@phdthesis{Ohphd18,
TITLE = {Image Manipulation against Learned Models Privacy and Security Implications},
AUTHOR = {Oh, Seong Joon},
LANGUAGE = {eng},
URL = {urn:nbn:de:bsz:291-scidok-ds-273042},
DOI = {10.22028/D291-27304},
SCHOOL = {Universit{\"a}t des Saarlandes},
ADDRESS = {Saarbr{\"u}cken},
YEAR = {2018},
DATE = {2018},
ABSTRACT = {Machine learning is transforming the world. Its application areas span privacy<br>sensitive and security critical tasks such as human identification and self-driving<br>cars. These applications raise privacy and security related questions that are not<br>fully understood or answered yet: Can automatic person recognisers identify people<br>in photos even when their faces are blurred? How easy is it to find an adversarial<br>input for a self-driving car that makes it drive off the road?<br>This thesis contributes one of the first steps towards a better understanding of<br>such concerns. We observe that many privacy and security critical scenarios for<br>learned models involve input data manipulation: users obfuscate their identity by<br>blurring their faces and adversaries inject imperceptible perturbations to the input<br>signal. We introduce a data manipulator framework as a tool for collectively describing<br>and analysing privacy and security relevant scenarios involving learned models.<br>A data manipulator introduces a shift in data distribution for achieving privacy or<br>security related goals, and feeds the transformed input to the target model. This<br>framework provides a common perspective on the studies presented in the thesis.<br>We begin the studies from the user{\textquoteright}s privacy point of view. We analyse the<br>efficacy of common obfuscation methods like face blurring, and show that they<br>are surprisingly ineffective against state of the art person recognition systems. We<br>then propose alternatives based on head inpainting and adversarial examples. By<br>studying the user privacy, we also study the dual problem: model security. In model<br>security perspective, a model ought to be robust and reliable against small amounts<br>of data manipulation. In both cases, data are manipulated with the goal of changing<br>the target model prediction. User privacy and model security problems can be<br>described with the same objective.<br>We then study the knowledge aspect of the data manipulation problem. The more<br>one knows about the target model, the more effective manipulations one can craft.<br>We propose a game theoretic manipulation framework to systematically represent<br>the knowledge level on the target model and derive privacy and security guarantees.<br>We then discuss ways to increase knowledge about a black-box model by only querying<br>it, deriving implications that are relevant to both privacy and security perspectives.},
}
