IP Library › Granted Patent US 12,664,313
Granted Patent B2
US 12,664,313 · App. 18/524,419 · Granted Jun 23, 2026

Utility preserving anonymization of visual content

Inventors: Kieran Fraser (Dublin, IE); Liubov Nedoshivina (Dublin, IE); Anisa Halimi (Dublin, IE); Stefano Braghin (Dublin, IE)
Assignee: International Business Machines Corporation
G06F21/6263G16H40/67
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,664,313
App. No.
18/524,419
Filed
Nov 30, 2023
Granted
Jun 23, 2026
Kind
B2
Art Unit
2445
USPC
726/28
Abstract

A method, computer system, and a computer program product for visual content privatization is provided. The present invention may include receiving visual content associated with a subject. The present invention may include altering the visual content using at least one or more image perturbations or one or more adversarial patches in response to a practitioner requesting an external consultation from a third party. The present invention may include presenting an altered visual content to the practitioner within a user interface. The present invention may include transmitting the altered visual content to the third party following an approval by the practitioner.

Claims (39)

1 . A method for visual content privatization, the method comprising:

receiving visual content associated with a subject;

altering the visual content using at least one or more image perturbations or one or more adversarial patches in response to a practitioner requesting an external consultation from a third party, wherein the visual content is altered within a privacy-utility system comprised of a feature recognition component and a visual content altering component, wherein the visual content altering component implements a level of noise within the visual content such that the altered visual content is misclassified by a trained classification model, and wherein the feature recognition component utilizes one or more feature recognition algorithms and one or more feature re-identification algorithms;

presenting an altered visual content to the practitioner within a user interface including analytics associated with the altered visual content and one or more additional recommendations, wherein the analytics and one or more recommendations are generated using one or more machine learning models;

transmitting the altered visual content to the third party following an approval by the practitioner; and

retraining the one or more machine learning models based on the one or more additional recommendations implemented and not implemented by the practitioner.

2 . The method of claim 1 , wherein altering the visual content in response to the practitioner requesting the external consultation further comprises:

displaying one or more prompts to the practitioner in the user interface, wherein the one or more prompts are designed to gather information about a downstream task, wherein adversarial algorithms, including a Fast Gradient Sign Method (FGSM), and utility metrics are leveraged in altering the visual content based on the downstream task.

3 . The method of claim 2 , wherein the altered visual content presented to the practitioner maximizes a utility of the visual content for the downstream task and minimizes a reidentification risk of the subject associated with the visual content, wherein a degree of the image perturbations, locations, and pervasiveness are throttled depending on the downstream task.

4 . The method of claim 2 , wherein the retraining of the one or more machine learning models further utilizes interactions and actions of the practitioner within the user interface during an evaluation process to fine tune the one or more machine learning models specifically to the practitioner or the downstream task.

5 . The method of claim 1 , wherein the privacy-utility system is further comprised of an evaluation component and a threshold component.

6 . The method of claim 1 , wherein the approval by the practitioner is received in the user interface following an evaluation by the practitioner of the altered visual content in an interactive environment within the user interface.

7 . The method of claim 6 , wherein actions associated with the evaluation by the practitioner are utilized for additional training of the one or more machine learning models, such that the one or more machine learning models improve future alterations to new visual content in a manner specific to a downstream task or the practitioner.

8 . The method of claim 1 , wherein the practitioner may adjust levels of acceptable utility reduction and a privacy threshold within the user interface based on the analytics associated with the altered visual content.

9 . A computer system for visual content privatization, comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

program instructions, stored on at least one of the one or more computer-readable storage media for execution by at least one of the one or more processors via at least one of the one or more memories, to receive visual content associated with a subject;

program instructions, stored on at least one of the one or more computer-readable storage media for execution by at least one of the one or more processors via at least one of the one or more memories, to alter the visual content using at least one or more image perturbations or one or more adversarial patches in response to a practitioner requesting an external consultation from a third party, wherein the visual content is altered within a privacy-utility system comprised of a feature recognition component and a visual content altering component, wherein the visual content altering component implements a level of noise within the visual content such that the altered visual content is misclassified by a trained classification model, and wherein the feature recognition component utilizes one or more feature recognition algorithms and one or more feature re-identification algorithms;

program instructions, stored on at least one of the one or more computer-readable storage media for execution by at least one of the one or more processors via at least one of the one or more memories, to present an altered visual content to the practitioner within a user interface including analytics associated with the altered visual content and one or more additional recommendations, wherein the analytics and one or more recommendations are generated using one or more machine learning models;

program instructions, stored on at least one of the one or more computer-readable storage media for execution by at least one of the one or more processors via at least one of the one or more memories, to transmit the altered visual content to the third party following an approval by the practitioner; and

program instructions, stored on at least one of the one or more computer-readable storage media for execution by at least one of the one or more processors via at least one of the one or more memories, to retrain the one or more machine learning models based on the one or more additional recommendations implemented and not implemented by the practitioner.

10 . The computer system of claim 9 , wherein the program instructions to alter the visual content in response to the practitioner requesting the external consultation further comprises:

program instructions, stored on at least one of the one or more computer-readable storage media for execution by at least one of the one or more processors via at least one of the one or more memories, to display one or more prompts to the practitioner in the user interface, wherein the one or more prompts are designed to gather information about a downstream task, wherein adversarial algorithms, including a Fast Gradient Sign Method (FGSM), and utility metrics are leveraged in altering the visual content based on the downstream task.

11 . The computer system of claim 10 , wherein the altered visual content presented to the practitioner maximizes a utility of the visual content for the downstream task and minimizes a reidentification risk of the subject associated with the visual content, wherein a degree of the image perturbations, locations, and pervasiveness are throttled depending on the downstream task.

12 . The computer system of claim 9 , wherein the privacy-utility system is further comprised of an evaluation component and a threshold component.

13 . The computer system of claim 9 , wherein the approval by the practitioner is received in the user interface following an evaluation by the practitioner of the altered visual content in an interactive environment within the user interface.

14 . The computer system of claim 13 , wherein actions associated with the evaluation by the practitioner are utilized for additional training of the one or more machine learning models, such that the one or more machine learning models improve future alterations to new visual content in a manner specific to a downstream task or the practitioner.

15 . A computer program product for visual content privatization, comprising:

one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions comprising:

program instructions, stored on at least one of the one or more computer-readable storage media, to receive visual content associated with a subject;

program instructions, stored on at least one of the one or more computer-readable storage media, to alter the visual content using at least one or more image perturbations or one or more adversarial patches in response to a practitioner requesting an external consultation from a third party, wherein the visual content is altered within a privacy-utility system comprised of a feature recognition component and a visual content altering component, wherein the visual content altering component implements a level of noise within the visual content such that the altered visual content is misclassified by a trained classification model, and wherein the feature recognition component utilizes one or more feature recognition algorithms and one or more feature re-identification algorithms;

program instructions, stored on at least one of the one or more computer-readable storage media, to present an altered visual content to the practitioner within a user interface including analytics associated with the altered visual content and one or more additional recommendations, wherein the analytics and one or more recommendations are generated using one or more machine learning models;

program instructions, stored on at least one of the one or more computer-readable storage media, to transmit the altered visual content to the third party following an approval by the practitioner; and

program instructions, stored on at least one of the one or more computer-readable storage media, to retrain the one or more machine learning models based on the one or more additional recommendations implemented and not implemented by the practitioner.

16 . The computer program product of claim 15 , wherein the program instructions to alter the visual content in response to the practitioner requesting the external consultation further comprises:

program instructions, stored on at least one of the one or more computer-readable storage media, to display one or more prompts to the practitioner in the user interface, wherein the one or more prompts are designed to gather information about a downstream task, wherein adversarial algorithms, including a Fast Gradient Sign Method (FGSM), and utility metrics are leveraged in altering the visual content based on the downstream task.

17 . The computer program product of claim 16 , wherein the altered visual content presented to the practitioner maximizes a utility of the visual content for the downstream task and minimizes a reidentification risk of the subject associated with the visual content, wherein a degree of the image perturbations, locations, and pervasiveness are throttled depending on the downstream task.

18 . The computer program product of claim 15 , wherein the privacy-utility system is further comprised of an evaluation component and a threshold component.

19 . The computer program product of claim 15 , wherein the approval by the practitioner is received in the user interface following an evaluation by the practitioner of the altered visual content in an interactive environment within the user interface.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: FRASER, KIERAN; NEDOSHIVINA, LIUBOV; HALIMI, ANISA; BRAGHIN, STEFANO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065716/0101 →
Continuity (1)
Related Publication 20250181770A1 · Jun 5, 2025
References Cited (48)
US 8463006B2 · Prokoski · 2013 [cited by applicant]
US 10535120B2 · Edwards · 2020 [cited by applicant]
US 10803347B2 · Salavon · 2020 [cited by applicant]
US 11520923B2 · Sohn · 2022 [cited by applicant]
US 20130060579A1 · Yu · 2013 [cited by examiner]
US 20190279765A1 · Giataganas · 2019 [cited by examiner]
US 20200312457A1 · Kasthurirathne · 2020 [cited by applicant]
US 20230137378A1 · Laterza · 2023 [cited by applicant]
US 20230186098A1 · Chang · 2023 [cited by applicant]
US 20240394408A1 · Schmidtlein · 2024 [cited by examiner]
US 20250239366A1 · Ayodhimani · 2025 [cited by examiner]
CN 112836653A · 2021 [cited by applicant]
JP 2006320488A · 2011 [cited by applicant]
Alslman, et al., “Hybrid Encryption Scheme for Medical Imaging Using AutoEncoder and Advanced Encryption Standard”, MDPI, Electronics 2022, 11, 3967, Published Nov. 30, 2022, 15 pgs. [cited by applicant]
Antonatos, et al., “PRIMA: An End-to-End Framework for Privacy at Scale”, ResearchGate, Apr. 2018, 13 pgs. [cited by applicant]
Brown, et al., “Adversarial Patch”, arXiv:1712.09665v2 [cs.CV], May 17, 2018, 6 pgs. [cited by applicant]
Bruna, et al., “Modified MRI Anonymization (De-Facing) for Improved MEG Coregistration”, MDPI, Bioengineering 2022, 9, 591, Published Oct. 21, 2022, 15 pgs. [cited by applicant]
Carlini, et al., “Towards Evaluating the Robustness of Neural Networks”, 2017 IEEE Symposium on Security and Privacy, IEEE Computer Society, 2017, pp. 39-57. [cited by applicant]
Chatterjee, et al., “Classification of Brain Tumours in MR Images Using Deep Spatiospatial Models”, arXiv:2105.14071v2 [eess.IV], Jan. 14, 2022, 13 pgs. [cited by applicant]
Chen, et al., “HopSkipJumpAttack: A Query-Efficient Decision-Based Attack”, arXiv:1904.02144v5 [cs.LG], Apr. 28, 2020, 18 pgs. [cited by applicant]
De Sitter, et al., “Facing Privacy in Neuroimaging: Removing Facial Features Degrades Performance of Image Analysis Methods”, Springer, European Radiology (2020) 30:1062-1074, 13 pgs. [cited by applicant]
DLIB, “High Quality Face Recognition with Deep Metric Learning”, DLIB C++ Library, Feb. 12, 2017, 40 pgs. [cited by applicant]
DLIB, “Major Features”, DLIB C++ Library, [accessed Sep. 6, 2023], 4 pgs., Retrieved from the Internet: <http://dlib.net/>. [cited by applicant]
Ghiasi, et al., “Breaking Certified Defenses: Semantic Adversarial Examples with Spoofed Robustness Certificates”, arXiv:2003.08937v1 [cs.LG], Mar. 19, 2020, 16 pgs. [cited by applicant]
Goodfellow, et al., “Explaining and Harnessing Adversarial Examples”, arXiv:1412.6572v3 [stat.ML], Mar. 20, 2015, pp. 1-11. [cited by applicant]
He, et al., “Deep Residual Learning for Image Recognition”, arXiv:1512.03385v1 [cs.CV], Dec. 10, 2015, pp. 1-12. [cited by applicant]
Jeong, et al., “De-Identification of Facial Features in Magnetic Resonance Images: Software Development Using Deep Learning Technology”, J Med Internet Res Dec. 2020; 22(12):e27739, Published online Dec. 10, 2020, 16 pa… [cited by applicant]
Jeong, et al., “De-Identification of Facial Features in Magnetic Resonance Images: Software Development Using Deep Learning Technology”, Journal of Medical Internet Research 2020;22(12):e22739, 8 pgs. [cited by applicant]
Knoche, et al., “Octuplet Loss: Make Face Recognition Robust to Image Resolution”, arXiv:2207.06726v2 [cs.CV], Mar. 21, 2023, 14 pgs. [cited by applicant]
Lee, et al., “On Physical Adversarial Patches for Object Detection”, ICML 2019 Workshop on Security and Privacy of Machine Learning, arXiv:1906.11897v1 [cs.CV], Jun. 20, 2019, 5 pgs. [cited by applicant]
Letournel, et al., “Face De-Identification With Expressions Preservation”, 2015 IEEE Internationl Conference on Image Processing (ICIP), Quebec City, Canada, 2015, pp. 4366-4370, 6 pgs. [cited by applicant]
Liu, et al., “Deep Face-Swap Model Combining Attention Mechanism and CycleGAN”, Journal of Physics: Conference Series, 2278 (2022) 012037, 10 pgs. [cited by applicant]
Madry, et al., “Towards Deep Learning Models Resistant to Adversarial Attacks”, arXiv:1706.06083v4 [stat.ML] Sep. 4, 2019, 28 pgs. [cited by applicant]
Oh, et al., “Adversarial Image Perturbation for Privacy Protection A Game Theory Perspective”, 2017 IEEE International Conference on Computer Vision, pp. 1491-1500. [cited by applicant]
Parks, et al., “Automated Facial Recognition of Computed Tomography-Derived Facial Images: Patient Privacy Implications”, Springer, J DIgit Imaging (2017) 30:204-214, 11 pgs. [cited by applicant]
Popescu, et al., “Obfuscation Algorithm for Privacy-Preserving Deep Learning-Based Medical Image Analysis”, MDPI, Applied Sciences 2022, 12, 3997, Published Apr. 14, 2022, 26 pgs. [cited by applicant]
Rakpurkar, et al., “CheXNet: Radiologist-Level Pneumonia Detection on Chest X-Rays with Deep Learning”, arXiv:1711.05225v3 [cs.CV], Dec. 25, 2017, 7 pgs. [cited by applicant]
Ryu, et al., “Adversarial Attacks by Attaching Noise Markers on the Face Against Deep Face Recognition”, Elsevier, Journal of Information Security and Applications 60 (2021) 102874, May 21, 2021, 11 pgs. [cited by applicant]
Schwarz, et al., “Face Recognition from Research Brain PET: An Unexpected PET Problem”, Elsevier, NeuroImage 258 (2022) 119357, Jun. 3, 2022, 11 pgs. [cited by applicant]
Terhorst, et al., “QMagFace: Simple and Accurate Quality-Aware Face Recognition”, arXiv:2111.13475v3 [cs.CV], Mar. 23, 2022, 16 pgs. [cited by applicant]
Ter-Sarkisov, “Detection and Segmentation of Lesion Areas in Chest CT Scans for the Prediction of COVID-19”, Computer Society, ASCEE, Science in Information Technology Letters, vol. 1., No. 2, Nov. 2020, pp. 92-99. [cited by applicant]
Tesseract OCR, “Various Documents Related to Tesseract OCR”, Tesseract OCR, [accessed Sep. 5, 2023], 5 pgs., Retrieved from the Internet: <https://tesseract-ocr.github.io/docs/>. [cited by applicant]
Torfi, “Privacy-Preserving Synthetic Medical Data Generation with Deep Learning”, Doctor of Philosophy Dissertation, Virginia Polytechnic Institute and State University, Aug. 10, 2020, 115 pgs. [cited by applicant]
Xiao, et al., “Improving Transferability of Adversarial Patches on Face Recognition with Generative Models”, 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 10 pages. [cited by applicant]
Xue, et al., “Face Image De-Identification by Feature Space Adversarial Perturbation”, Wiley, Concurrency Computat Pract Exper. 2023;35:e7554, 13 pgs. [cited by applicant]
Yang, et al., “A Digital Mask to Safeguard Patient Privacy”, Nature Medicine, vol. 28, Sep. 2022, 1883-1892, 22 pgs. [cited by applicant]
Zhong, et al., “Face Transformer for Recognition”, arXiv:2103.14803v2 [cs.CV], Apr. 13, 2021, 5 pgs. [cited by applicant]
Zhu, et al., “Human Recognition Using Face in Computed Tomography”, arXiv:2005.14238v1 [cs.CV], May 28, 2020, 11 pgs. [cited by applicant]