Adversarial Perturbations for Image Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine learning-based recognition algorithms used in internet services pose privacy concerns by effectively identifying individuals in uploaded media, leading to potential breaches of user privacy, as current mechanisms like image blurring are undesirable in public sharing scenarios and fail to protect identities while preserving visual recognition.

Innovation Solution

Applying adversarial perturbations to electronic media, such as images, by using a neural network model to add small, unperceivable changes that fool machine learning-based recognition models, while maintaining the visual integrity of the media, thereby preventing identification by image recognition algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If image blurring is applied to protect privacy, then individual identification is prevented, but visual recognition and aesthetic quality deteriorate

Engineering Contradiction:
Improveprivacy protection effectivenessVSAvoidvisual appearance quality
Core Design Contradiction:
ReliabilityVSShape

Solution Approach 1:

The patent applies different processing strategies to different regions of the image. Adversarial perturbations are selectively applied to regions containing identifiable features (such as faces) while leaving other regions unchanged, thereby protecting privacy in critical areas while preserving overall visual quality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent transforms the image data by adding carefully crafted perturbations that change the pixel values in ways that are imperceptible to humans but effective at fooling machine learning models. This parameter transformation maintains visual appearance while altering the semantic information that recognition algorithms rely on.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If adversarial perturbations are applied to protect privacy, then machine learning recognition is fooled, but the complexity of the pre-processing operation increases

Engineering Contradiction:
Improveprivacy protection effectivenessVSAvoidpre-processing operation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs adversarial perturbation generation as a pre-processing step before image upload. By preparing the protected image in advance using gradient-based optimization, the system establishes privacy protection before the image encounters recognition algorithms, simplifying the overall architecture despite the computational intensity of the pre-processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary pre-processing component that acts as a bridge between the original image and the upload process. This intermediary layer applies the necessary transformations to fool recognition algorithms while maintaining the simplicity of the core upload functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If small unperceivable perturbations are added to images, then machine learning models are fooled and privacy is protected, but the precision of image data is altered

Engineering Contradiction:
Improveprivacy protection effectivenessVSAvoidimage data precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent deliberately changes image parameters by adding perturbations that are below the threshold of human perception. These parameter changes are calculated to be minimal yet sufficient to alter the decision boundaries of machine learning models, achieving privacy protection while maintaining perceptual fidelity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10542034B1Providing adversarial perturbations to media
Publication Date: 2020.01.21 GEN DIGITAL INC
  • US10542034B1 patent drawing
  • US10542034B1 patent drawing
  • US10542034B1 patent drawing

AI summary

A method for applying perturbations to electronic media is described. A computing device may receive an electronic request to upload an electronic media to an internet-based service and perform a pre-processing operation on the electronic media based on the electronic request and a feature of the electronic media. In some examples, the computing device may perform a security action on the electronic media. For example, the computing device may apply perturbations to elements of the electronic media based on a gradient of a model. The computing device may transmit the electronic media to the internet-based service.