Adversarial Image Perturbation for Privacy Protection -- A Game Theory Perspective
arXiv:1703.09471
Abstract
Users like sharing personal photos with others through social media. At the same time, they might want to make automatic identification in such photos difficult or even impossible. Classic obfuscation methods such as blurring are not only unpleasant but also not as effective as one would expect. Recent studies on adversarial image perturbations (AIP) suggest that it is possible to confuse recognition systems effectively without unpleasant artifacts. However, in the presence of counter measures against AIPs, it is unclear how effective AIP would be in particular when the choice of counter measure is unknown. Game theory provides tools for studying the interaction between agents with uncertainties in the strategies. We introduce a general game theoretical framework for the user-recogniser dynamics, and present a case study that involves current state of the art AIP and person recognition techniques. We derive the optimal strategy for the user that assures an upper bound on the recognition rate independent of the recogniser's counter measure. Code is available at https://goo.gl/hgvbNK.
To appear at ICCV'17
References in corpus (8)
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Simple Black-Box Adversarial Perturbations for Deep Networks
- Defeating Image Obfuscation with Deep Learning
- Learning Deep Features via Congenerous Cosine Loss for Person Recognition
- Beyond Frontal Faces: Improving Person Recognition Using Multiple Cues
- Faceless Person Recognition; Privacy Implications in Social Media
- Assessing Threat of Adversarial Examples on Deep Neural Networks
- A Domain Based Approach to Social Relation Recognition
Cited by in corpus (7)
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- On Success and Simplicity: A Second Look at Transferable Targeted Attacks
- A Hybrid Model for Identity Obfuscation by Face Replacement
- Butterfly Effect: Bidirectional Control of Classification Performance by Small Additive Perturbation
- Natural and Effective Obfuscation by Head Inpainting
- Amadeus: Scalable, Privacy-Preserving Live Video Analytics
- Distribution Discrepancy Maximization for Image Privacy Preserving