{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T06:46:20Z","timestamp":1773125180140,"version":"3.50.1"},"reference-count":82,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"1","license":[{"start":{"date-parts":[[2020,11,9]],"date-time":"2020-11-09T00:00:00Z","timestamp":1604880000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,1,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Image hosting platforms are a popular way to store and share images with family members and friends. However, such platforms typically have full access to images raising privacy concerns. These concerns are further exacerbated with the advent of Convolutional Neural Networks (CNNs) that can be trained on available images to automatically detect and recognize faces with high accuracy.<\/jats:p>\n               <jats:p>Recently, <jats:italic>adversarial perturbations<\/jats:italic> have been proposed as a potential defense against automated recognition and classification of images by CNNs. In this paper, we explore the practicality of adversarial perturbation-based approaches as a privacy defense against automated face recognition. Specifically, we first identify practical requirements for such approaches and then propose two practical adversarial perturbation approaches \u2013 (i) learned <jats:italic>universal ensemble perturbations (UEP)<\/jats:italic>, and (ii) <jats:italic>k-randomized transparent image overlays (k-RTIO)<\/jats:italic> that are <jats:italic>semantic adversarial perturbations<\/jats:italic>. We demonstrate how users can generate effective transferable perturbations under realistic assumptions with less effort.<\/jats:p>\n               <jats:p>We evaluate the proposed methods against state-of-theart online and offline face recognition models, Clarifai.com and DeepFace, respectively. Our findings show that UEP and k-RTIO respectively achieve more than 85% and 90% success against face recognition models. Additionally, we explore potential countermeasures that classifiers can use to thwart the proposed defenses. Particularly, we demonstrate one effective countermeasure against UEP.<\/jats:p>","DOI":"10.2478\/popets-2021-0006","type":"journal-article","created":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T11:47:01Z","timestamp":1608637621000},"page":"85-106","source":"Crossref","is-referenced-by-count":27,"title":["On the (Im)Practicality of Adversarial Perturbation for Image Privacy"],"prefix":"10.56553","volume":"2021","author":[{"given":"Arezoo","family":"Rajabi","sequence":"first","affiliation":[{"name":"Oregon State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rakesh B.","family":"Bobba","sequence":"additional","affiliation":[{"name":"Oregon State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mike","family":"Rosulek","sequence":"additional","affiliation":[{"name":"Oregon State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charles V.","family":"Wright","sequence":"additional","affiliation":[{"name":"Portland State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wu-chi","family":"Feng","sequence":"additional","affiliation":[{"name":"Portland State University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2020,11,9]]},"reference":[{"key":"2022062314354995929_j_popets-2021-0006_ref_001_w2aab3b7c12b1b6b1ab1ab1Aa","unstructured":"[1] An app that encrypts your photos from camera to cloud. https:\/\/www.wired.com\/story\/pixek-app-encrypts-photos-from-camera-to-cloud\/. Accessed: 2019-11-30."},{"key":"2022062314354995929_j_popets-2021-0006_ref_002_w2aab3b7c12b1b6b1ab1ab2Aa","unstructured":"[2] Planet selfie. https:\/\/www.businessinsider.com\/were-now-posting-a-staggering-18-billion-photos-to-social-media-every-day-2014-5. Accessed: 2019-11-30."},{"key":"2022062314354995929_j_popets-2021-0006_ref_003_w2aab3b7c12b1b6b1ab1ab3Aa","unstructured":"[3] M. Abbasi, A. Rajabi, C. Gagn\u00e9, and R. B. Bobba. Towards Dependable Deep Convolutional Neural Networks (CNNs) with Out-distribution Learning. Workshop on Dependable and Secure Machine Learning, 2018."},{"key":"2022062314354995929_j_popets-2021-0006_ref_004_w2aab3b7c12b1b6b1ab1ab4Aa","doi-asserted-by":"crossref","unstructured":"[4] N. Akhtar and A. Mian. Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 6:14410\u201314430, 2018.","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"2022062314354995929_j_popets-2021-0006_ref_005_w2aab3b7c12b1b6b1ab1ab5Aa","unstructured":"[5] A. Athalye, N. Carlini, and D. A. Wagner. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In J. G. Dy and A. Krause, editors, Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Stockholmsm\u00e4ssan, Stockholm, Sweden, July 10-15, 2018, volume 80 of Proceedings of Machine Learning Research, pages 274\u2013283. PMLR, 2018."},{"key":"2022062314354995929_j_popets-2021-0006_ref_006_w2aab3b7c12b1b6b1ab1ab6Aa","unstructured":"[6] S. Baluja and I. Fischer. Adversarial transformation networks: Learning to generate adversarial examples. arXiv preprint arXiv:1703.09387, 2017."},{"key":"2022062314354995929_j_popets-2021-0006_ref_007_w2aab3b7c12b1b6b1ab1ab7Aa","doi-asserted-by":"crossref","unstructured":"[7] M. Bertalmio, G. Sapiro, V. Caselles, and C. Ballester. Image inpainting. In Proceedings of the 27th Annual Conference on Computer Graphics and Interactive Techniques, SIGGRAPH \u201900, pages 417\u2013424, New York, NY, USA, 2000. ACM Press\/Addison-Wesley Publishing Co.10.1145\/344779.344972","DOI":"10.1145\/344779.344972"},{"key":"2022062314354995929_j_popets-2021-0006_ref_008_w2aab3b7c12b1b6b1ab1ab8Aa","doi-asserted-by":"crossref","unstructured":"[8] D. Bitouk, N. Kumar, S. Dhillon, P. Belhumeur, and S. K. Nayar. Face swapping: Automatically replacing faces in photographs. ACM Trans. Graph., 27(3):39:1\u201339:8, Aug. 2008.10.1145\/1360612.1360638","DOI":"10.1145\/1360612.1360638"},{"key":"2022062314354995929_j_popets-2021-0006_ref_009_w2aab3b7c12b1b6b1ab1ab9Aa","unstructured":"[9] C. Bourez. Course 2: build deep learning neural networks in 5 days only, 2018. http:\/\/christopher5106.github.io\/deep\/learning\/2018\/10\/20\/course-two-build-deep-learning-networks.html\u201d."},{"key":"2022062314354995929_j_popets-2021-0006_ref_010_w2aab3b7c12b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] J. F. Cardoso. Blind signal separation: statistical principles. Proceedings of the IEEE, 86(10):2009\u20132025, Oct 1998.10.1109\/5.720250","DOI":"10.1109\/5.720250"},{"key":"2022062314354995929_j_popets-2021-0006_ref_011_w2aab3b7c12b1b6b1ab1ac11Aa","doi-asserted-by":"crossref","unstructured":"[11] N. Carlini and D. Wagner. Towards evaluating the robustness of neural networks. In Security and Privacy (SP), 2017 IEEE Symposium on, pages 39\u201357. IEEE, 2017.10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"2022062314354995929_j_popets-2021-0006_ref_012_w2aab3b7c12b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] F. Carmo, J. Assis, V. Estrela, and A. Coelho. Blind signal separation and identification of mixtures of images. pages 337 \u2013 342, 12 2009.10.1109\/ACSSC.2009.5470083","DOI":"10.1109\/ACSSC.2009.5470083"},{"key":"2022062314354995929_j_popets-2021-0006_ref_013_w2aab3b7c12b1b6b1ab1ac13Aa","doi-asserted-by":"crossref","unstructured":"[13] K. Chinomi, N. Nitta, Y. Ito, and N. Babaguchi. Prisurv: Privacy protected video surveillance system using adaptive visual abstraction. In Proceedings of the 14th International Conference on Advances in Multimedia Modeling, MMM\u201908, pages 144\u2013154, Berlin, Heidelberg, 2008. Springer-Verlag.10.1007\/978-3-540-77409-9_14","DOI":"10.1007\/978-3-540-77409-9_14"},{"key":"2022062314354995929_j_popets-2021-0006_ref_014_w2aab3b7c12b1b6b1ab1ac14Aa","doi-asserted-by":"crossref","unstructured":"[14] F. Chollet. Xception: Deep learning with depthwise separable convolutions. In Proceedings of the IEEE conference on computer vision and pattern recognition, pages 1251\u20131258, 2017.10.1109\/CVPR.2017.195","DOI":"10.1109\/CVPR.2017.195"},{"key":"2022062314354995929_j_popets-2021-0006_ref_015_w2aab3b7c12b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] N. Das, M. Shanbhogue, S.-T. Chen, F. Hohman, S. Li, L. Chen, M. E. Kounavis, and D. H. Chau. Shield: Fast, practical defense and vaccination for deep learning using jpeg compression. In Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pages 196\u2013204. ACM, 2018.10.1145\/3219819.3219910","DOI":"10.1145\/3219819.3219910"},{"key":"2022062314354995929_j_popets-2021-0006_ref_016_w2aab3b7c12b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] B. Driessen and M. D\u00fcrmuth. Achieving Anonymity against Major Face Recognition Algorithms, pages 18\u201333. Springer Berlin Heidelberg, Berlin, Heidelberg, 2013.10.1007\/978-3-642-40779-6_2","DOI":"10.1007\/978-3-642-40779-6_2"},{"key":"2022062314354995929_j_popets-2021-0006_ref_017_w2aab3b7c12b1b6b1ab1ac17Aa","doi-asserted-by":"crossref","unstructured":"[17] L. Fan. Image pixelization with differential privacy. In Data and Applications Security and Privacy XXXII - 32nd Annual IFIP WG 11.3 Conference, DBSec 2018, Bergamo, Italy, July 16-18, 2018, Proceedings, pages 148\u2013162, 2018.10.1007\/978-3-319-95729-6_10","DOI":"10.1007\/978-3-319-95729-6_10"},{"key":"2022062314354995929_j_popets-2021-0006_ref_018_w2aab3b7c12b1b6b1ab1ac18Aa","doi-asserted-by":"crossref","unstructured":"[18] L. Fan. Practical image obfuscation with provable privacy. In Proceedings of IEEE International Conference on Multimedia and Expo (ICME), 2019, 2019.10.1109\/ICME.2019.00140","DOI":"10.1109\/ICME.2019.00140"},{"key":"2022062314354995929_j_popets-2021-0006_ref_019_w2aab3b7c12b1b6b1ab1ac19Aa","unstructured":"[19] R. A. Fisher, F. Yates, et al. Statistical tables for biological, agricultural and medical research. Statistical tables for biological, agricultural and medical research., (6th ed), 1963."},{"key":"2022062314354995929_j_popets-2021-0006_ref_020_w2aab3b7c12b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"[20] C. Gao, V. Chandrasekaran, K. Fawaz, and S. Jha. Face-off: Adversarial face obfuscation. arXiv preprint arXiv:2003.08861, 2020.","DOI":"10.2478\/popets-2021-0032"},{"key":"2022062314354995929_j_popets-2021-0006_ref_021_w2aab3b7c12b1b6b1ab1ac21Aa","unstructured":"[21] E.-J. Goh, H. Shacham, N. Modadugu, and D. Boneh. Sirius: Securing remote untrusted storage. In NDSS, volume 3, pages 131\u2013145, 2003."},{"key":"2022062314354995929_j_popets-2021-0006_ref_022_w2aab3b7c12b1b6b1ab1ac22Aa","unstructured":"[22] I. Goodfellow, Y. Bengio, and A. Courville. Deep learning. MIT press, 2016."},{"key":"2022062314354995929_j_popets-2021-0006_ref_023_w2aab3b7c12b1b6b1ab1ac23Aa","unstructured":"[23] I. Goodfellow, J. Shlens, and C. Szegedy. Explaining and harnessing adversarial examples. In International Conference on Learning Representations, 2015."},{"key":"2022062314354995929_j_popets-2021-0006_ref_024_w2aab3b7c12b1b6b1ab1ac24Aa","doi-asserted-by":"crossref","unstructured":"[24] R. Gross, E. Airoldi, B. Malin, and L. Sweeney. Integrating utility into face de-identification. In Proceedings of the 5th International Conference on Privacy Enhancing Technologies, PET\u201905, pages 227\u2013242, Berlin, Heidelberg, 2006. Springer-Verlag.10.1007\/11767831_15","DOI":"10.1007\/11767831_15"},{"key":"2022062314354995929_j_popets-2021-0006_ref_025_w2aab3b7c12b1b6b1ab1ac25Aa","doi-asserted-by":"crossref","unstructured":"[25] R. Gross, L. Sweeney, J. Cohn, F. Torre, and S. Baker. Face de-identification. Protecting Privacy in Video Surveillance, pages 129\u2013146, 2009.10.1007\/978-1-84882-301-3_8","DOI":"10.1007\/978-1-84882-301-3_8"},{"key":"2022062314354995929_j_popets-2021-0006_ref_026_w2aab3b7c12b1b6b1ab1ac26Aa","unstructured":"[26] K. Hill. The Secretive Company That Might End Privacy as We Know It, 1\/182020."},{"key":"2022062314354995929_j_popets-2021-0006_ref_027_w2aab3b7c12b1b6b1ab1ac27Aa","doi-asserted-by":"crossref","unstructured":"[27] S. Hill, Z. Zhou, L. Saul, and H. Shacham. On the (in)effectiveness of mosaicing and blurring as tools for document redaction. Proc. Privacy Enhancing Technologies, 2016(4):403\u201317, Oct. 2016.10.1515\/popets-2016-0047","DOI":"10.1515\/popets-2016-0047"},{"key":"2022062314354995929_j_popets-2021-0006_ref_028_w2aab3b7c12b1b6b1ab1ac28Aa","doi-asserted-by":"crossref","unstructured":"[28] H. Hosseini and R. Poovendran. Semantic adversarial examples. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR) Workshops, 2018.10.1109\/CVPRW.2018.00212","DOI":"10.1109\/CVPRW.2018.00212"},{"key":"2022062314354995929_j_popets-2021-0006_ref_029_w2aab3b7c12b1b6b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"[29] H. Hosseini, B. Xiao, A. Clark, and R. Poovendran. Attacking automatic video analysis algorithms: A case study of google cloud video intelligence API. In R. A. Hallman, K. Rohloff, and V. I. Chang, editors, Proceedings of the 2017 on Multimedia Privacy and Security, MPS@CCS 2017, Dallas, TX, USA, October 30, 2017, pages 21\u201332. ACM, 2017.10.1145\/3137616.3137618","DOI":"10.1145\/3137616.3137618"},{"key":"2022062314354995929_j_popets-2021-0006_ref_030_w2aab3b7c12b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] T. Huang, G. Yang, and G. Tang. A fast two-dimensional median filtering algorithm. IEEE Transactions on Acoustics, Speech, and Signal Processing, 27(1):13\u201318, 1979.10.1109\/TASSP.1979.1163188","DOI":"10.1109\/TASSP.1979.1163188"},{"key":"2022062314354995929_j_popets-2021-0006_ref_031_w2aab3b7c12b1b6b1ab1ac31Aa","unstructured":"[31] S. Joon Oh, M. Fritz, and B. Schiele. Adversarial image perturbation for privacy protection \u2013 a game theory perspective. In The IEEE International Conference on Computer Vision (ICCV), Oct 2017."},{"key":"2022062314354995929_j_popets-2021-0006_ref_032_w2aab3b7c12b1b6b1ab1ac32Aa","doi-asserted-by":"crossref","unstructured":"[32] A. Jourabloo, X. Yin, and X. Liu. Attribute preserved face de-identification. In 2015 International Conference on Bio-metrics (ICB), pages 278\u2013285, May 2015.10.1109\/ICB.2015.7139096","DOI":"10.1109\/ICB.2015.7139096"},{"key":"2022062314354995929_j_popets-2021-0006_ref_033_w2aab3b7c12b1b6b1ab1ac33Aa","unstructured":"[33] M. Kallahalla, E. Riedel, R. Swaminathan, Q. Wang, and K. Fu. Plutus: Scalable secure file sharing on untrusted storage. In Fast, volume 3, pages 29\u201342, 2003."},{"key":"2022062314354995929_j_popets-2021-0006_ref_034_w2aab3b7c12b1b6b1ab1ac34Aa","doi-asserted-by":"crossref","unstructured":"[34] A. C. Kokaram, R. D. Morris, W. J. Fitzgerald, and P. J. W. Rayner. Interpolation of missing data in image sequences. IEEE Transactions on Image Processing, 4(11):1509\u20131519, Nov 1995.10.1109\/83.46993218291983","DOI":"10.1109\/83.469932"},{"key":"2022062314354995929_j_popets-2021-0006_ref_035_w2aab3b7c12b1b6b1ab1ac35Aa","unstructured":"[35] A. Krizhevsky, I. Sutskever, and G. E. Hinton. Imagenet classification with deep convolutional neural networks. In Advances in neural information processing systems, pages 1097\u20131105, 2012."},{"key":"2022062314354995929_j_popets-2021-0006_ref_036_w2aab3b7c12b1b6b1ab1ac36Aa","doi-asserted-by":"crossref","unstructured":"[36] A. Kurakin, I. Goodfellow, and S. Bengio. Adversarial examples in the physical world. Workshop Track of the International Conference on Learning Representations (ICLR), 2017.10.1201\/9781351251389-8","DOI":"10.1201\/9781351251389-8"},{"key":"2022062314354995929_j_popets-2021-0006_ref_037_w2aab3b7c12b1b6b1ab1ac37Aa","doi-asserted-by":"crossref","unstructured":"[37] K. Lander, V. Bruce, and H. Hill. Evaluating the effectiveness of pixelation and blurring on masking the identity of familiar faces. Applied Cognitive Psychology, 15(1):101\u2013116, 2001.10.1002\/1099-0720(200101\/02)15:1<101::AID-ACP697>3.0.CO;2-7","DOI":"10.1002\/1099-0720(200101\/02)15:1<101::AID-ACP697>3.0.CO;2-7"},{"key":"2022062314354995929_j_popets-2021-0006_ref_038_w2aab3b7c12b1b6b1ab1ac38Aa","doi-asserted-by":"crossref","unstructured":"[38] S. Lawrence, C. L. Giles, A. C. Tsoi, and A. D. Back. Face recognition: A convolutional neural-network approach. IEEE transactions on neural networks, 8(1):98\u2013113, 1997.","DOI":"10.1109\/72.554195"},{"key":"2022062314354995929_j_popets-2021-0006_ref_039_w2aab3b7c12b1b6b1ab1ac39Aa","unstructured":"[39] Y. Le and X. Yang. Tiny imagenet visual recognition challenge. CS 231N, 2015."},{"key":"2022062314354995929_j_popets-2021-0006_ref_040_w2aab3b7c12b1b6b1ab1ac40Aa","doi-asserted-by":"crossref","unstructured":"[40] T. Li and L. Lin. Anonymousnet: Natural face deidentification with measurable privacy. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR) Workshops, June 2019.10.1109\/CVPRW.2019.00013","DOI":"10.1109\/CVPRW.2019.00013"},{"key":"2022062314354995929_j_popets-2021-0006_ref_041_w2aab3b7c12b1b6b1ab1ac41Aa","doi-asserted-by":"crossref","unstructured":"[41] Y. Lin, S. Wang, Q. Lin, and F. Tang. Face swapping under large pose variations: A 3d model based approach. In 2012 IEEE International Conference on Multimedia and Expo, pages 333\u2013338, July 2012.10.1109\/ICME.2012.26","DOI":"10.1109\/ICME.2012.26"},{"key":"2022062314354995929_j_popets-2021-0006_ref_042_w2aab3b7c12b1b6b1ab1ac42Aa","unstructured":"[42] Y. Liu, X. Chen, C. Liu, and D. Song. Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770, 2016."},{"key":"2022062314354995929_j_popets-2021-0006_ref_043_w2aab3b7c12b1b6b1ab1ac43Aa","unstructured":"[43] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083, 2017."},{"key":"2022062314354995929_j_popets-2021-0006_ref_044_w2aab3b7c12b1b6b1ab1ac44Aa","doi-asserted-by":"crossref","unstructured":"[44] B. Marohn, C. V. Wright, W.-c. Feng, M. Rosulek, and R. B. Bobba. Approximate thumbnail preserving encryption. 2017.10.1145\/3137616.3137621","DOI":"10.1145\/3137616.3137621"},{"key":"2022062314354995929_j_popets-2021-0006_ref_045_w2aab3b7c12b1b6b1ab1ac45Aa","doi-asserted-by":"crossref","unstructured":"[45] M. Mathias, R. Benenson, M. Pedersoli, and L. Van Gool. Face detection without bells and whistles. In European Conference on Computer Vision, pages 720\u2013735. Springer, 2014.10.1007\/978-3-319-10593-2_47","DOI":"10.1007\/978-3-319-10593-2_47"},{"key":"2022062314354995929_j_popets-2021-0006_ref_046_w2aab3b7c12b1b6b1ab1ac46Aa","unstructured":"[46] R. McPherson, R. Shokri, and V. Shmatikov. Defeating image obfuscation with deep learning. arXiv preprint arXiv:1609.00408, 2016."},{"key":"2022062314354995929_j_popets-2021-0006_ref_047_w2aab3b7c12b1b6b1ab1ac47Aa","doi-asserted-by":"crossref","unstructured":"[47] D. Meng and H. Chen. Magnet: a two-pronged defense against adversarial examples. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 135\u2013147. ACM, 2017.10.1145\/3133956.3134057","DOI":"10.1145\/3133956.3134057"},{"key":"2022062314354995929_j_popets-2021-0006_ref_048_w2aab3b7c12b1b6b1ab1ac48Aa","doi-asserted-by":"crossref","unstructured":"[48] S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard. Universal Adversarial Perturbations. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 1765\u20131773, 2017.10.1109\/CVPR.2017.17","DOI":"10.1109\/CVPR.2017.17"},{"key":"2022062314354995929_j_popets-2021-0006_ref_049_w2aab3b7c12b1b6b1ab1ac49Aa","doi-asserted-by":"crossref","unstructured":"[49] S. M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard. Deep-fool: A simple and accurate method to fool deep neural networks. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 2574\u20132582, June 2016.10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"2022062314354995929_j_popets-2021-0006_ref_050_w2aab3b7c12b1b6b1ab1ac50Aa","doi-asserted-by":"crossref","unstructured":"[50] E. M. Newton, L. Sweeney, and B. Malin. Preserving privacy by de-identifying face images. IEEE transactions on Knowledge and Data Engineering, 17(2):232\u2013243, 2005.10.1109\/TKDE.2005.32","DOI":"10.1109\/TKDE.2005.32"},{"key":"2022062314354995929_j_popets-2021-0006_ref_051_w2aab3b7c12b1b6b1ab1ac51Aa","unstructured":"[51] H.-W. Ng and S. Winkler. A data-driven approach to cleaning large face datasets. In 2014 IEEE international conference on image processing (ICIP), pages 343\u2013347. IEEE, 2014."},{"key":"2022062314354995929_j_popets-2021-0006_ref_052_w2aab3b7c12b1b6b1ab1ac52Aa","unstructured":"[52] G. Oded. Foundations of Cryptography: Volume 2, Basic Applications. Cambridge University Press, USA, 1st edition, 2009."},{"key":"2022062314354995929_j_popets-2021-0006_ref_053_w2aab3b7c12b1b6b1ab1ac53Aa","doi-asserted-by":"crossref","unstructured":"[53] S. J. Oh, R. Benenson, M. Fritz, and B. Schiele. Faceless Person Recognition: Privacy Implications in Social Media, pages 19\u201335. Springer International Publishing, Cham, 2016.10.1007\/978-3-319-46487-9_2","DOI":"10.1007\/978-3-319-46487-9_2"},{"key":"2022062314354995929_j_popets-2021-0006_ref_054_w2aab3b7c12b1b6b1ab1ac54Aa","doi-asserted-by":"crossref","unstructured":"[54] T. Orekondy, B. Schiele, and M. Fritz. Towards a visual privacy advisor: Understanding and predicting privacy risks in images. In IEEE International Conference on Computer Vision, ICCV 2017, Venice, Italy, October 22-29, 2017, pages 3706\u20133715. IEEE Computer Society, 2017.10.1109\/ICCV.2017.398","DOI":"10.1109\/ICCV.2017.398"},{"key":"2022062314354995929_j_popets-2021-0006_ref_055_w2aab3b7c12b1b6b1ab1ac55Aa","unstructured":"[55] A. B. Pande and S. Prabha. Image blind signal separation algorithm based on fast ica. In IJCA Proceedings on International Conference on Advances in Communication and Computing Technologies 2012, number 3, pages 21\u201324. Citeseer, 2012."},{"key":"2022062314354995929_j_popets-2021-0006_ref_056_w2aab3b7c12b1b6b1ab1ac56Aa","doi-asserted-by":"crossref","unstructured":"[56] N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami. Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pages 506\u2013519. ACM, 2017.10.1145\/3052973.3053009","DOI":"10.1145\/3052973.3053009"},{"key":"2022062314354995929_j_popets-2021-0006_ref_057_w2aab3b7c12b1b6b1ab1ac57Aa","doi-asserted-by":"crossref","unstructured":"[57] O. M. Parkhi, A. Vedaldi, and A. Zisserman. Deep face recognition. In British Machine Vision Conference, 2015.10.5244\/C.29.41","DOI":"10.5244\/C.29.41"},{"key":"2022062314354995929_j_popets-2021-0006_ref_058_w2aab3b7c12b1b6b1ab1ac58Aa","unstructured":"[58] M.-R. Ra, R. Govindan, and A. Ortega. P3: Toward privacy-preserving photo sharing. In Presented as part of the 10th USENIX Symposium on Networked Systems Design and Implementation (NSDI 13), pages 515\u2013528, Lombard, IL, 2013. USENIX."},{"key":"2022062314354995929_j_popets-2021-0006_ref_059_w2aab3b7c12b1b6b1ab1ac59Aa","doi-asserted-by":"crossref","unstructured":"[59] A. RachelAbraham, A. Kethsy Prabhavathy, and J. Devi Shree. A Survey on Video Inpainting. International Journal of Computer Applications, 56(9):43\u201347, Oct. 2012.10.5120\/8923-2761","DOI":"10.5120\/8923-2761"},{"key":"2022062314354995929_j_popets-2021-0006_ref_060_w2aab3b7c12b1b6b1ab1ac60Aa","unstructured":"[60] E. Reinhard, W. Heidrich, P. Debevec, S. Pattanaik, G. Ward, and K. Myszkowski. High dynamic range imaging: acquisition, display, and image-based lighting. Morgan Kaufmann, 2010."},{"key":"2022062314354995929_j_popets-2021-0006_ref_061_w2aab3b7c12b1b6b1ab1ac61Aa","doi-asserted-by":"crossref","unstructured":"[61] O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. C. Berg, and L. Fei-Fei. ImageNet Large Scale Visual Recognition Challenge. International Journal of Computer Vision (IJCV), 115(3):211\u2013252, 2015.10.1007\/s11263-015-0816-y","DOI":"10.1007\/s11263-015-0816-y"},{"key":"2022062314354995929_j_popets-2021-0006_ref_062_w2aab3b7c12b1b6b1ab1ac62Aa","unstructured":"[62] S. Sengupta and K. J. O\u2019Brien. Facebook can id faces, but using them grows tricky. The New York Times, September 2012."},{"key":"2022062314354995929_j_popets-2021-0006_ref_063_w2aab3b7c12b1b6b1ab1ac63Aa","unstructured":"[63] S. Shan, E. Wenger, J. Zhang, H. Li, H. Zheng, and B. Y. Zhao. Fawkes: Protecting personal privacy against unauthorized deep learning models. arXiv preprint arXiv:2002.08327, 2020."},{"key":"2022062314354995929_j_popets-2021-0006_ref_064_w2aab3b7c12b1b6b1ab1ac64Aa","unstructured":"[64] Y. Sharma and P.-Y. Chen. Attacking the madry defense model with l_1-based adversarial examples. arXiv preprint arXiv:1710.10733, 2017."},{"key":"2022062314354995929_j_popets-2021-0006_ref_065_w2aab3b7c12b1b6b1ab1ac65Aa","doi-asserted-by":"crossref","unstructured":"[65] Y. Shoshitaishvili, C. Kruegel, and G. Vigna. Portrait of a privacy invasion. Proceedings on Privacy Enhancing Technologies, 2015(1):41\u201360, 2015.10.1515\/popets-2015-0004","DOI":"10.1515\/popets-2015-0004"},{"key":"2022062314354995929_j_popets-2021-0006_ref_066_w2aab3b7c12b1b6b1ab1ac66Aa","unstructured":"[66] K. Simonyan and A. Zisserman. Very deep convolutional networks for large-scale image recognition. International Conference on Learning Representations(ICLR), 2015."},{"key":"2022062314354995929_j_popets-2021-0006_ref_067_w2aab3b7c12b1b6b1ab1ac67Aa","unstructured":"[67] N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov. Dropout: A simple way to prevent neural networks from overfitting. The Journal of Machine Learning Research, 15(1):1929\u20131958, 2014."},{"key":"2022062314354995929_j_popets-2021-0006_ref_068_w2aab3b7c12b1b6b1ab1ac68Aa","doi-asserted-by":"crossref","unstructured":"[68] Z. Stone, T. Zickler, and T. Darrell. Autotagging facebook: Social network context improves photo annotation. In 2008 IEEE Computer Society Conference on Computer Vision and Pattern Recognition Workshops, pages 1\u20138, June 2008.10.1109\/CVPRW.2008.4562956","DOI":"10.1109\/CVPRW.2008.4562956"},{"key":"2022062314354995929_j_popets-2021-0006_ref_069_w2aab3b7c12b1b6b1ab1ac69Aa","doi-asserted-by":"crossref","unstructured":"[69] Q. Sun, A. Tewari, W. Xu, M. Fritz, C. Theobalt, and B. Schiele. A hybrid model for identity obfuscation by face replacement. In V. Ferrari, M. Hebert, C. Sminchisescu, and Y. Weiss, editors, Computer Vision \u2013 ECCV 2018, pages 570\u2013586, Cham, 2018. Springer International Publishing.10.1007\/978-3-030-01246-5_34","DOI":"10.1007\/978-3-030-01246-5_34"},{"key":"2022062314354995929_j_popets-2021-0006_ref_070_w2aab3b7c12b1b6b1ab1ac70Aa","doi-asserted-by":"crossref","unstructured":"[70] Y. Sun, X. Wang, and X. Tang. Deep convolutional network cascade for facial point detection. In Computer Vision and Pattern Recognition (CVPR), 2013 IEEE Conference on, pages 3476\u20133483. IEEE, 2013.10.1109\/CVPR.2013.446","DOI":"10.1109\/CVPR.2013.446"},{"key":"2022062314354995929_j_popets-2021-0006_ref_071_w2aab3b7c12b1b6b1ab1ac71Aa","doi-asserted-by":"crossref","unstructured":"[71] Z. Sun, L. Meng, and A. Ariyaeeinia. Distinguishable deidentified faces. In Automatic Face and Gesture Recognition (FG), 2015 11th IEEE International Conference and Workshops on, volume 04, pages 1\u20136, May 2015.10.1109\/FG.2015.7285019","DOI":"10.1109\/FG.2015.7285019"},{"key":"2022062314354995929_j_popets-2021-0006_ref_072_w2aab3b7c12b1b6b1ab1ac72Aa","doi-asserted-by":"crossref","unstructured":"[72] L. Sweeney. K-anonymity: A model for protecting privacy. Int. J. Uncertain. Fuzziness Knowl.-Based Syst., 10(5):557\u2013570, Oct. 2002.10.1142\/S0218488502001648","DOI":"10.1142\/S0218488502001648"},{"key":"2022062314354995929_j_popets-2021-0006_ref_073_w2aab3b7c12b1b6b1ab1ac73Aa","unstructured":"[73] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus. Intriguing properties of neural networks. In International Conference on Learning Representations, 2014."},{"key":"2022062314354995929_j_popets-2021-0006_ref_074_w2aab3b7c12b1b6b1ab1ac74Aa","doi-asserted-by":"crossref","unstructured":"[74] K. Tajik, A. Gunasekaran, R. Dutta, B. Ellis, R. B. Bobba, M. Rosulek, C. V. Wright, and W. Feng. Balancing image privacy and usability with thumbnail-preserving encryption. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019, San Diego, California, USA, February 24-27, 2019, 2019.10.14722\/ndss.2019.23432","DOI":"10.14722\/ndss.2019.23432"},{"key":"2022062314354995929_j_popets-2021-0006_ref_075_w2aab3b7c12b1b6b1ab1ac75Aa","doi-asserted-by":"crossref","unstructured":"[75] S. Tansuriyavong and S.-i. Hanaki. Privacy protection by concealing persons in circumstantial video image. In Proceedings of the 2001 Workshop on Perceptive User Interfaces, PUI \u201901, pages 1\u20134, New York, NY, USA, 2001. ACM.10.1145\/971478.971519","DOI":"10.1145\/971478.971519"},{"key":"2022062314354995929_j_popets-2021-0006_ref_076_w2aab3b7c12b1b6b1ab1ac76Aa","doi-asserted-by":"crossref","unstructured":"[76] M. Tierney, I. Spiro, C. Bregler, and L. Subramanian. Cryptagram: Photo privacy for online social media. In Proceedings of the First ACM Conference on Online Social Networks, COSN \u201913, pages 75\u201388, New York, NY, USA, 2013. ACM.10.1145\/2512938.2512939","DOI":"10.1145\/2512938.2512939"},{"key":"2022062314354995929_j_popets-2021-0006_ref_077_w2aab3b7c12b1b6b1ab1ac77Aa","doi-asserted-by":"crossref","unstructured":"[77] L. Wolf, T. Hassner, and I. Maoz. Face recognition in unconstrained videos with matched background similarity. In Computer Vision and Pattern Recognition (CVPR), 2011 IEEE Conference on, pages 529\u2013534. IEEE, 2011.10.1109\/CVPR.2011.5995566","DOI":"10.1109\/CVPR.2011.5995566"},{"key":"2022062314354995929_j_popets-2021-0006_ref_078_w2aab3b7c12b1b6b1ab1ac78Aa","doi-asserted-by":"crossref","unstructured":"[78] C. V. Wright, W.-c. Feng, and F. Liu. Thumbnail-preserving encryption for jpeg. In Proceedings of the 3rd ACM Workshop on Information Hiding and Multimedia Security, IH&#38;MMSec \u201915, pages 141\u2013146, New York, NY, USA, 2015. ACM.10.1145\/2756601.2756618","DOI":"10.1145\/2756601.2756618"},{"key":"2022062314354995929_j_popets-2021-0006_ref_079_w2aab3b7c12b1b6b1ab1ac79Aa","doi-asserted-by":"crossref","unstructured":"[79] Z. Wu, Z. Wang, Z. Wang, and H. Jin. Towards privacy-preserving visual recognition via adversarial training: A pilot study. In V. Ferrari, M. Hebert, C. Sminchisescu, and Y. Weiss, editors, Computer Vision \u2013 ECCV 2018, pages 627\u2013645, Cham, 2018. Springer International Publishing.10.1007\/978-3-030-01270-0_37","DOI":"10.1007\/978-3-030-01270-0_37"},{"key":"2022062314354995929_j_popets-2021-0006_ref_080_w2aab3b7c12b1b6b1ab1ac80Aa","doi-asserted-by":"crossref","unstructured":"[80] W. Xu, D. Evans, and Y. Qi. Feature squeezing: Detecting adversarial examples in deep neural networks. Network and Distributed System Security Symposium, 2018.10.14722\/ndss.2018.23198","DOI":"10.14722\/ndss.2018.23198"},{"key":"2022062314354995929_j_popets-2021-0006_ref_081_w2aab3b7c12b1b6b1ab1ac81Aa","unstructured":"[81] Q. A. Zhao and J. T. Stasko. The awareness-privacy trade-off in video supported informal awareness: A study of image-filtering based techniques. Technical report, Goergia Tech, http:\/\/hdl.handle.net\/1853\/3452, 1998."},{"key":"2022062314354995929_j_popets-2021-0006_ref_082_w2aab3b7c12b1b6b1ab1ac82Aa","doi-asserted-by":"crossref","unstructured":"[82] Zhou Wang, A. C. Bovik, H. R. Sheikh, and E. P. Simon-celli. Image quality assessment: from error visibility to structural similarity. IEEE Transactions on Image Processing, 13(4):600\u2013612, 2004.","DOI":"10.1109\/TIP.2003.819861"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/content.sciendo.com\/view\/journals\/popets\/2021\/1\/article-p85.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0006","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:31:18Z","timestamp":1658334678000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0006.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,9]]},"references-count":82,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2020,11,9]]},"published-print":{"date-parts":[[2021,1,1]]}},"alternative-id":["10.2478\/popets-2021-0006"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0006","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,11,9]]}}}