RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    민감 영역 선택적 차등 프라이버시 확산모델을 이용한 얼굴 이미지 합성 기법에 관한 연구 = A Study on Facial Image Synthesis Using a Selective Differential Privacy Diffusion Model for Sensitive Regions

    한글로보기

    https://www.riss.kr/link?id=T17407128

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    최근 Diffusion Model은 높은 합성 품질로 주목받고 있지만 훈련 데이터에 포함된 개인정보가 모델 내부에 잔존하거나, 재합성될 위험이 수반된다. 해당 문제 해결을 위해 차등 프라이버시(Differentially Privacy, DP) 적용 연구가 활발히 진행되고 있다. 그러나 기존의 차등 프라이버시 확산 모델(Differentially Private Diffusion Model, DPDM)은 데이터 전 영역에 동일한 크기의 DP 노이즈(Noise)를 주입함으로써 전역적 프라이버시를 보장하지만, 비민감 영역까지 손상시켜 모델의 합성 품질이 저하되는 문제가 발생한다. 이에 본 연구는 데이터 내 영역별 민감도를 반영하여 DP를 적용하는 선택적 차등 프라이버시 확산 모델(Selective Differentially Private Diffusion Model, SDPDM)을 제안했다. 제안하는 SDPDM은 사전훈련(Pretrained)을 통해 비DP Diffusion Model을 학습한 뒤, 출력 파라미터를 DPDM과 SDPDM의 공통 초기값으로 사용함으로써 DP 학습 시 발생하는 수렴 불안정성과 품질 저하를 완화했다. 이후 CelebAMask-HQ 데이터셋의 Segmentation Mask 정보를 활용하여 얼굴 이미지 내 개인 식별이 가능한 민감 영역(Sensitive Region)에는 강화된 프라이버시 보호를 적용하고, 이외 비민감 영역(Standard Region)은 일반적인 학습 경로를 유지하여 불필요한 품질 손실을 최소화하는 선택적 DP 구조를 설계했다. 실험은 기존 DPDM과 동일한 네트워크 구조 및 실험 환경에서 비교 평가를 진행했다. 합성 품질 평가는 FID(Fréchet Inception Distance), LPIPS(Learned Perceptual Image Patch Similarity), SSIM(Structural Similarity Index Measure) 지표를 사용했다. 실험 결과 제안하는 SDPDM은 기존 DPDM 대비 모든 지표에서 일관된 성능 향상을 보였다. 특히, 민감 영역에 의 프라이버시 보호를 적용한 SDPDM-Aggressive 설정은 FID 30.238, LPIPS 0.0359, SSIM 0.5245를 기록하였으며, 더 완화된 프라이버시 설정 을 사용한 DPDM 보다 우수한 성능을 보였다. 이를 통해 동일하거나 더 엄격한 프라이버시 조건에서도 품질 저하 없이 안정적인 합성이 가능함을 입증했다. SDPDM의 실험 결과는 단순한 노이즈 강도 조정보다 데이터의 민감도 분포와 학습 안정성을 고려한 공간적 프라이버시 재구성 전략이 생성 모델의 품질과 보호 효율을 결정하는 핵심 요인임을 보여준다. 향후 연구에서는 사전훈련 단계가 DP 학습의 수렴 안정성에 미치는 영향을 정량적으로 분석하고, SDPDM의 고해상도 이미지 및 다양한 도메인으로 확장하여 선택적 DP 구조의 일반성을 검증할 예정이다. 또한 MIA(Membership Inference Attack) 등 실제 공격 시나리오를 적용해 SDPDM의 방어 성능을 실증적으로 검증함으로써, 프라이버시 보장형 Diffusion Model의 실증적 활용 가능성을 검증할 예정이다.
    번역하기

    최근 Diffusion Model은 높은 합성 품질로 주목받고 있지만 훈련 데이터에 포함된 개인정보가 모델 내부에 잔존하거나, 재합성될 위험이 수반된다. 해당 문제 해결을 위해 차등 프라이버시(Differe...

    최근 Diffusion Model은 높은 합성 품질로 주목받고 있지만 훈련 데이터에 포함된 개인정보가 모델 내부에 잔존하거나, 재합성될 위험이 수반된다. 해당 문제 해결을 위해 차등 프라이버시(Differentially Privacy, DP) 적용 연구가 활발히 진행되고 있다. 그러나 기존의 차등 프라이버시 확산 모델(Differentially Private Diffusion Model, DPDM)은 데이터 전 영역에 동일한 크기의 DP 노이즈(Noise)를 주입함으로써 전역적 프라이버시를 보장하지만, 비민감 영역까지 손상시켜 모델의 합성 품질이 저하되는 문제가 발생한다. 이에 본 연구는 데이터 내 영역별 민감도를 반영하여 DP를 적용하는 선택적 차등 프라이버시 확산 모델(Selective Differentially Private Diffusion Model, SDPDM)을 제안했다. 제안하는 SDPDM은 사전훈련(Pretrained)을 통해 비DP Diffusion Model을 학습한 뒤, 출력 파라미터를 DPDM과 SDPDM의 공통 초기값으로 사용함으로써 DP 학습 시 발생하는 수렴 불안정성과 품질 저하를 완화했다. 이후 CelebAMask-HQ 데이터셋의 Segmentation Mask 정보를 활용하여 얼굴 이미지 내 개인 식별이 가능한 민감 영역(Sensitive Region)에는 강화된 프라이버시 보호를 적용하고, 이외 비민감 영역(Standard Region)은 일반적인 학습 경로를 유지하여 불필요한 품질 손실을 최소화하는 선택적 DP 구조를 설계했다. 실험은 기존 DPDM과 동일한 네트워크 구조 및 실험 환경에서 비교 평가를 진행했다. 합성 품질 평가는 FID(Fréchet Inception Distance), LPIPS(Learned Perceptual Image Patch Similarity), SSIM(Structural Similarity Index Measure) 지표를 사용했다. 실험 결과 제안하는 SDPDM은 기존 DPDM 대비 모든 지표에서 일관된 성능 향상을 보였다. 특히, 민감 영역에 의 프라이버시 보호를 적용한 SDPDM-Aggressive 설정은 FID 30.238, LPIPS 0.0359, SSIM 0.5245를 기록하였으며, 더 완화된 프라이버시 설정 을 사용한 DPDM 보다 우수한 성능을 보였다. 이를 통해 동일하거나 더 엄격한 프라이버시 조건에서도 품질 저하 없이 안정적인 합성이 가능함을 입증했다. SDPDM의 실험 결과는 단순한 노이즈 강도 조정보다 데이터의 민감도 분포와 학습 안정성을 고려한 공간적 프라이버시 재구성 전략이 생성 모델의 품질과 보호 효율을 결정하는 핵심 요인임을 보여준다. 향후 연구에서는 사전훈련 단계가 DP 학습의 수렴 안정성에 미치는 영향을 정량적으로 분석하고, SDPDM의 고해상도 이미지 및 다양한 도메인으로 확장하여 선택적 DP 구조의 일반성을 검증할 예정이다. 또한 MIA(Membership Inference Attack) 등 실제 공격 시나리오를 적용해 SDPDM의 방어 성능을 실증적으로 검증함으로써, 프라이버시 보장형 Diffusion Model의 실증적 활용 가능성을 검증할 예정이다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The Diffusion Model inherently learns fine-grained patterns within the data, which poses a potential risk that personally identifiable information contained in the training dataset may remain within the model or be unintentionally regenerated during synthesis. Therefore, extensive research has been conducted to apply DP(Differential Privacy) in order to ensure privacy protection while maintaining high-quality image generation. The existing DPDM(Differentially Private Diffusion Model) injects an equal magnitude of DP noise across the entire data space to guarantee global privacy. However, this approach inevitably degrades image quality by introducing unnecessary distortion in non-sensitive regions. To address this limitation, this study proposes a SDPDM(Selective Differentially Private Diffusion Model) that applies differential privacy selectively based on the sensitivity of each region within the data. The proposed SDPDM first performs pretrained on a non-DP diffusion model, and the resulting parameters are used as common initialization weights for both DPDM and SDPDM. This pretrained step helps mitigate convergence instability and quality degradation that typically occur during DP training. Subsequently, using the segmentation mask information from the CelebAMask-HQ dataset, regions corresponding to personally identifiable facial components defined as sensitive regions are trained with enhanced privacy protection, while standard regions(non-sensitive regions) follow the regular training path to minimize unnecessary quality loss. Through this design, a selective DP framework is constructed to balance privacy preservation and image quality. The experiments were conducted using the CelebAMask-HQ dataset, and comparative evaluations were performed under the same network architecture and experimental settings as the existing DPDM. The quality of image synthesis was evaluated using FID(Fréchet Inception Distance), LPIPS(Learned Perceptual Image Patch Similarity), and SSIM(Structural Similarity Index Measure) metrics. Experimental results indicate that the proposed SDPDM achieved consistent improvements across all evaluation metrics, outperforming the existing DPDM. In particular, the SDPDM-Aggressive configuration, which applies privacy protection with    limited to sensitive regions, achieved an FID of 30.238, LPIPS of 0.0359, and SSIM of 0.5245, exhibiting superior performance compared to the DPDM with a more relaxed privacy setting of . This result demonstrates that stable image synthesis can be achieved without quality degradation, even under identical or more stringent privacy conditions. In future work, we plan to quantitatively analyze the impact of the pretrained stage on the convergence stability of DP-based training and extend SDPDM to high-resolution images and diverse domains to validate the generality of the selective DP framework. In addition, we plan to empirically evaluate the defense performance of SDPDM by applying real-world attack scenarios such as MIA(Membership Inference Attacks), thereby verifying the practical applicability of privacy preserving diffusion models.
    번역하기

    The Diffusion Model inherently learns fine-grained patterns within the data, which poses a potential risk that personally identifiable information contained in the training dataset may remain within the model or be unintentionally regenerated during s...

    The Diffusion Model inherently learns fine-grained patterns within the data, which poses a potential risk that personally identifiable information contained in the training dataset may remain within the model or be unintentionally regenerated during synthesis. Therefore, extensive research has been conducted to apply DP(Differential Privacy) in order to ensure privacy protection while maintaining high-quality image generation. The existing DPDM(Differentially Private Diffusion Model) injects an equal magnitude of DP noise across the entire data space to guarantee global privacy. However, this approach inevitably degrades image quality by introducing unnecessary distortion in non-sensitive regions. To address this limitation, this study proposes a SDPDM(Selective Differentially Private Diffusion Model) that applies differential privacy selectively based on the sensitivity of each region within the data. The proposed SDPDM first performs pretrained on a non-DP diffusion model, and the resulting parameters are used as common initialization weights for both DPDM and SDPDM. This pretrained step helps mitigate convergence instability and quality degradation that typically occur during DP training. Subsequently, using the segmentation mask information from the CelebAMask-HQ dataset, regions corresponding to personally identifiable facial components defined as sensitive regions are trained with enhanced privacy protection, while standard regions(non-sensitive regions) follow the regular training path to minimize unnecessary quality loss. Through this design, a selective DP framework is constructed to balance privacy preservation and image quality. The experiments were conducted using the CelebAMask-HQ dataset, and comparative evaluations were performed under the same network architecture and experimental settings as the existing DPDM. The quality of image synthesis was evaluated using FID(Fréchet Inception Distance), LPIPS(Learned Perceptual Image Patch Similarity), and SSIM(Structural Similarity Index Measure) metrics. Experimental results indicate that the proposed SDPDM achieved consistent improvements across all evaluation metrics, outperforming the existing DPDM. In particular, the SDPDM-Aggressive configuration, which applies privacy protection with    limited to sensitive regions, achieved an FID of 30.238, LPIPS of 0.0359, and SSIM of 0.5245, exhibiting superior performance compared to the DPDM with a more relaxed privacy setting of . This result demonstrates that stable image synthesis can be achieved without quality degradation, even under identical or more stringent privacy conditions. In future work, we plan to quantitatively analyze the impact of the pretrained stage on the convergence stability of DP-based training and extend SDPDM to high-resolution images and diverse domains to validate the generality of the selective DP framework. In addition, we plan to empirically evaluate the defense performance of SDPDM by applying real-world attack scenarios such as MIA(Membership Inference Attacks), thereby verifying the practical applicability of privacy preserving diffusion models.

    더보기

    목차 (Table of Contents)

    • Ⅰ. 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구 목적 및 범위 3
    • 1.3 논문의 구성 4
    • Ⅱ. 관련 연구 5
    • Ⅰ. 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구 목적 및 범위 3
    • 1.3 논문의 구성 4
    • Ⅱ. 관련 연구 5
    • 2.1 Diffusion Model 5
    • 2.2 Diffusion Model의 Memorization 문제 7
    • 2.3 Differentialy Private Diffusion Model 8
    • Ⅲ. 제안하는 선택적 차등프라이버시 확산모델 10
    • 3.1 제안하는 알고리즘의 개요 10
    • 3.2 비DP Diffusion Model 사전훈련 13
    • 3.3 SDPDM 14
    • Ⅳ. 구현 및 성능 평가 22
    • 4.1 실험 환경 22
    • 4.2 데이터셋 23
    • 4.3 평가 지표 24
    • 4.4 하이퍼파라미터 26
    • 4.5 정량적 평가 28
    • 4.6 이미지 품질 평가 35
    • Ⅴ. 결론 및 향후 연구 39
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼