On the Importance of Conditioning for Privacy-Preserving Data Augmentation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lorenz, Julian, Ludwig, Katja, Haug, Valentin, Lienhart, Rainer
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908306903138304
author Lorenz, Julian
Ludwig, Katja
Haug, Valentin
Lienhart, Rainer
author_facet Lorenz, Julian
Ludwig, Katja
Haug, Valentin
Lienhart, Rainer
contents Latent diffusion models can be used as a powerful augmentation method to artificially extend datasets for enhanced training. To the human eye, these augmented images look very different to the originals. Previous work has suggested to use this data augmentation technique for data anonymization. However, we show that latent diffusion models that are conditioned on features like depth maps or edges to guide the diffusion process are not suitable as a privacy preserving method. We use a contrastive learning approach to train a model that can correctly identify people out of a pool of candidates. Moreover, we demonstrate that anonymization using conditioned diffusion models is susceptible to black box attacks. We attribute the success of the described methods to the conditioning of the latent diffusion model in the anonymization process. The diffusion model is instructed to produce similar edges for the anonymized images. Hence, a model can learn to recognize these patterns for identification.
format Preprint
id arxiv_https___arxiv_org_abs_2504_05849
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Importance of Conditioning for Privacy-Preserving Data Augmentation
Lorenz, Julian
Ludwig, Katja
Haug, Valentin
Lienhart, Rainer
Computer Vision and Pattern Recognition
Latent diffusion models can be used as a powerful augmentation method to artificially extend datasets for enhanced training. To the human eye, these augmented images look very different to the originals. Previous work has suggested to use this data augmentation technique for data anonymization. However, we show that latent diffusion models that are conditioned on features like depth maps or edges to guide the diffusion process are not suitable as a privacy preserving method. We use a contrastive learning approach to train a model that can correctly identify people out of a pool of candidates. Moreover, we demonstrate that anonymization using conditioned diffusion models is susceptible to black box attacks. We attribute the success of the described methods to the conditioning of the latent diffusion model in the anonymization process. The diffusion model is instructed to produce similar edges for the anonymized images. Hence, a model can learn to recognize these patterns for identification.
title On the Importance of Conditioning for Privacy-Preserving Data Augmentation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2504.05849