fawkes/README.md

85 wiersze
3.1 KiB
Markdown

Fawkes
------
2021-03-07 06:39:19 +00:00
:warning: Check out our MacOS/Windows Software on our official [webpage](https://sandlab.cs.uchicago.edu/fawkes/#code).
2021-01-26 23:11:14 +00:00
2021-03-07 06:39:19 +00:00
Fawkes is a privacy protection system developed by researchers at [SANDLab](https://sandlab.cs.uchicago.edu/),
University of Chicago. For more information about the project, please refer to our
project [webpage](https://sandlab.cs.uchicago.edu/fawkes/). Contact us at fawkes-team@googlegroups.com.
2020-07-27 00:20:24 +00:00
2021-03-07 06:39:19 +00:00
We published an academic paper to summarize our
work "[Fawkes: Protecting Personal Privacy against Unauthorized Deep Learning Models](https://www.shawnshan.com/files/publication/fawkes.pdf)"
at *USENIX Security 2020*.
2020-07-15 00:34:51 +00:00
Copyright
---------
2021-03-07 06:39:19 +00:00
This code is intended only for personal privacy protection or academic research.
2020-07-15 00:34:51 +00:00
Usage
-----
`$ fawkes`
Options:
2021-03-07 06:39:19 +00:00
* `-m`, `--mode` : the tradeoff between privacy and perturbation size. Select from `low`, `mid`, `high`. The
higher the mode is, the more perturbation will add to the image and provide stronger protection.
2020-07-30 04:02:34 +00:00
* `-d`, `--directory` : the directory with images to run protection.
* `-g`, `--gpu` : the GPU id when using GPU for optimization.
2021-03-07 06:39:19 +00:00
* `--batch-size` : number of images to run optimization together. Change to >1 only if you have extremely powerful
compute power.
* `--format` : format of the output image (png or jpg).
2020-06-29 01:22:27 +00:00
### Example
2020-06-29 01:22:27 +00:00
2021-03-07 06:43:15 +00:00
`fawkes -d ./imgs --mode low`
2021-03-07 06:43:37 +00:00
or `python3 protection.py -d ./imgs --mode low`
2021-03-07 06:43:15 +00:00
### Tips
2021-03-07 06:39:19 +00:00
- The perturbation generation takes ~60 seconds per image on a CPU machine, and it would be much faster on a GPU
machine. Use `batch-size=1` on CPU and `batch-size>1` on GPUs.
- Run on GPU. The current Fawkes package and binary does not support GPU. To use GPU, you need to clone this repo, install
the required packages in `setup.py`, and replace tensorflow with tensorflow-gpu. Then you can run Fawkes
by `python3 fawkes/protection.py [args]`.
2020-07-14 00:06:33 +00:00
2020-08-01 17:17:10 +00:00
![](http://sandlab.cs.uchicago.edu/fawkes/files/obama.png)
2020-08-01 17:14:27 +00:00
2021-03-07 06:39:19 +00:00
### How do I know my images are secure?
We are actively working on this. Python scripts that can test the protection effectiveness will be ready shortly.
Quick Installation
------------------
2020-07-26 19:47:03 +00:00
Install from [PyPI](https://pypi.org/project/fawkes/):
```
pip install fawkes
```
If you don't have root privilege, please try to install on user namespace: `pip install --user fawkes`.
2020-09-30 03:01:54 +00:00
Academic Research Usage
-----------------------
2021-03-07 06:39:19 +00:00
For academic researchers, whether seeking to improve fawkes or to explore potential vunerability, please refer to the
following guide to test Fawkes.
2020-07-14 00:06:05 +00:00
2021-09-27 06:03:09 +00:00
To protect a class in a dataset, first move the label's image to a separate location and run Fawkes. Please
2021-03-07 06:39:19 +00:00
use `--debug` option and set `batch-size` to a reasonable number (i.e 16, 32). If the images are already cropped and
aligned, then also use the `no-align` option.
2020-07-14 00:06:05 +00:00
2020-06-29 01:22:27 +00:00
### Citation
2021-03-07 06:39:19 +00:00
2020-06-29 01:22:27 +00:00
```
@inproceedings{shan2020fawkes,
title={Fawkes: Protecting Personal Privacy against Unauthorized Deep Learning Models},
author={Shan, Shawn and Wenger, Emily and Zhang, Jiayun and Li, Huiying and Zheng, Haitao and Zhao, Ben Y},
2021-01-31 08:28:02 +00:00
booktitle={Proc. of {USENIX} Security},
2020-06-29 01:22:27 +00:00
year={2020}
}
```