LDP-Feat: Image Features with Local Differential Privacy

08/22/2023
by   Francesco Pittaluga, et al.
0

Modern computer vision services often require users to share raw feature descriptors with an untrusted server. This presents an inherent privacy risk, as raw descriptors may be used to recover the source images from which they were extracted. To address this issue, researchers recently proposed privatizing image features by embedding them within an affine subspace containing the original feature as well as adversarial feature samples. In this paper, we propose two novel inversion attacks to show that it is possible to (approximately) recover the original image features from these embeddings, allowing us to recover privacy-critical image content. In light of such successes and the lack of theoretical privacy guarantees afforded by existing visual privacy methods, we further propose the first method to privatize image features via local differential privacy, which, unlike prior approaches, provides a guaranteed bound for privacy leakage regardless of the strength of the attacks. In addition, our method yields strong performance in visual localization as a downstream task while enjoying the privacy guarantee.

READ FULL TEXT

page 1

page 4

page 6

page 7

research
06/11/2020

Privacy-Preserving Visual Feature Descriptors through Adversarial Affine Subspace Embedding

Many computer vision systems require users to upload image features to t...
research
01/18/2018

On the Contractivity of Privacy Mechanisms

We present a novel way to compare the statistical cost of privacy mechan...
research
11/08/2021

Distribution-Invariant Differential Privacy

Differential privacy is becoming one gold standard for protecting the pr...
research
12/23/2021

NinjaDesc: Content-Concealing Visual Descriptors via Adversarial Learning

In the light of recent analyses on privacy-concerning scene revelation f...
research
10/20/2022

Content-based Graph Privacy Advisor

People may be unaware of the privacy risks of uploading an image online....
research
05/09/2021

Analysis and Mitigations of Reverse Engineering Attacks on Local Feature Descriptors

As autonomous driving and augmented reality evolve, a practical concern ...
research
09/02/2020

Privacy Leakage of SIFT Features via Deep Generative Model based Image Reconstruction

Many practical applications, e.g., content based image retrieval and obj...

Please sign up or login with your details

Forgot password? Click here to reset