Obfuscation Network Training via Frequency Filtering for Privacy-Preserving ML
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data anonymization techniques distort original data, making it unusable for machine learning algorithms and failing to completely conceal identification information, especially in large datasets like big data, which hinders privacy protection and data sharing.
Innovation Solution
A learning method that trains an obfuscation network to filter frequency information, generating obfuscated data that is recognizable by computers but not by humans, using techniques like high-pass and low-pass filters or band reject filters to create data that is similar to the original for machine learning but distinct for human recognition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional face-concealing methods are used to mask or blur identification information, then privacy protection is improved, but machine learning algorithms cannot utilize the data due to distortion
Solution Approach 1:
The patent applies parameter changes by transforming the facial region through geometric transformations (scaling, rotating, shearing) and intensity transformations (brightness, contrast, saturation adjustments) to generate synthetic images that maintain structural information for machine learning while altering appearance for privacy protection
Solution Approach 2:
The patent creates synthetic copies of facial regions through generative models that replicate the structural and textural characteristics of original faces while generating visually distinct images that cannot be used for identification, thereby preserving data usability without compromising privacy
2Device complexity
If simple blurring is applied to anonymize video frames, then processing complexity is reduced, but critical information such as facial expressions is lost and identification information may remain
Solution Approach 1:
The patent applies multiple parameter changes including geometric transformations (scaling, rotating, shearing), intensity transformations (brightness, contrast, saturation), and frequency transformations (blurring, sharpening) to systematically alter facial regions while preserving essential structural information needed for expression analysis
Solution Approach 2:
The patent combines multiple transformation techniques (geometric, intensity, frequency) and applies them in composite sequences to achieve cumulative privacy protection effects while maintaining data utility, creating a multi-layered obfuscation approach
3Reliability
If original data is obfuscated to be different from the original, then privacy protection is improved, but the obfuscated data becomes less similar to the original for machine learning purposes
Solution Approach 1:
The patent carefully controls the degree and type of parameter changes applied to facial regions, selecting transformations that alter appearance sufficiently for privacy protection while maintaining the structural integrity and semantic information needed for machine learning tasks
Solution Approach 2:
The patent generates synthetic copies that replicate the essential characteristics and patterns of original data while being visually distinct, ensuring that the copied data maintains statistical properties and relationships needed for machine learning while preventing identification
Data Source
AI summary
A learning method for training an obfuscation network capable of obfuscating original data for privacy, including steps of: (a) inputting training data into the obfuscation network to filter frequency information of the training data and thus generate obfuscated data; and (b) (i) inputting the obfuscated data into a learning network to generate characteristic information by performing learning operation on the obfuscated data, (ii) generating at least one task loss by referring to (ii-1) the characteristic information and its corresponding ground truth or (ii-2) a task-specific output, generated by using the characteristic information, and its corresponding ground truth, and (iii) training at least one of the learning network and the obfuscation network through a backpropagation of the task loss.


