As a rapidly growing research field over the past decade, deep learning technology relies on large amounts of data to achieve better performance. However, privacy concerns arise due to the potential leakage of sensitive information in training data. Recent studies have shown that deep learning models are susceptible to various privacy attacks, leading to the exposure of their training data. Existing methods have high requirements for computational power. In this paper, we are proposing a lightweight transformation-based method to protect training data privacy. Our experimental results show that deep learning models trained on images processed by our method can still achieve acceptable accuracy. Additionally, we explored the reasons for the feasibility of this method and conducted a security and privacy analysis of the proposed approach, demonstrating that attackers cannot recover the images from the transformed training set or obtain usable image information.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Lightweight Transformation Method for Privacy Protection in Image Classification

  • Jiahao Liu,
  • Wei Ren,
  • Yifei Cai,
  • Wenmao Liu,
  • Xianchao Zhang,
  • Tianqing Zhu

摘要

As a rapidly growing research field over the past decade, deep learning technology relies on large amounts of data to achieve better performance. However, privacy concerns arise due to the potential leakage of sensitive information in training data. Recent studies have shown that deep learning models are susceptible to various privacy attacks, leading to the exposure of their training data. Existing methods have high requirements for computational power. In this paper, we are proposing a lightweight transformation-based method to protect training data privacy. Our experimental results show that deep learning models trained on images processed by our method can still achieve acceptable accuracy. Additionally, we explored the reasons for the feasibility of this method and conducted a security and privacy analysis of the proposed approach, demonstrating that attackers cannot recover the images from the transformed training set or obtain usable image information.