IP Library › Granted Patent US 11,520,923
Granted Patent B2
US 11,520,923 · App. 16/674,425 · Granted Dec 6, 2022

Privacy-preserving visual recognition via adversarial learning

Inventors: Kihyuk Sohn (Fremont, CA); Manmohan Chandraker (Santa Clara, CA); Yi-Hsuan Tsai (San Jose, CA)
G06F21/6245G06N3/0454G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,520,923
App. No.
16/674,425
Filed
Nov 5, 2019
Granted
Dec 6, 2022
Kind
B2
Art Unit
2674
USPC
726/26
Abstract

A method for protecting visual private data by preventing data reconstruction from latent representations of deep networks is presented. The method includes obtaining latent features from an input image and learning, via an adversarial reconstruction learning framework, privacy-preserving feature representations to maintain utility performance and prevent the data reconstruction by simulating a black-box model inversion attack by training a decoder to reconstruct the input image from the latent features and training an encoder to maximize a reconstruction error to prevent the decoder from inverting the latent features while minimizing the task loss.

Claims (96)

1. A computer-implemented method executed on a processor for protecting visual private data by preventing data reconstruction from latent representations of deep networks, the method comprising:

obtaining latent features from an input image; and

learning, via an adversarial reconstruction learning framework, privacy-preserving feature representations to maintain utility performance and prevent the data reconstruction by:

simulating a black-box model inversion attack by training a decoder to reconstruct the input image from the latent features; and

training an encoder to maximize a reconstruction error to prevent the decoder from inverting the latent features while minimizing the task loss.

2. The method of claim 1 , wherein the latent features are transmitted and stored on a cloud for further processing.

3. The method of claim 1 , wherein the adversarial reconstruction learning framework adopts a multilayer perceptron (MLP) classifier that predicts a utility label by minimizing a utility loss.

4. The method of claim 3 , wherein the utility loss is given by:

u = {(X∈χ 1 ,Y)} [ ( f ( Z ), Y )],

where f(Z)=f(Enc(X)), Y is a ground-truth label for utility, is a standard loss for utility, X is an input, and χ 1 is private training data.

5. The method of claim 4 , wherein the decoder is trained to compete against the encoder such that the decoder learns to decode an output of the encoder by minimizing a reconstruction loss.

6. The method of claim 5 , wherein the reconstruction loss is given by:

p = {(X∈χ 1 ,Z)} [∥ Dec ( Z )− X∥ 2 ],

where X is an input, Z is the output of the encoder, and χ 1 is private training data.

7. The method of claim 6 , wherein a quality of reconstruction is modified by employing a perceptual similarity loss given by:

perc = {(X∈χ 1 ,Z)} [∥ g ( Dec ( Z ))− g ( X )∥ 2 ],

where X is an input, Z is the output of the encoder, and χ 1 is private training data.

8. The method of claim 7 , wherein an overall training objective of a protector is given by:

min

Enc

,

f

⁢

⁢

ℒ

u

-

λ

1

⁢

ℒ

p

-

λ

2

⁢

ℒ

perc

,

where u is the utility loss, p is the reconstruction loss, and perc is the perceptual similarity loss.

9. A non-transitory computer-readable storage medium comprising a computer-readable program for protecting visual private data by preventing data reconstruction from latent representations of deep networks, wherein the computer-readable program when executed on a computer causes the computer to perform the steps of:

obtaining latent features from an input image; and

learning, via an adversarial reconstruction learning framework, privacy-preserving feature representations to maintain utility performance and prevent the data reconstruction by:

simulating a black-box model inversion attack by training a decoder to reconstruct the input image from the latent features; and

training an encoder to maximize a reconstruction error to prevent the decoder from inverting the latent features while minimizing the task loss.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the latent features are transmitted and stored on a cloud for further processing.

11. The non-transitory computer-readable storage medium of claim 9 , wherein the adversarial reconstruction learning framework adopts a multilayer perceptron (MLP) classifier that predicts a utility label by minimizing a utility loss.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the utility loss is given by:

u = {(X∈χ 1 ,Y)} [ ( f ( z ), Y )],

where f(Z)=f(Enc(X)), Y is a ground-truth label for utility, is a standard loss for utility, X is an input, and χ 1 is private training data.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the decoder is trained to compete against the encoder such that the decoder learns to decode an output of the encoder by minimizing a reconstruction loss.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the reconstruction loss is given by:

p = {(X∈χ 1 ,Z)} [∥ Dec ( Z )− X∥ 2 ],

where X is an input, Z is the output of the encoder, and χ 1 is private training data.

15. The non-transitory computer-readable storage medium of claim 14 , wherein a quality of reconstruction is modified by employing a perceptual similarity loss given by:

perc = {(X∈χ 1 ,Z)} [∥ g ( Dec ( Z ))− g ( X )∥ 2 ],

where X is an input, Z is the output of the encoder, and χ 1 is private training data.

16. The non-transitory computer-readable storage medium of claim 15 , wherein an overall training objective of a protector is given by:

min

Enc

,

f

⁢

⁢

ℒ

u

-

λ

1

⁢

ℒ

p

-

λ

2

⁢

ℒ

perc

,

where u is the utility loss, p is the reconstruction loss, perc and is the perceptual similarity loss.

17. A system for protecting visual private data by preventing data reconstruction from latent representations of deep networks, the system comprising:

a memory; and

one or more processors in communication with the memory configured to:

obtain latent features from an input image; and

learn, via an adversarial reconstruction learning framework, privacy-preserving feature representations to maintain utility performance and prevent the data reconstruction by:

simulating a black-box model inversion attack by training a decoder to reconstruct the input image from the latent features; and

training an encoder to maximize a reconstruction error to prevent the decoder from inverting the latent features while minimizing the task loss.

18. The system of claim 17 , wherein the adversarial reconstruction learning framework adopts a multilayer perceptron (MLP) classifier that predicts a utility label by minimizing a utility loss given by:

u = {(X∈χ 1 ,Y)} [ ( f ( Z ), Y )],

where f(Z)=f(Enc(X)), Y is a ground-truth label for utility, is a standard loss for utility, X is an input, and χ 1 is private training data.

19. The system of claim 18 , wherein the decoder is trained to compete against the encoder such that the decoder learns to decode an output of the encoder by minimizing a reconstruction loss given by:

p = {(X∈χ 1 ,Z)} [∥ Dec ( Z )− X∥ 2 ],

where X is an input, Z is the output of the encoder, and χ 1 is private training data.

20. The system of claim 19 , wherein a quality of reconstruction is modified by employing a perceptual similarity loss given by:

perc = {(X∈χ 1 ,Z)} [∥ g ( Dec ( Z ))− g ( X )∥ 2 ],

where X is an input, Z is the output of the encoder, and χ 1 is private training data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2022
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 061494/0163 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2019
From: SOHN, KIHYUK; CHANDRAKER, MANMOHAN; TSAI, YI-HSUAN
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 050919/0154 →
Continuity (3)
Provisional Application 62878786 · Jul 26, 2019
Provisional Application 62756765 · Nov 7, 2018
Related Publication 20200143079A1 · May 7, 2020
Cited By (2)
US 12,664,313 US 12,699,785