IP Library Granted Patent US 12,682,023
Granted Patent B2
US 12,682,023 · App. 17/083,566 · Granted Jul 14, 2026

Published content protection

Inventors: Hessel Tuinhof (Dublin, IE); Killian Levacher (Dundrum, IE); Stefano Braghin (Dublin, IE)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/125G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,682,023
App. No.
17/083,566
Granted
Jul 14, 2026
Kind
B2
Abstract

A method, computer system, and a computer program product for published content protection is provided. The present invention may include receiving a content file from a content management system (CMS). The present invention may include extracting a feature from the received content file. The present invention may include transforming, using an adversarial generation algorithm, the received content file into an adversarial content file. The present invention may include returning the adversarial content file to the CMS. The returned adversarial content file may represent an equivalent of the received content file to a content consumer. The present invention may include preventing an application of the returned adversarial content file in at least one machine learning task based on the adversarial noise included in the returned adversarial content file.

Claims (56)

1 . A computer-implemented method, comprising:

receiving a content file from a content management system (CMS);

extracting at least one feature from the received content file to determine, from a plurality of machine learning tasks, at least one machine learning task for a media type of the received content file;

determining an adverse noise limit by balancing competing objectives of reducing performance of the at least one machine learning task on the received content file and maintaining an equivalent representation of the received content file for a human content consumer;

selecting, based on the media type and the at least one machine learning task associated with the received content file, an adversarial generation algorithm;

controlling the adversarial generation algorithm to apply adversarial noise within the determined adverse noise limit to transform the received content file into an adversarial content file, wherein the adversarial content file maintains the equivalent representation of the received content file for the human content consumer and reduces the performance of the at least one machine learning task on the adversarial content file; and

returning the adversarial content file to the CMS.

2 . The method of claim 1 , further comprising:

in response to receiving, from the human content consumer, a request to access the received content file, transforming the received content file into the adversarial content file, wherein the adversarial content file is transmitted to the human content consumer.

3 . The method of claim 1 , wherein the extracted at least one feature is selected from the group consisting of a content type, a potential machine learning task, an adverse noise type, and the adverse noise limit.

4 . The method of claim 2 , further comprising:

in response to receiving a first request to access the received content file from a first content consumer, transforming the received content file into a first version of the adversarial content file, wherein the first version of the adversarial content file is transmitted to the first content consumer; and

in response to receiving a second request to access the received content file from a second content consumer, transforming the received content file into a second version of the adversarial content file, wherein the second version of the adversarial content file is transmitted to the second content consumer, wherein the first version of the adversarial content file and the second version of the adversarial content file represent different noisy versions of the received content file to the first content consumer and the second content consumer, respectively.

5 . The method of claim 1 , further comprising:

in response to receiving, from the human content consumer, a request to access the received content file, executing a run-time process, comprising:

retrieving, from a metadata storage device, the extracted at least one feature of the received content file using a unique identifier associated with the received content file, wherein the metadata storage device is configured to store the extracted at least one feature with the unique identifier associated with the received content file;

selecting the adversarial generation algorithm based on the extracted at least one feature of the received content file including the media type and the at least one machine learning task; and

transforming the received content file into the adversarial content file using the selected adversarial generation algorithm by executing the selected adversarial generation algorithm to generate and apply the adversarial noise subject to the adverse noise limit, the adverse noise limit constraining an amount of the adversarial noise applied to the received content file.

6 . A computer system for published content protection, comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage media, and program instructions stored on at least one of the one or more computer-readable tangible storage media for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

receiving a content file from a content management system (CMS);

extracting at least one feature from the received content file to determine, from a plurality of machine learning tasks, at least one machine learning task for a media type of the received content file;

determining an adverse noise limit by balancing competing objectives of reducing performance of the at least one machine learning task on the received content file and maintaining an equivalent representation of the received content file for a human content consumer;

selecting, based on the media type and the at least one machine learning task associated with the received content file, an adversarial generation algorithm;

controlling the adversarial generation algorithm to apply adversarial noise within the determined adverse noise limit to transform the received content file into an adversarial content file, wherein the adversarial content file maintains the equivalent representation of the received content file for the human content consumer and reduces the performance of the at least one machine learning task on the adversarial content file; and

returning the adversarial content file to the CMS.

7 . The computer system of claim 6 , further comprising:

in response to receiving, from the human content consumer, a request to access the received content file, transforming the received content file into the adversarial content file, wherein the adversarial content file is transmitted to the human content consumer.

8 . The computer system of claim 6 , wherein the extracted at least one feature is selected from the group consisting of a content type, a potential machine learning task, an adverse noise type, and the adverse noise limit.

9 . The computer system of claim 7 , further comprising:

in response to receiving a first request to access the received content file from a first content consumer, transforming the received content file into a first version of the adversarial content file, wherein the first version of the adversarial content file is transmitted to the first content consumer; and

in response to receiving a second request to access the received content file from a second content consumer, transforming the received content file into a second version of the adversarial content file, wherein the second version of the adversarial content file is transmitted to the second content consumer, wherein the first version of the adversarial content file and the second version of the adversarial content file represent different noisy versions of the received content file to the first content consumer and the second content consumer, respectively.

10 . The computer system of claim 6 , further comprising:

in response to receiving, from the human content consumer, a request to access the received content file, executing a run-time process, comprising:

retrieving, from a metadata storage device, the extracted at least one feature of the received content file using a unique identifier associated with the received content file, wherein the metadata storage device is configured to store the extracted at least one feature with the unique identifier associated with the received content file;

selecting the adversarial generation algorithm based on the extracted at least one feature of the received content file including the media type and the at least one machine learning task; and

transforming the received content file into the adversarial content file using the selected adversarial generation algorithm by executing the selected adversarial generation algorithm to generate and apply the adversarial noise subject to the adverse noise limit, the adverse noise limit constraining an amount of the adversarial noise applied to the received content file.

11 . A computer program product for published content protection, comprising:

one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable by a processor to cause the processor to perform a method comprising:

receiving a content file from a content management system (CMS);

extracting at least one feature from the received content file to determine, from a plurality of machine learning tasks, at least one machine learning task for a media type of the received content file;

determining an adverse noise limit by balancing competing objectives of reducing performance of the at least one machine learning task on the received content file and maintaining an equivalent representation of the received content file for a human content consumer;

selecting, based on the media type and the at least one machine learning task associated with the received content file, an adversarial generation algorithm;

controlling the adversarial generation algorithm to apply adversarial noise within the determined adverse noise limit to transform the received content file into an adversarial content file, wherein the adversarial content file maintains the equivalent representation of the received content file for the human content consumer and reduces the performance of the at least one machine learning task on the adversarial content file; and

returning the adversarial content file to the CMS.

12 . The computer program product of claim 11 , further comprising:

in response to receiving, from the human content consumer, a request to access the received content file, transforming the received content file into the adversarial content file, wherein the adversarial content file is transmitted to the human content consumer.

13 . The computer program product of claim 11 , wherein the extracted at least one feature is selected from the group consisting of a content type, a potential machine learning task, an adverse noise type, and the adverse noise limit.

14 . The computer program product of claim 11 , further comprising:

in response to receiving, from the human content consumer, a request to access the received content file, executing a run-time process, comprising:

retrieving, from a metadata storage device, the extracted at least one feature of the received content file using a unique identifier associated with the received content file, wherein the metadata storage device is configured to store the extracted at least one feature with the unique identifier associated with the received content file;

selecting the adversarial generation algorithm based on the extracted at least one feature of the received content file including the media type and the at least one machine learning task; and

transforming the received content file into the adversarial content file using the selected adversarial generation algorithm by executing the selected adversarial generation algorithm to generate and apply the adversarial noise subject to the adverse noise limit, the adverse noise limit constraining an amount of the adversarial noise applied to the received content file.

15 . The computer program product of claim 12 , further comprising:

in response to receiving a first request to access the received content file from a first content consumer, transforming the received content file into a first version of the adversarial content file, wherein the first version of the adversarial content file is transmitted to the first content consumer; and

in response to receiving a second request to access the received content file from a second content consumer, transforming the received content file into a second version of the adversarial content file, wherein the second version of the adversarial content file is transmitted to the second first content consumer, wherein the first version of the adversarial content file and the second version of the adversarial content file represent different noisy versions of the received content file to the first content consumer and the second content consumer, respectively.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2020
From: TUINHOF, HESSEL; LEVACHER, KILLIAN; BRAGHIN, STEFANO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 054209/0095 →
Continuity (1)
Related Publication 20220138287A1 · May 5, 2022
References Cited (27)
US 6317868B1 · Grimm · 2001 [cited by applicant]
US 7313824B1 · Bala · 2007 [cited by applicant]
US 7328453B2 · Merkle, Jr. · 2008 [cited by applicant]
US 7565697B2 · Levine · 2009 [cited by applicant]
US 9659338B2 · Lim · 2017 [cited by applicant]
US 10587584B2 · Vikramaratne et al. · 2020 [cited by examiner]
US 10679389B2 · Allen · 2020 [cited by applicant]
US 11762998B2 · Kuta et al. · 2023 [cited by examiner]
US 20050021947A1 · Doyle · 2005 [cited by applicant]
US 20080097922A1 · Davydov · 2008 [cited by applicant]
US 20090064348A1 · Bang · 2009 [cited by applicant]
US 20150019311A1 · Lee et al. · 2015 [cited by examiner]
US 20170270625A1 · Kereth · 2017 [cited by applicant]
US 20200097767A1 · Perry · 2020 [cited by examiner]
US 20200387829A1 · Kearney · 2020 [cited by examiner]
US 20210067842A1 · Revital et al. · 2021 [cited by examiner]
Rizzo et al., Text Watermarking in Social Media, Jul. 2017, ASONAM '17: Proceedings of the 2017 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining 2017, pp. 208-211. [cited by examiner]
Joon Oh et al., Adversarial Image Perturbation for Privacy Protection A Game Theory Perspective, Jul. 2017, IEEE International Conference on Computer Vision (ICCV). [cited by examiner]
Shan et al., Fawkes: Protecting Privacy against Unauthorized Deep Learning Models, Jun. 2020, USENIX Security Symposium 2020. [cited by examiner]
Hartung et al., “Multimedia Watermarking Techniques,” Proceedings of the IEEE, vol. 87, No. 7, Jul. 1999, p. 1079-1107. [cited by applicant]
Hill, “The Secretive Company That Might End Privacy as we Know It,” The New York Times, Published Jan. 18, 2020, Updated Feb. 10, 2020, https://www.nytimes.com/2020/01/18/technology/clearview-privacy-facial-recognition.… [cited by applicant]
Joon Oh et al., “Adversarial Image Perturbation for Privacy Protection a Game Theory Perspective, ”arXiv: 1703.09471v2 [cs.CV] Jul. 26, 2017, 17 pages. [cited by applicant]
Kim et al., “Digital Watermarking,” Springer, 7th International Workshop, IWDW 2008, LNCS 5450, 481 pages. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, National Institute of Standards and Technology, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Shan et al., “Fawkes: Protecting Privacy against Unauthorized Deep Learning Models,” Proc. of USENIX Security Symposium 2020, arXiv:2002.08327v2 [cs.CR] Jun. 23, 2020, 16 pages. [cited by applicant]
Song et al., “Fooling OCR Systems with Adversarial Text Images,” arXiv:1802.05385v1 [cs.LG] Feb. 15, 2018, 15 pages. [cited by applicant]
Zhang et al., “Protecting Intellectual Property of Deep Neural Networks with Watermarking,” ASIACCS '18: Proceedings of the 2018 on Asia Conference on Computer and Communications Security, May 2018, 13 pages. [cited by applicant]