{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T02:09:59Z","timestamp":1762049399368,"version":"build-2065373602"},"reference-count":36,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2022,5,3]],"date-time":"2022-05-03T00:00:00Z","timestamp":1651536000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>With the recent developments of Machine Learning as a Service (MLaaS), various privacy concerns have been raised. Having access to the user\u2019s data, an adversary can design attacks with different objectives, namely, reconstruction or attribute inference attacks. In this paper, we propose two different training frameworks for an image classification task while preserving user data privacy against the two aforementioned attacks. In both frameworks, an encoder is trained with contrastive loss, providing a superior utility-privacy trade-off. In the reconstruction attack scenario, a supervised contrastive loss was employed to provide maximal discrimination for the targeted classification task. The encoded features are further perturbed using the obfuscator module to remove all redundant information. Moreover, the obfuscator module is jointly trained with a classifier to minimize the correlation between private feature representation and original data while retaining the model utility for the classification. For the attribute inference attack, we aim to provide a representation of data that is independent of the sensitive attribute. Therefore, the encoder is trained with supervised and private contrastive loss. Furthermore, an obfuscator module is trained in an adversarial manner to preserve the privacy of sensitive attributes while maintaining the classification performance on the target attribute. The reported results on the CelebA dataset validate the effectiveness of the proposed frameworks.<\/jats:p>","DOI":"10.3390\/e24050643","type":"journal-article","created":{"date-parts":[[2022,5,3]],"date-time":"2022-05-03T08:26:35Z","timestamp":1651566395000},"page":"643","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Privacy-Preserving Image Template Sharing Using Contrastive Learning"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8103-3722","authenticated-orcid":false,"given":"Shideh","family":"Rezaeifar","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Geneva, 1227 Carouge, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0416-9674","authenticated-orcid":false,"given":"Slava","family":"Voloshynovskiy","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Geneva, 1227 Carouge, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0027-6405","authenticated-orcid":false,"given":"Meisam","family":"Asgari Jirhandeh","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Geneva, 1227 Carouge, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vitality","family":"Kinakh","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Geneva, 1227 Carouge, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,5,3]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"167425","DOI":"10.1109\/ACCESS.2020.3023084","article-title":"Privacy-Preserving Deep Learning on Machine Learning as a Service\u2014A Comprehensive Survey","volume":"8","author":"Tanuwidjaja","year":"2020","journal-title":"IEEE Access"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1188","DOI":"10.1109\/TPAMI.2018.2827389","article-title":"On the Reconstruction of Face Images from Deep Face Templates","volume":"41","author":"Mai","year":"2019","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"403","DOI":"10.1515\/popets-2016-0047","article-title":"On the (in) effectiveness of mosaicing and blurring as tools for document redaction","volume":"2016","author":"Hill","year":"2016","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"3502","DOI":"10.1109\/TIP.2012.2192126","article-title":"Modeling the performance of image restoration from motion blur","volume":"21","author":"Boracchi","year":"2012","journal-title":"IEEE Trans. Image Process."},{"key":"ref_5","unstructured":"Vishwamitra, N., Knijnenburg, B., Hu, H., and Kelly Caine, Y.P. (2017, January 21\u201326). Blur vs. block: Investigating the effectiveness of privacy-enhancing obfuscation for images. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, Honolulu, HI, USA."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Tekli, J., Al Bouna, B., Couturier, R., Tekli, G., Al Zein, Z., and Kamradt, M. (2019, January 26\u201328). A Framework for Evaluating Image Obfuscation under Deep Learning-Assisted Privacy Attacks. Proceedings of the 2019 17th International Conference on Privacy, Security and Trust (PST), Fredericton, NB, Canada.","DOI":"10.1109\/PST47121.2019.8949040"},{"key":"ref_7","unstructured":"McPherson, R., Shokri, R., and Shmatikov, V. (2016). Defeating image obfuscation with deep learning. arXiv."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Li, T., and Lin, L. (2019, January 16\u201317). AnonymousNet: Natural Face De-Identification With Measurable Privacy. Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), Long Beach, CA, USA.","DOI":"10.1109\/CVPRW.2019.00013"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Ren, Z., Lee, Y.J., and Ryoo, M.S. (2018, January 8\u201314). Learning to anonymize faces for privacy preserving action detection. Proceedings of the European Conference on Computer Vision (ECCV), Munich, Germany.","DOI":"10.1007\/978-3-030-01246-5_38"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Li, J., Han, L., Chen, R., Zhang, H., Han, B., Wang, L., and Cao, X. (2021, January 20\u201324). Identity-Preserving Face Anonymization via Adaptively Facial Attributes Obfuscation. Proceedings of the 29th ACM International Conference on Multimedia, Virtual Event, China.","DOI":"10.1145\/3474085.3475367"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"502","DOI":"10.1016\/j.procs.2013.09.310","article-title":"Homomorphic encryption","volume":"20","author":"Ogburn","year":"2013","journal-title":"Procedia Comput. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1109\/TKDE.2018.2878698","article-title":"Deep Private-Feature Extraction","volume":"32","author":"Ossia","year":"2020","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_13","unstructured":"Li, M., Lai, L., Suda, N., Chandra, V., and Pan, D.Z. (2017). Privynet: A flexible framework for privacy-preserving deep neural network training. arXiv."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Pittaluga, F., Koppal, S., and Chakrabarti, A. (2019, January 26\u201328). Learning privacy preserving encodings through adversarial training. Proceedings of the 2019 IEEE Winter Conference on Applications of Computer Vision (WACV), Waikoloa, HI, USA.","DOI":"10.1109\/WACV.2019.00089"},{"key":"ref_15","first-page":"1","article-title":"Privacy adversarial network: Representation learning for mobile data privacy","volume":"Volume 3","author":"Liu","year":"2019","journal-title":"Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies"},{"key":"ref_16","unstructured":"Li, A., Guo, J., Yang, H., Salim, F.D., and Chen, Y. (2019). DeepObfuscator: Obfuscating Intermediate Representations with Privacy-Preserving Adversarial Learning on Smartphones. arXiv."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Huang, C., Kairouz, P., Chen, X., Sankar, L., and Rajagopal, R. (2017). Context-aware generative adversarial privacy. Entropy, 19.","DOI":"10.3390\/e19120656"},{"key":"ref_18","unstructured":"Chen, T., Kornblith, S., Norouzi, M., and Hinton, G. (2020). A simple framework for contrastive learning of visual representations. International Conference on Machine Learning, PMLR."},{"key":"ref_19","unstructured":"Khosla, P., Teterwak, P., Wang, C., Sarna, A., Tian, Y., Isola, P., Maschinot, A., Liu, C., and Krishnan, D. (2020). Supervised contrastive learning. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Trans. Image Process."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Gretton, A., Bousquet, O., Smola, A., and Sch\u00f6lkopf, B. (2005). Measuring statistical dependence with Hilbert-Schmidt norms. International Conference on Algorithmic Learning Theory, Springer.","DOI":"10.1007\/11564089_7"},{"key":"ref_22","unstructured":"Gretton, A., Fukumizu, K., Teo, C.H., Song, L., Sch\u00f6lkopf, B., and Smola, A.J. (2007, January 3\u20136). A kernel statistical test of independence. Proceedings of the 20th International Conference on Neural Information Processing Systems  (NIPS 2007), Vancouver British, BC, Canada."},{"key":"ref_23","first-page":"2769","article-title":"Measuring and testing dependence by correlation of distances","volume":"35","author":"Rizzo","year":"2007","journal-title":"Ann. Stat."},{"key":"ref_24","unstructured":"Sun, J., Yao, Y., Gao, W., Xie, J., and Wang, C. (2021). Defending against Reconstruction Attack in Vertical Federated Learning. arXiv."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"122001","DOI":"10.1103\/PhysRevLett.125.122001","article-title":"Robust Jet Classifiers through Distance Correlation","volume":"125","author":"Kasieczka","year":"2020","journal-title":"Phys. Rev. Lett."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Vepakomma, P., Singh, A., Gupta, O., and Raskar, R. (2020). NoPeek: Information leakage reduction to share activations in distributed deep learning. arXiv.","DOI":"10.1109\/ICDMW51313.2020.00134"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., and Tang, X. (2015, January 7\u201313). Deep Learning Face Attributes in the Wild. Proceedings of the 2015 IEEE International Conference on Computer Vision (ICCV), Santiago, Chile.","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Ledig, C., Theis, L., Husz\u00e1r, F., Caballero, J., Cunningham, A., Acosta, A., Aitken, A., Tejani, A., Totz, J., and Wang, Z. (2017, January 21\u201326). Photo-realistic single image super-resolution using a generative adversarial network. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.19"},{"key":"ref_29","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv."},{"key":"ref_30","unstructured":"Wang, Z., Simoncelli, E.P., and Bovik, A.C. (2003, January 9\u201312). Multiscale structural similarity for image quality assessment. Proceedings of the Thrity-Seventh Asilomar Conference on Signals, Systems & Computers, Pacific Grove, CA, USA."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"He, K., Fan, H., Wu, Y., Xie, S., and Girshick, R. (2020, January 13\u201319). Momentum contrast for unsupervised visual representation learning. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Virtual Event.","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Dai, Z., Cai, B., Lin, Y., and Chen, J. (2021). UniMoCo: Unsupervised, Semi-Supervised and Full-Supervised Visual Representation Learning. arXiv.","DOI":"10.1109\/SMC53654.2022.9945500"},{"key":"ref_33","unstructured":"Papernot, N., Song, S., Mironov, I., Raghunathan, A., Talwar, K., and Erlingsson, \u00da. (2018). Scalable private learning with pate. arXiv."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Truex, S., Baracaldo, N., Anwar, A., Steinke, T., Ludwig, H., Zhang, R., and Zhou, Y. (2019, January 15). A hybrid approach to privacy-preserving federated learning. Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security, London, UK.","DOI":"10.1145\/3338501.3357370"},{"key":"ref_35","unstructured":"Dhar, P., Gleason, J., Souri, H., Castillo, C.D., and Chellappa, R. (2020). Towards gender-neutral face descriptors for mitigating bias in face recognition. arXiv."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Boutet, A., Lebrun, T., Aalmoes, J., and Baud, A. (2021). MixNN: Protection of Federated Learning against Inference Attacks by Mixing Neural Network Layers. arXiv.","DOI":"10.1145\/3528535.3565240"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/24\/5\/643\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:05:36Z","timestamp":1760137536000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/24\/5\/643"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,3]]},"references-count":36,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2022,5]]}},"alternative-id":["e24050643"],"URL":"https:\/\/doi.org\/10.3390\/e24050643","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2022,5,3]]}}}