arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

所见较少并非更安全:任务范围机器人感知导出的隐私泄露

Seeing Less Is Not Seeing Safely: Privacy Leakage from Task-Scoped Robot Perception Exports

Yuqiao Xu, Erman Ayday

arXiv 2609.03055首次发表:更新:

发表机构

Case Western Reserve University(凯斯西储大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对家用机器人感知导出的隐私泄露问题,提出TFPD框架,实验表明不同导航导出隐私特性不同,无通用隐私排序,需开展特定任务的多风险评估。

AI 中文摘要

家用机器人依赖丰富的感知能力在私人住宅中运行,但即使原始传感器数据保留在本地,隐私风险仍然存在。导出到下游规划器、云服务、日志或学习流水线的结构化表示仍可通过语义、几何、空间结构和任务目标泄露家庭信息。我们引入任务功能感知蒸馏(Task-Functional Perception Distillation,TFPD),这是一种任务范围的表示导出框架,可将丰富的感知保留在本地,并根据任务效用、直接暴露和多种残余推理风险对下游导出进行分析。使用120个AI2-THOR场景,采用场景不相交的训练/验证/测试拆分、冻结的攻击者选择和感知表示感知的保留攻击,我们评估导航、碰撞检测和对象目标执行任务。三种导航导出实现了相同的成功率(1.000)和平均路径比(0.898),但表示级可链接性范围为0.532至0.970。用目标区域替换显式目标标签会使目标类别宏F1从1.000降至0.077,同时保持成功率为0.995;而几何粗化会使对象类别宏F1从0.704降至0.556,同时产生可测量的碰撞效用成本。ProcTHOR复现保留了导航任务等价/隐私不等价的发现,同时改变了归一化和拓扑导出的相对排序。这些结果表明,无论是字段移除还是更强的抽象都不会产生通用的隐私排序,并促使对完整公共表示进行特定任务的多风险评估。

英文摘要

Domestic robots rely on rich perception to operate in private homes, but privacy risk persists even when raw sensor data remain local. Structured representations exported to downstream planners, cloud services, logs, or learning pipelines can still reveal household information through semantics, geometry, spatial structure, and task targets. We introduce Task-Functional Perception Distillation (TFPD), a task-scoped representation-export framework that keeps rich perception local and profiles downstream exports according to task utility, direct exposure, and multiple residual inference risks. Using 120 AI2-THOR scenes with scene-disjoint train/validation/test splits, frozen attacker selection, and representation-aware held-out attacks, we evaluate navigation, collision checking, and object-goal execution. Three navigation exports achieve identical success (1.000) and mean path ratio (0.898), yet representation-level linkability ranges from 0.532 to 0.970. Replacing an explicit target label with a target region reduces target-category macro-F1 from 1.000 to 0.077 while preserving success at 0.995, while geometric coarsening reduces object-category macro-F1 from 0.704 to 0.556 at a measurable collision-utility cost. A ProcTHOR replication preserves the navigation task-equivalence/privacy-inequivalence finding while changing the relative ordering of normalized and topological exports. These results show that neither field removal nor stronger abstraction induces a universal privacy ordering and motivate task-specific, multi-risk evaluation of the complete public representation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑