面向三维点云的语义隐私保护与效用保持
Semantic Privacy Protection with Utility Preservation for 3D Point Clouds
- Indiana University(印第安纳大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出基于类别迁移的点云语义加密框架,利用归一化流、LoRA/FiLM和神经常微分方程,在隐藏原始类别的同时保持下游效用,并支持授权恢复。
AI中文摘要:
点云数据在采集、传输和跨机构共享过程中面临严重的语义隐私风险。现有方法大多依赖几何扰动或破坏性加密,虽然能降低原始类别的可识别性,但往往损害下游可用性。本文提出一种基于类别迁移的点云语义加密框架,旨在隐藏原始类别信息的同时保持任务效用,并支持授权恢复。具体而言,我们利用共享骨干的归一化流构建统一潜在空间,并结合LoRA和FiLM实现参数高效的类别条件自适应。我们进一步引入扩散引导的流对齐来正则化潜在分布,构建基于能量的类别转换图,并通过全局匹配获得最优类别迁移表。随后,潜在空间中的神经常微分方程将源类别潜在表示连续演化为目标类别潜在表示,再通过逆流解码为目标类别点云。我们采用攻击者导向的评估指标,包括新类别识别率(NCRR)、原始类别泄露率(OCLR)和原始标签恢复率(OLRR),以评估隐私和效用。在分类和分割基准上的实验表明,所提方法实现了可控的语义变换,有效降低了原始类别语义泄露,在保护域中保持了下游可学习性,并支持可靠的授权重建。
英文摘要:
Point cloud data face serious semantic privacy risks during acquisition, transmission, and cross-institutional sharing. Existing methods mostly rely on geometric perturbation or destructive encryption, which can reduce the recognizability of the original class but often impair downstream usability. This paper proposes a class-transfer-based semantic encryption framework for point clouds, aiming to conceal original class information while preserving task utility and supporting authorized recovery. Specifically, we construct a unified latent space with a shared-backbone Normalizing Flow, and combine LoRA and FiLM to achieve parameter-efficient class-conditional adaptation. We further introduce diffusion-guided flow alignment to regularize the latent distribution, construct an energy-based category transition graph, and obtain an optimal class-transfer table through global matching. Then, a latent-space Neural ODE continuously evolves source-class latents into target-class latents, which are decoded into target-class point clouds through the inverse flow. We adopt attacker-oriented metrics, including New-Class Recognition Rate (NCRR), Original-Class Leakage Rate (OCLR), and Original Label Recovery Rate (OLRR), to evaluate privacy and utility. Experiments on classification and segmentation benchmarks show that the proposed method achieves controllable semantic transformation, effectively reduces original-class semantic leakage, preserves downstream learnability in the protected domain, and supports reliable authorized reconstruction.