arrow
Return

Interpretable Rotation-Equivariant Multiary-Valued Network for Attribute Obfuscation

delete2025-08-15
delete0
PRE
AI
Q
Quanshi Zhang
张浩 (Hao Zhang)
Y
Yi-Ting Chen
Q
Qihan Ren
J
Jie Ren
X
Xu Cheng
L
Liyao Xiang
DOI:10.1109/TPAMI.2025.3599592delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
This paper focuses on the problem of preventing information leakage in neural networks, <i>i.e.</i>, assuming that attackers have obtained intermediate-layer features of a neural network, and preventing attackers from inverting these features to the input with private information. We propose a generic method to slightly revise each arbitrary traditional neural network into a multiary-valued rotation-equivariant neural network (RENN) for preventing information leakage. Specifically, we convert real-valued features in the network into multi-ary features, and each element in the feature vector is a multi-ary number. We hide the input information into a certain phase of the multi-ary feature, and rotate the multi-ary feature for attribute obfuscation in the encryption process. The rotation axis and angle can be considered as the private key. In this way, even when attackers have obtained network parameters and intermediate-layer features, they still cannot extract input information without knowing the rotation information. More crucially, the encryption operation does not damage the spatial correlations between features, so that the encrypted features can be easily processed by convolution operations in the neural network without difficulties. In order to implement successful encryption and decryption, the RENN is designed to satisfy the rotation equivariance property. To this end, we propose a set of rules to revise classic operations in the neural network to ensure the rotation equivariance property. Besides, we prove that the <inline-formula><tex-math notation="LaTeX">$d$</tex-math></inline-formula>-ary RENN is downward compatible with the <inline-formula><tex-math notation="LaTeX">$d^{\prime }$</tex-math></inline-formula>-ary RENN when <inline-formula><tex-math notation="LaTeX">$d^{\prime }&lt; d$</tex-math></inline-formula>. In experiments, the RENN significantly boosts the capacity of preventing information leakage, yet with only mild degradation of classification accuracy, compared to traditional neural networks. Besides, the computational cost is much less than the homomorphic encryption.
Keywords:
Convolutional neural networks
privacy protection
preventing information leakage

Journal

IEEE Transactions on Pattern Analysis and Machine Intelligence cover
IEEE Transactions on Pattern Analysis and Machine Intelligence
IF:
18.6
Papers:
831
Citations:
9.8W

Organization

S
shanghai jiao tong university
Scholars:
15.3W
Papers: 11.5W
Citations: 159