SlideShare a Scribd company logo
Pixel Privacy at MediaEval 2018
Martha Larson, Zhuoran Liu, Simon Brugman, Zhengyu Zhao
MediaEval 2018 Workshop, EURECOM, Sophia Antipolis, France
31 October 2018
First some
MediaEval history
Geo-location Estimation: Placing Task
• Given a multimedia item and its associated metadata, predict a geo-location.
• Data are images and videos drawn from Flickr.
Placing Task: Year-to-year insights
• 2010: (5k/5k)* move from images to videos, language modeling works well,
uploader ID a key indicator.
• 2011: (10k/5k) first use of audio, granularity of regions is critical.
• 2012: (15k/5k) user models, motion features, two-stage approaches.
• 2013: (9M/262k) eliminated uploader ID, confidence prediction, retrieval
approaches.
• 2014: (5M/500k) YFCC100M data set, graph approaches, again external
knowledge resources hurt.
• 2015: (5M/1M) 8% correct visual, 27% correct multimodal.
*(training data size/test data size)
M. Larson, P. Kelm, A. Rae, C. Hauff, B. Thomee, M. Trevisiol, J. Choi, O. van Laere, S. Schockaert, G. J. F.
Jones, P. Serdyukov, V. Murdock, and G. Friedland. The benchmark as a research catalyst: Charting the
progress of geo-prediction for social multimedia. In J. Choi and G. Friedland, editors, Multimodal Location
Estimation of Videos and Images. Springer, pp. 5-40. 2015.
User Images on Social Media
User Images on Social Media
User Images on Social Media
Gerald Friedland, Symeon Papadopoulos, Julia Bernd, and Yiannis Kompatsiaris. 2016. Multimedia Privacy. In Proceedings of the 2016
ACM on Multimedia Conference (MM '16). ACM, New York, NY, USA, 1479-1480.
Cybercasing: Beware of large-scale automatic image mining
Protecting Privacy
is a Problem
How can we
nudge users to
protect
themselves?
Example images whose locations are protected
by an Instagram filter
Jaeyoung Choi, Martha Larson, Xinchao Li, Kevin Li, Gerald Friedland, and Alan Hanjalic.
2017. The Geo-Privacy Bonus of Popular Photo Enhancements. ACM ICMR 2017.
Pixel Privacy at MediaEval 2018
Task Goal:
• Increasing image appeal,
• while blocking automatic inference of sensitive scene information.
Evaluation Criteria:
• Protection: % of images whose location categories can no longer be inferred by
the “attack algorithm”. (Attack algorithm taken to be: ResNet50 classifier trained
on the training set of the Places365-Standard dataset.)
• Appeal: Degree to which the images are enhanced from the point of view of
users.
Novelty:
We combine work on adversarial examples and image enhancement, which have
been previously studied separately.
B. Zhou, A. Lapedriza, A. Khosla, A. Oliva and A. Torralba, "Places: A 10 Million Image Database for Scene Recognition," in IEEE
Transactions on Pattern Analysis and Machine Intelligence, vol. 40, no. 6, pp. 1452-1464, 1 June 2018.
Pixel Privacy at MediaEval 2018
Task Data: Places365-Standard dataset
Sensitive scene information: Taken to be the class labels of classes in
Places365-Standard dataset associated privacy criteria (that we defined):
• Places in the home,
• Places far away from the home (typical vacation places),
• Places typical for children,
• Places related to religion,
• Places related to people's health,
• Places related to alcohol consumption,
• Places in which people do not typically wear street clothes,
• Places related to people's living conditions/income,
• Places related to security, Places related to military.
B. Zhou, A. Lapedriza, A. Khosla, A. Oliva and A. Torralba, "Places: A 10 Million Image Database for Scene Recognition," in IEEE
Transactions on Pattern Analysis and Machine Intelligence, vol. 40, no. 6, pp. 1452-1464, 1 June 2018.
http://places.csail.mit.edu/cellImgs/b_bedroom.jpg
Universal Adversarial Perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal
adversarial perturbations. CVPR 2017.
Universal Adversarial Perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal
adversarial perturbations. CVPR 2017.
Example images whose scene categories are protected style transfer
Yang Chen, Yu-Kun Lai, and Yong-Jin Liu. CartoonGAN: Generative Adversarial Networks for Photo
Cartoonization. CVPR 2018.
Example images whose scene categories are protected style transfer
Yang Chen, Yu-Kun Lai, and Yong-Jin Liu. CartoonGAN: Generative Adversarial Networks for Photo
Cartoonization. CVPR 2018.
Baseline: Protection with CartoonGAN
Protection: About 60% of the images that can be recognized are protected.
Appeal: CartoonGAN designed to appeal (appeal not specifically tested.)
Outlook
• What is appeal?
• Protecting other types of sensitive information?
• Protecting under less-constrained conditions:
- Protecting against other attacks?
- Protecting in the case of which negative images?
• Can we keep up in the “arms race” against classifiers trained on protected
images?
• Detection vs. Protection: Can the task help to restore the balance in effort that is
invested in research?

More Related Content

PPTX
University of Nottingham - NGI Geospatial Science Example Activities
PDF
Crowdsourced camera trapping for ecology & citizen science
PPT
ppt
PDF
Protect Social Connection Using Privacy Predictive Algorithm
PDF
Adversarial Photo Frame: Concealing Sensitive Scene Information in a User-Acc...
PPTX
A Semantic Context-aware Privacy Model for FaceBlock
PDF
iaetsd Adaptive privacy policy prediction for user uploaded images on
PPTX
Multimedia Privacy
University of Nottingham - NGI Geospatial Science Example Activities
Crowdsourced camera trapping for ecology & citizen science
ppt
Protect Social Connection Using Privacy Predictive Algorithm
Adversarial Photo Frame: Concealing Sensitive Scene Information in a User-Acc...
A Semantic Context-aware Privacy Model for FaceBlock
iaetsd Adaptive privacy policy prediction for user uploaded images on
Multimedia Privacy

Similar to MediaEval 2018 Pixel Privacy: Task Overview (20)

PDF
Implementation of Privacy Policy Specification System for User Uploaded Image...
PDF
Encry-Pixel: A Novel Approach Towards Locational Privacy Enhancement in Images
PDF
Semantic and Sensitivity Aware Location-Privacy Protection for the Internet o...
DOCX
PRIVACY POLICY INFERENCE OF USER-UPLOADED IMAGES ON CONTENT SHARING SITES
DOCX
PRIVACY POLICY INFERENCE OF USER-UPLOADED IMAGES ON CONTENT SHARING SITES - I...
DOCX
Privacy policy inference of user uploaded
DOCX
Privacy policy inference of user uploaded
PDF
A Survey On Privacy Policy Inference for Social Images
PDF
Privacy Policy Inference of User-Uploaded Images on Content Sharing Sites
PDF
Privacy Policy Inference of User-Uploaded Images on Content Sharing Sites
PPTX
HCMUS at Pixel Privacy 2019: Scene Category Protection with Back Propagation ...
PDF
Urban Planning Using APIS
PDF
Towards Secure and Interpretable AI: Scalable Methods, Interactive Visualizat...
PPTX
A brief introduction to extracting information from images
PDF
GeoVisualization for Understanding Cities
PDF
Harnessing AI for Data Privacy through a Multidimensional Framework
PDF
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
PDF
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
PDF
Harnessing AI for Data Privacy through a Multidimensional Framework
Implementation of Privacy Policy Specification System for User Uploaded Image...
Encry-Pixel: A Novel Approach Towards Locational Privacy Enhancement in Images
Semantic and Sensitivity Aware Location-Privacy Protection for the Internet o...
PRIVACY POLICY INFERENCE OF USER-UPLOADED IMAGES ON CONTENT SHARING SITES
PRIVACY POLICY INFERENCE OF USER-UPLOADED IMAGES ON CONTENT SHARING SITES - I...
Privacy policy inference of user uploaded
Privacy policy inference of user uploaded
A Survey On Privacy Policy Inference for Social Images
Privacy Policy Inference of User-Uploaded Images on Content Sharing Sites
Privacy Policy Inference of User-Uploaded Images on Content Sharing Sites
HCMUS at Pixel Privacy 2019: Scene Category Protection with Back Propagation ...
Urban Planning Using APIS
Towards Secure and Interpretable AI: Scalable Methods, Interactive Visualizat...
A brief introduction to extracting information from images
GeoVisualization for Understanding Cities
Harnessing AI for Data Privacy through a Multidimensional Framework
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
HARNESSING AI FOR DATA PRIVACY THROUGH A MULTIDIMENSIONAL FRAMEWORK
Harnessing AI for Data Privacy through a Multidimensional Framework
Ad

More from multimediaeval (20)

PPTX
Classification of Strokes in Table Tennis with a Three Stream Spatio-Temporal...
PDF
HCMUS at MediaEval 2020: Ensembles of Temporal Deep Neural Networks for Table...
PDF
Sports Video Classification: Classification of Strokes in Table Tennis for Me...
PDF
Predicting Media Memorability from a Multimodal Late Fusion of Self-Attention...
PPTX
Essex-NLIP at MediaEval Predicting Media Memorability 2020 Task
PDF
Overview of MediaEval 2020 Predicting Media Memorability task: What Makes a V...
PDF
Fooling an Automatic Image Quality Estimator
PDF
Fooling Blind Image Quality Assessment by Optimizing a Human-Understandable C...
PDF
Pixel Privacy: Quality Camouflage for Social Images
PDF
HCMUS at MediaEval 2020:Image-Text Fusion for Automatic News-Images Re-Matching
PPTX
Efficient Supervision Net: Polyp Segmentation using EfficientNet and Attentio...
PDF
HCMUS at Medico Automatic Polyp Segmentation Task 2020: PraNet and ResUnet++ ...
PDF
Depth-wise Separable Atrous Convolution for Polyps Segmentation in Gastro-Int...
PPTX
Deep Conditional Adversarial learning for polyp Segmentation
PPTX
A Temporal-Spatial Attention Model for Medical Image Detection
PPTX
HCMUS-Juniors 2020 at Medico Task in MediaEval 2020: Refined Deep Neural Netw...
PDF
Fine-tuning for Polyp Segmentation with Attention
PPTX
Bigger Networks are not Always Better: Deep Convolutional Neural Networks for...
PPTX
Insights for wellbeing: Predicting Personal Air Quality Index using Regressio...
PDF
Use Visual Features From Surrounding Scenes to Improve Personal Air Quality ...
Classification of Strokes in Table Tennis with a Three Stream Spatio-Temporal...
HCMUS at MediaEval 2020: Ensembles of Temporal Deep Neural Networks for Table...
Sports Video Classification: Classification of Strokes in Table Tennis for Me...
Predicting Media Memorability from a Multimodal Late Fusion of Self-Attention...
Essex-NLIP at MediaEval Predicting Media Memorability 2020 Task
Overview of MediaEval 2020 Predicting Media Memorability task: What Makes a V...
Fooling an Automatic Image Quality Estimator
Fooling Blind Image Quality Assessment by Optimizing a Human-Understandable C...
Pixel Privacy: Quality Camouflage for Social Images
HCMUS at MediaEval 2020:Image-Text Fusion for Automatic News-Images Re-Matching
Efficient Supervision Net: Polyp Segmentation using EfficientNet and Attentio...
HCMUS at Medico Automatic Polyp Segmentation Task 2020: PraNet and ResUnet++ ...
Depth-wise Separable Atrous Convolution for Polyps Segmentation in Gastro-Int...
Deep Conditional Adversarial learning for polyp Segmentation
A Temporal-Spatial Attention Model for Medical Image Detection
HCMUS-Juniors 2020 at Medico Task in MediaEval 2020: Refined Deep Neural Netw...
Fine-tuning for Polyp Segmentation with Attention
Bigger Networks are not Always Better: Deep Convolutional Neural Networks for...
Insights for wellbeing: Predicting Personal Air Quality Index using Regressio...
Use Visual Features From Surrounding Scenes to Improve Personal Air Quality ...
Ad

Recently uploaded (20)

PDF
IFIT3 RNA-binding activity primores influenza A viruz infection and translati...
PPTX
2. Earth - The Living Planet earth and life
PPTX
Taita Taveta Laboratory Technician Workshop Presentation.pptx
PPTX
2Systematics of Living Organisms t-.pptx
PDF
bbec55_b34400a7914c42429908233dbd381773.pdf
PPTX
Comparative Structure of Integument in Vertebrates.pptx
PPTX
Derivatives of integument scales, beaks, horns,.pptx
PPTX
neck nodes and dissection types and lymph nodes levels
PPT
The World of Physical Science, • Labs: Safety Simulation, Measurement Practice
PPTX
famous lake in india and its disturibution and importance
PDF
AlphaEarth Foundations and the Satellite Embedding dataset
PDF
Sciences of Europe No 170 (2025)
PDF
Mastering Bioreactors and Media Sterilization: A Complete Guide to Sterile Fe...
PPT
protein biochemistry.ppt for university classes
PDF
The scientific heritage No 166 (166) (2025)
PPTX
ANEMIA WITH LEUKOPENIA MDS 07_25.pptx htggtftgt fredrctvg
PPTX
Microbiology with diagram medical studies .pptx
PPTX
DRUG THERAPY FOR SHOCK gjjjgfhhhhh.pptx.
PPTX
The KM-GBF monitoring framework – status & key messages.pptx
PPT
POSITIONING IN OPERATION THEATRE ROOM.ppt
IFIT3 RNA-binding activity primores influenza A viruz infection and translati...
2. Earth - The Living Planet earth and life
Taita Taveta Laboratory Technician Workshop Presentation.pptx
2Systematics of Living Organisms t-.pptx
bbec55_b34400a7914c42429908233dbd381773.pdf
Comparative Structure of Integument in Vertebrates.pptx
Derivatives of integument scales, beaks, horns,.pptx
neck nodes and dissection types and lymph nodes levels
The World of Physical Science, • Labs: Safety Simulation, Measurement Practice
famous lake in india and its disturibution and importance
AlphaEarth Foundations and the Satellite Embedding dataset
Sciences of Europe No 170 (2025)
Mastering Bioreactors and Media Sterilization: A Complete Guide to Sterile Fe...
protein biochemistry.ppt for university classes
The scientific heritage No 166 (166) (2025)
ANEMIA WITH LEUKOPENIA MDS 07_25.pptx htggtftgt fredrctvg
Microbiology with diagram medical studies .pptx
DRUG THERAPY FOR SHOCK gjjjgfhhhhh.pptx.
The KM-GBF monitoring framework – status & key messages.pptx
POSITIONING IN OPERATION THEATRE ROOM.ppt

MediaEval 2018 Pixel Privacy: Task Overview

  • 1. Pixel Privacy at MediaEval 2018 Martha Larson, Zhuoran Liu, Simon Brugman, Zhengyu Zhao MediaEval 2018 Workshop, EURECOM, Sophia Antipolis, France 31 October 2018
  • 3. Geo-location Estimation: Placing Task • Given a multimedia item and its associated metadata, predict a geo-location. • Data are images and videos drawn from Flickr.
  • 4. Placing Task: Year-to-year insights • 2010: (5k/5k)* move from images to videos, language modeling works well, uploader ID a key indicator. • 2011: (10k/5k) first use of audio, granularity of regions is critical. • 2012: (15k/5k) user models, motion features, two-stage approaches. • 2013: (9M/262k) eliminated uploader ID, confidence prediction, retrieval approaches. • 2014: (5M/500k) YFCC100M data set, graph approaches, again external knowledge resources hurt. • 2015: (5M/1M) 8% correct visual, 27% correct multimodal. *(training data size/test data size)
  • 5. M. Larson, P. Kelm, A. Rae, C. Hauff, B. Thomee, M. Trevisiol, J. Choi, O. van Laere, S. Schockaert, G. J. F. Jones, P. Serdyukov, V. Murdock, and G. Friedland. The benchmark as a research catalyst: Charting the progress of geo-prediction for social multimedia. In J. Choi and G. Friedland, editors, Multimodal Location Estimation of Videos and Images. Springer, pp. 5-40. 2015.
  • 6. User Images on Social Media
  • 7. User Images on Social Media
  • 8. User Images on Social Media
  • 9. Gerald Friedland, Symeon Papadopoulos, Julia Bernd, and Yiannis Kompatsiaris. 2016. Multimedia Privacy. In Proceedings of the 2016 ACM on Multimedia Conference (MM '16). ACM, New York, NY, USA, 1479-1480. Cybercasing: Beware of large-scale automatic image mining
  • 11. How can we nudge users to protect themselves?
  • 12. Example images whose locations are protected by an Instagram filter Jaeyoung Choi, Martha Larson, Xinchao Li, Kevin Li, Gerald Friedland, and Alan Hanjalic. 2017. The Geo-Privacy Bonus of Popular Photo Enhancements. ACM ICMR 2017.
  • 13. Pixel Privacy at MediaEval 2018 Task Goal: • Increasing image appeal, • while blocking automatic inference of sensitive scene information. Evaluation Criteria: • Protection: % of images whose location categories can no longer be inferred by the “attack algorithm”. (Attack algorithm taken to be: ResNet50 classifier trained on the training set of the Places365-Standard dataset.) • Appeal: Degree to which the images are enhanced from the point of view of users. Novelty: We combine work on adversarial examples and image enhancement, which have been previously studied separately. B. Zhou, A. Lapedriza, A. Khosla, A. Oliva and A. Torralba, "Places: A 10 Million Image Database for Scene Recognition," in IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 40, no. 6, pp. 1452-1464, 1 June 2018.
  • 14. Pixel Privacy at MediaEval 2018 Task Data: Places365-Standard dataset Sensitive scene information: Taken to be the class labels of classes in Places365-Standard dataset associated privacy criteria (that we defined): • Places in the home, • Places far away from the home (typical vacation places), • Places typical for children, • Places related to religion, • Places related to people's health, • Places related to alcohol consumption, • Places in which people do not typically wear street clothes, • Places related to people's living conditions/income, • Places related to security, Places related to military. B. Zhou, A. Lapedriza, A. Khosla, A. Oliva and A. Torralba, "Places: A 10 Million Image Database for Scene Recognition," in IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 40, no. 6, pp. 1452-1464, 1 June 2018.
  • 16. Universal Adversarial Perturbations Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal adversarial perturbations. CVPR 2017.
  • 17. Universal Adversarial Perturbations Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal adversarial perturbations. CVPR 2017.
  • 18. Example images whose scene categories are protected style transfer Yang Chen, Yu-Kun Lai, and Yong-Jin Liu. CartoonGAN: Generative Adversarial Networks for Photo Cartoonization. CVPR 2018.
  • 19. Example images whose scene categories are protected style transfer Yang Chen, Yu-Kun Lai, and Yong-Jin Liu. CartoonGAN: Generative Adversarial Networks for Photo Cartoonization. CVPR 2018.
  • 20. Baseline: Protection with CartoonGAN Protection: About 60% of the images that can be recognized are protected. Appeal: CartoonGAN designed to appeal (appeal not specifically tested.)
  • 21. Outlook • What is appeal? • Protecting other types of sensitive information? • Protecting under less-constrained conditions: - Protecting against other attacks? - Protecting in the case of which negative images? • Can we keep up in the “arms race” against classifiers trained on protected images? • Detection vs. Protection: Can the task help to restore the balance in effort that is invested in research?