A Study of Face Obfuscation in ImageNet
arXiv:2103.06191
Abstract
Face obfuscation (blurring, mosaicing, etc.) has been shown to be effective for privacy protection; nevertheless, object recognition research typically assumes access to complete, unobfuscated images. In this paper, we explore the effects of face obfuscation on the popular ImageNet challenge visual recognition benchmark. Most categories in the ImageNet challenge are not people categories; however, many incidental people appear in the images, and their privacy is a concern. We first annotate faces in the dataset. Then we demonstrate that face obfuscation has minimal impact on the accuracy of recognition models. Concretely, we benchmark multiple deep neural networks on obfuscated images and observe that the overall recognition accuracy drops only slightly (<= 1.0%). Further, we experiment with transfer learning to 4 downstream tasks (object recognition, scene recognition, face attribute classification, and object detection) and show that features learned on obfuscated images are equally transferable. Our work demonstrates the feasibility of privacy-aware visual recognition, improves the highly-used ImageNet challenge benchmark, and suggests an important path for future visual datasets. Data and code are available at https://github.com/princetonvisualai/imagenet-face-obfuscation.
Accepted to ICML 2022
References in corpus (5)
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- No Classification without Representation: Assessing Geodiversity Issues in Open Data Sets for the Developing World
- Defeating Image Obfuscation with Deep Learning
- Privacy Protection in Street-View Panoramas using Depth and Multi-View Imagery
- Auditing ImageNet: Towards a Model-driven Framework for Annotating Demographic Attributes of Large-Scale Image Datasets
Cited by in corpus (9)
- Intriguing Properties of Vision Transformers
- Multimodal datasets: misogyny, pornography, and malignant stereotypes
- On Improving Adversarial Transferability of Vision Transformers
- Mitigating Dataset Harms Requires Stewardship: Lessons from 1000 Papers
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanning
- Anonymization for Skeleton Action Recognition
- Privacy-Preserving Portrait Matting
- Understanding top-down attention using task-oriented ablation design
- PatchGame: Learning to Signal Mid-level Patches in Referential Games