Subverting Privacy-Preserving GANs: Hiding Secrets in Sanitized Images

09/19/2020
by   Kang Liu, et al.
6

Unprecedented data collection and sharing have exacerbated privacy concerns and led to increasing interest in privacy-preserving tools that remove sensitive attributes from images while maintaining useful information for other tasks. Currently, state-of-the-art approaches use privacy-preserving generative adversarial networks (PP-GANs) for this purpose, for instance, to enable reliable facial expression recognition without leaking users' identity. However, PP-GANs do not offer formal proofs of privacy and instead rely on experimentally measuring information leakage using classification accuracy on the sensitive attributes of deep learning (DL)-based discriminators. In this work, we question the rigor of such checks by subverting existing privacy-preserving GANs for facial expression recognition. We show that it is possible to hide the sensitive identification data in the sanitized output images of such PP-GANs for later extraction, which can even allow for reconstruction of the entire input images, while satisfying privacy checks. We demonstrate our approach via a PP-GAN-based architecture and provide qualitative and quantitative evaluations using two public datasets. Our experimental results raise fundamental questions about the need for more rigorous privacy checks of PP-GANs, and we provide insights into the social impact of these.

READ FULL TEXT
research
03/19/2018

VGAN-Based Image Representation Learning for Privacy-Preserving Facial Expression Recognition

Reliable facial expression recognition plays a critical role in human-ma...
research
05/03/2023

GANonymization: A GAN-based Face Anonymization Framework for Preserving Emotional Expressions

In recent years, the increasing availability of personal data has raised...
research
06/02/2020

A GAN-Based Image Transformation Scheme for Privacy-Preserving Deep Neural Networks

We propose a novel image transformation scheme using generative adversar...
research
06/01/2023

Privacy-Preserving Remote Heart Rate Estimation from Facial Videos

Remote Photoplethysmography (rPPG) is the process of estimating PPG from...
research
12/26/2018

Protecting Sensitive Attributes via Generative Adversarial Networks

Recent advances in computing have allowed for the possibility to collect...
research
06/16/2020

Adversarial representation learning for private speech generation

As more and more data is collected in various settings across organizati...
research
04/05/2021

Perceptual Indistinguishability-Net (PI-Net): Facial Image Obfuscation with Manipulable Semantics

With the growing use of camera devices, the industry has many image data...

Please sign up or login with your details

Forgot password? Click here to reset