Electronic Device Perturbation Data for Image Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices face challenges in protecting personal information within images from misuse or abuse, as existing methods like encryption and image modification are either ineffective or degrade image quality, and inserting watermarks cannot prevent misuse.
Innovation Solution
An electronic device generates and applies perturbation data to recognized facial areas in images using a machine learning model, causing malfunction in image recognition algorithms without visually noticeable modifications, thereby preventing misuse when transmitting images.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to protect images, then personal information security is improved, but image sharing functionality deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-processing images with perturbation data before sharing. The image processing module automatically adds imperceptible perturbations to facial regions in advance, so that when images are shared externally, the machine learning models cannot recognize faces even without additional encryption steps.
2Reliability
If image modification (blur, emoticon insertion) is applied, then personal information protection is improved, but image quality deteriorates
Solution Approach 1:
The patent applies parameter changes by modifying image pixel values through perturbation data with extremely small magnitudes (e.g., L2 norm constraints). These parameter changes are subtle enough to be imperceptible to human eyes but sufficient to cause machine learning models to fail in face recognition, thus protecting privacy without degrading visible image quality.
Solution Approach 2:
The patent applies color changes by adding perturbation data that subtly alters pixel colors and intensities in facial regions. These color changes are designed to be invisible to humans but effective at disrupting machine learning-based face recognition algorithms.
3Reliability
If watermark insertion is used, then personal information protection is improved, but misuse prevention capability deteriorates
Solution Approach 1:
The patent converts the harm of potential misuse into a benefit by making images intentionally unrecognizable to machine learning models. The perturbation data that degrades machine recognition capability also serves as protection against misuse, as stolen or leaked images cannot be effectively used for deepfake generation or other malicious purposes.
4Object-affected harmful factors
If perturbation data is applied to recognized areas, then misuse prevention is improved, but image recognition accuracy deteriorates
Solution Approach 1:
The patent applies local quality by targeting perturbation data specifically to recognized facial regions rather than the entire image. The image processing module identifies face areas and applies perturbations locally to these regions, making the image unrecognizable to machines in those specific areas while leaving the rest of the image quality intact.
Data Source
AI summary
An electronic device according to an embodiment disclosed herein may include a communication circuit, a processor; and a memory configured to be operatively connected to the processor. The memory according to an embodiment may store instructions that, when executed, cause the processor to: recognize an area comprising at least part of a face in an image to be transmitted to an external device; generate perturbation data about the recognized area based on a machine learning model stored in the memory; apply the perturbation data to the recognized area; and transmit the image to which the perturbation data has been applied to the external device. Various other embodiments are possible.


