vix.ing · top · new · best · stats · spec

DISCO: Dynamic and Invariant Sensitive Channel Obfuscation for deep\n neural networks

2020/12/20 by Abhishek Singh, Singh, Abhishek, Ayush Chopra +11 · 4 citations
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Artificial Intelligence (cs.AI) #Computer Vision and Pattern Recognition (cs.CV) #Digital Media Forensic Detection #FOS: Computer and information sciences

paper · pdf · doi:10.48550/arxiv.2012.11025

openalex publication_date 2020/12/20 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28

Abstract

Recent deep learning models have shown remarkable performance in image\nclassification. While these deep learning systems are getting closer to\npractical deployment, the common assumption made about data is that it does not\ncarry any sensitive information. This assumption may not hold for many\npractical cases, especially in the domain where an individual's personal\ninformation is involved, like healthcare and facial recognition systems. We\nposit that selectively removing features in this latent space can protect the\nsensitive information and provide a better privacy-utility trade-off.\nConsequently, we propose DISCO which learns a dynamic and data driven pruning\nfilter to selectively obfuscate sensitive information in the feature space. We\npropose diverse attack schemes for sensitive inputs & attributes and\ndemonstrate the effectiveness of DISCO against state-of-the-art methods through\nquantitative and qualitative evaluation. Finally, we also release an evaluation\nbenchmark dataset of 1 million sensitive representations to encourage rigorous\nexploration of novel attack schemes.\n

Cited by

Related