{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,20]],"date-time":"2026-08-20T15:04:37Z","timestamp":1787238277699,"version":"build-2736575974"},"reference-count":49,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2022,1,8]],"date-time":"2022-01-08T00:00:00Z","timestamp":1641600000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation of U.S.","doi-asserted-by":"crossref","award":["1704287, 1829674, 1912753, and 2011845"],"award-info":[{"award-number":["1704287, 1829674, 1912753, and 2011845"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Knowl. Discov. Data"],"published-print":{"date-parts":[[2022,8,31]]},"abstract":"<jats:p>Multi-label image recognition has been an indispensable fundamental component for many real computer vision applications. However, a severe threat of privacy leakage in multi-label image recognition has been overlooked by existing studies. To fill this gap, two privacy-preserving models, Privacy-Preserving Multi-label Graph Convolutional Networks (P2-ML-GCN) and Robust P2-ML-GCN (RP2-ML-GCN), are developed in this article, where differential privacy mechanism is implemented on the model\u2019s outputs so as to defend black-box attack and avoid large aggregated noise simultaneously. In particular, a regularization term is exploited in the loss function of RP2-ML-GCN to increase the model prediction accuracy and robustness. After that, a proper differential privacy mechanism is designed with the intention of decreasing the bias of loss function in P2-ML-GCN and increasing prediction accuracy. Besides, we analyze that a bounded global sensitivity can mitigate excessive noise\u2019s side effect and obtain a performance improvement for multi-label image recognition in our models. Theoretical proof shows that our two models can guarantee differential privacy for model\u2019s outputs, weights and input features while preserving model robustness. Finally, comprehensive experiments are conducted to validate the advantages of our proposed models, including the implementation of differential privacy on model\u2019s outputs, the incorporation of regularization term into loss function, and the adoption of bounded global sensitivity for multi-label image recognition.<\/jats:p>","DOI":"10.1145\/3491231","type":"journal-article","created":{"date-parts":[[2022,1,8]],"date-time":"2022-01-08T15:51:00Z","timestamp":1641657060000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["Privacy-Preserving Mechanisms for Multi-Label Image Recognition"],"prefix":"10.1145","volume":"16","author":[{"given":"Honghui","family":"Xu","sequence":"first","affiliation":[{"name":"Georgia State University, Department of Computer Science, Atlanta, GA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6017-975X","authenticated-orcid":false,"given":"Zhipeng","family":"Cai","sequence":"additional","affiliation":[{"name":"Georgia State University, Department of Computer Science, Atlanta, GA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Li","sequence":"additional","affiliation":[{"name":"Georgia State University, Department of Computer Science, Atlanta, GA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,1,8]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_1_3_2","first-page":"263","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Amin Kareem","year":"2019","unstructured":"Kareem Amin, Alex Kulesza, Andres Munoz, and Sergei Vassilvtiskii. 2019. Bounding user contributions: A bias-variance trade-off in differential privacy. In Proceedings of the International Conference on Machine Learning. 263\u2013271."},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1161\/CIRCOUTCOMES.118.005122"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.173"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3459992"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00986"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00532"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2006.870353"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-009-0275-4"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00139"},{"key":"e_1_3_1_13_2","article-title":"Chest X-rays classification: A multi-label and fine-grained problem","author":"Ge Zongyuan","year":"2018","unstructured":"Zongyuan Ge, Dwarikanath Mahapatra, Suman Sedai, Rahil Garnavi, and Rajib Chakravorty. 2018. Chest X-rays classification: A multi-label and fine-grained problem. arXiv:1807.07247. Retrieved from https:\/\/arxiv.org\/abs\/1807.07247.","journal-title":"arXiv:1807.07247"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10605-2_29"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1137\/090756090"},{"key":"e_1_3_1_19_2","volume-title":"Proceedings of the 5th International Conference on Learning Representations","author":"Kipf Thomas N.","year":"2017","unstructured":"Thomas N. Kipf and Max Welling. 2017. Semi-supervised classification with graph convolutional networks. In Proceedings of the 5th International Conference on Learning Representations."},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46466-4_41"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"e_1_3_1_22_2","unstructured":"Magnus Lundmark and Carl-Johan Dahlman. 2017. Differential Privacy and Machine Learning: Calculating Sensitivity with Generated Data Sets. Master\u2019s thesis. Royal Institute of Technology (KTH) Stockholm Sweden."},{"key":"e_1_3_1_23_2","article-title":"A general approach to adding differential privacy to iterative training procedures","author":"McMahan H. Brendan","year":"2018","unstructured":"H. Brendan McMahan, Galen Andrew, Ulfar Erlingsson, Steve Chien, Ilya Mironov, Nicolas Papernot, and Peter Kairouz. 2018. A general approach to adding differential privacy to iterative training procedures. arXiv:1812.06210. Retrieved from https:\/\/arxiv.org\/abs\/1812.06210.","journal-title":"arXiv:1812.06210"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/3015812.3016005"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2017.48"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1090\/S0002-9939-1993-1151815-2"},{"issue":"1","key":"e_1_3_1_28_2","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model.","volume":"11","author":"Rahman Md Atiqur","year":"2018","unstructured":"Md Atiqur Rahman, Tanzila Rahman, Robert Lagani\u00e8re, Noman Mohammed, and Yang Wang. 2018. Membership inference attack against differentially private deep learning model. Transactions on Data Privacy 11, 1 (2018), 61\u201379.","journal-title":"Transactions on Data Privacy"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.174"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_1_31_2","volume-title":"Proceedings of the 3rd International Conference on Learning Representations (ICLR\u201915)","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. In Proceedings of the 3rd International Conference on Learning Representations (ICLR\u201915)."},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2663337"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_1_34_2","article-title":"Towards demystifying membership inference attacks","author":"Truex Stacey","year":"2018","unstructured":"Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Lei Yu, and Wenqi Wei. 2018. Towards demystifying membership inference attacks. arXiv:1807.09173. Retrieved from https:\/\/arxiv.org\/abs\/1807.09173.","journal-title":"arXiv:1807.09173"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01083"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.251"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.58"},{"key":"e_1_3_1_38_2","article-title":"RPC: A large-scale retail product checkout dataset","author":"Wei Xiu-Shen","year":"2019","unstructured":"Xiu-Shen Wei, Quan Cui, Lei Yang, Peng Wang, and Lingqiao Liu. 2019. RPC: A large-scale retail product checkout dataset. arXiv:1901.07249. Retrieved from https:\/\/arxiv.org\/abs\/1901.07249.","journal-title":"arXiv:1901.07249"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00025"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3035918.3064047"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCSNT47585.2019.8962514"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3061065"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2897874"},{"key":"e_1_3_1_44_2","article-title":"Audio-visual autoencoding for privacy-preserving video streaming","author":"Xu Honghui","year":"2021","unstructured":"Honghui Xu, Zhipeng Cai, Daniel Takabi, and Wei Li. 2021. Audio-visual autoencoding for privacy-preserving video streaming. IEEE Internet of Things Journal (2021).","journal-title":"IEEE Internet of Things Journal"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1093\/aob\/mcg029"},{"key":"e_1_3_1_46_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Yoon Jinsung","year":"2019","unstructured":"Jinsung Yoon, James Jordon, and Mihaela van der Schaar. 2019. PATE-GAN: Generating synthetic data with differential privacy guarantees. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_47_2","volume-title":"the Processings of the 7th International Conference on Learning Representations (ICLR\u201919)","author":"Zhang Guodong","year":"2018","unstructured":"Guodong Zhang, Chaoqi Wang, Bowen Xu, and Roger Grosse. 2018. Three mechanisms of weight decay regularization. In the Processings of the 7th International Conference on Learning Representations (ICLR\u201919)."},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.3010335"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.219"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00159"}],"container-title":["ACM Transactions on Knowledge Discovery from Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3491231","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3491231","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T14:09:19Z","timestamp":1750169359000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3491231"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,8]]},"references-count":49,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,8,31]]}},"alternative-id":["10.1145\/3491231"],"URL":"https:\/\/doi.org\/10.1145\/3491231","relation":{},"ISSN":["1556-4681","1556-472X"],"issn-type":[{"value":"1556-4681","type":"print"},{"value":"1556-472X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,8]]},"assertion":[{"value":"2020-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-01-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}