an anonymized input image, i.e., without any identification information. In particular, the descriptor generation module 8 and the reconstruction module 13 form an autoencoder 16.
[0057] The descriptor generation module 8 is trained such that application information from the image cell 9 is retained for the application 12, but the identification information from the identification objects 15 is filtered out. The AI should thus be trained such that the descriptors are optimally suited for a target application. If the target application is, for example, visual localization, the AI should be trained such that the descriptors contain, for example, information about prominent static objects that serve for localization.
[0058] In other words, the procedure is implemented as follows:
[0059] Figure 1 shows a variant of the image recording process with camera 1, which constitutes an exemplary embodiment of the invention. First, light rays from the world are directed onto the optical image sensor 5 with the aid of an optical structure. To this extent, the camera described here corresponds to a typical camera. The camera 1 described differs in the following step, which is carried out before the recorded input image 3 of the world is made available to the outside via an interface. At this point, the image information is reduced using a method such that sensitive information (e.g. faces) can no longer be identified afterwards. The method used for the method could, for example, be implemented on a system-on-a-chip (SoC), which always processes the recorded data before it is passed on to the interfaces 14 of camera 1.The method used for anonymization is shown in Figure 2a and proceeds as follows: First, the input image 3 is divided into image cells 9. The cell size, as well as the dimensionality of the descriptor, can be adapted to the desired anonymization requirements. Then, for each image cell 9, a point is determined, which we will refer to as keypoint 11 below. For each keypoint 11, an N-dimensional real-valued (or binary) output vector is determined, which we will refer to as descriptor below. This descriptor describes the image content (in the vicinity of keypoint 11) in a compact manner. Subsequently, the remaining image information is reconstructed into the output image 7 using the extracted keypoints 11 and descriptors and output as output image 7 via the interface 14 of camera 1.Figure 2a thus shows a sketch of the input image 3 in which a person (identification object 15) can be recognized, who must be anonymized for data protection reasons. The described anonymization method divides the image into cells; for example, these image cells 9 can be square and have an edge length of a pixels. The described anonymization method reduces the given image information to an N-dimensional descriptor d per image cell 9. In addition, the method can specify for each image cell 9 the coordinates of a point contained therein (keypoint 11), to which the respective descriptor refers. Keypoints 11 do not necessarily have to be determined in the method; it would also be possible to equip each image cell 9 with a descriptor without this being tied to a specific keypoint in the image cell 9.
[0060] The output image 7 has an information loss region 17, which is caused by filtering out the identification information. Optionally, the information loss region 17 can be artificially filled by the reconstruction module 13.
[0061] The descriptor generation module 8 and the reconstruction module 13 can each be designed as a Kl, in particular a convolved or other neural network.
[0062] For training the descriptor generation module 8 with respect to the descriptors, a plurality of source images 7 can be used, as shown in Figure 2b, with loss functions taking into account, on the one hand, the suitability of the source image 7 for the application 12 and, on the other hand, the degree of anonymization of the identification object 15. In this way, the descriptor generation module 8 can be trained to encode the application information unfiltered in the descriptors and to filter out the identification information.
[0063] For training the reconstruction module 13, the quality of the reconstruction can be assessed by comparing the input image 3 and the output image 7. Thus, the output images 7 also serve as training data for the reconstruction module 13.
[0064] The application 12 can be configured as a navigation system or as a mapping system of the observation scene 6. Thus, the application information relates in particular to the detection of stationary objects in the observation scene 6, which can be particularly well identified by detecting keypoints 11.
[0065] Figure 3 shows a modified embodiment, wherein the same reference numerals refer to the same components, so that reference is made to the previous description. In the embodiment in Figure 3, the descriptor generation module 8 is designed as a combination of an optical neural network and the image sensor 5, wherein the optical neural network optically generates the descriptors and images them onto the image sensor 5, which then converts the image into a digital descriptor. The reconstruction into the output image 7 takes place as previously described. Overall, the system ensures that any use of the recorded image information is harmless from a data protection perspective, since the corresponding image content that is critical with regard to data protection is never accessible from outside the camera 1. Through intelligent information reduction, images are anonymized within the camera 1, so that, for example,Faces are no longer recognizable. This enables optical perception of the environment that does not violate people's privacy. For this purpose, camera 1 is equipped with an anonymization method that makes sensitive image content, such as faces, unrecognizable before it reaches an external interface (e.g. memory or radio connection). The light rays of the world visible to the camera fall through the aperture of camera 1 and are then directed by a lens system onto the optical sensor of camera 1. The described method is now used for anonymization by appropriately reducing the image information. The image information is then made available to the outside world via interfaces, e.g. by storing the images or forwarding them wirelessly or via cable.In one possible variant, the anonymization takes place before the optical sensor by not applying the corresponding method to the digitized image information of the optical sensor, but by integrating it in an analog manner into the optical lens system.
Claims
Claims 1 . Method for anonymizing an input image (3) of an observation scene (6), wherein in a descriptor generation step the input image (3) is divided into image cells (9), wherein a descriptor is generated for each image cell (9), wherein the descriptor is generated such that the descriptor comprises application information for an application (12) and identification information of identification objects (15) is filtered out.
2. Method according to claim 1, characterized by a reconstruction step, wherein in the reconstruction step an output image (7) is reconstructed on the basis of the descriptors, wherein the output image (7) comprises the application information, so that the output image (7) is formed as an anonymized input image (3).
3. Method according to one of the preceding claims, characterized in that the input image (3) is regularly divided by the image cells (9).
4. Method according to one of the preceding claims 2 or 3, characterized in that the output image (7) has information loss image areas (17) which arise by filtering out the identification information.
5. Method according to one of the preceding claims 2 to 4, characterized in that in the reconstruction step, image areas with filtered-out identification information are supplemented with artificial image content.
6. Method according to one of the preceding claims, characterized in that the descriptor is designed as an N-dimensional output vector.
7. Method according to one of the preceding claims, characterized in that in the descriptor generation step a keypoint (11) is generated for each image cell (9).
8. The method according to claim 7, wherein the output image (7) is reconstructed on the basis of the keypoints (11) and the associated descriptors of the respective image cells (9).
9. Method according to one of the preceding claims, characterized in that a first Kl is used in the descriptor generation step, wherein the first Kl is designed to generate the descriptors as output vectors and optionally additionally the keypoints (11) for each image cell (9) on the basis of image data of the input image (3).
10. The method according to claim 9, characterized in that the first Kl is designed as a digital neural network, wherein the descriptors are digitally designed or is designed as an optical neural network, wherein in the descriptor generation step the descriptors are optically displayed and are recorded by one or more image sensors (5). 11 . Method according to one of the preceding claims 2 to 10, characterized in that the reconstruction step is implemented by a second Kl.
12. Method according to one of the preceding claims 9 to 11, characterized in that the output images (7) are evaluated and the evaluated output images (7) are used for training the first class and / or the second class.
13. Anonymization arrangement (2) for carrying out the method according to one of the preceding claims, characterized in that it has a descriptor generation module (8) for carrying out the descriptor generation step and a reconstruction module (13) for carrying out the reconstruction step.
14. Anonymization arrangement (2) according to claim 13, characterized in that it comprises a camera (1) for recording the input image (3) and / or an interface (14) for outputting the output images and / or an output device for displaying, storing and / or further processing the output images (7) 15. Application (12) based on anonymized source images (7), wherein the anonymized source images (7) and / or the descriptors are generated by the method according to one of claims 1 to 12, wherein the application (12) is designed as a navigation of a mobile object and / or mapping of the observation scene (6).
Citation Information
Patent Citations
Privacy protection in vision systems
US20210035342A1
Anonymization device, monitoring apparatus, method, computer program, and storage medium
US20230102479A1