<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>MediaEval 2014 Visual Privacy Task: De-identification and Re-identification of Subjects in CCTV</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Cesar Pantoja</string-name>
          <email>c.pantoja@qmul.ac.uk</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ebroul Izquierdo</string-name>
          <email>e.izquierdo@qmul.ac.uk</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Queen Mary University of London</institution>
          ,
          <addr-line>Mile End Road, E1 4NS, London</addr-line>
          ,
          <country country="UK">UK</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2014</year>
      </pub-date>
      <fpage>16</fpage>
      <lpage>17</lpage>
      <abstract>
        <p>We present in this paper a method for de-identi cation of persons in a CCTV environment which uses di erent levels of ltering depending on the privacy sensitivity of the region of interest. The proposed method tries to tackle the problem of re-identifying (de- ltering) a person which has committed a crime. Validation of the method shows low results in privacy as a result of the identity of the subjects not being concealed at all times.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. INTRODUCTION</title>
      <p>
        Police and security forces around the world deploy great
amounts of CCTV in an e ort to ght crime and preserve
peace. This at a cost of regular citizens' privacy, as their
daily whereabouts are being recorded as well. For the
MediaEval 2014 Visual Privacy task[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], we propose a method
to de-identify people present in a CCTV with the option of
re-identifying them in the case it is established the person is
exposing a criminal behaviour. This causes that while the
privacy is being maintained, the intelligibility of the scene is
also preserved as the surveillance task can be carried away
un ltered when it is needed. Evaluations show acceptable
intelligibility and pleasantness results of the lter, but not
so good results in privacy, most likely because of the identity
of the subjects not being concealed all the time. The rest
of the paper is organised as follows: Section 2 presents the
proposed method, the objectives and design choices behind
it's development. Section 3 presents the evaluation results of
the method. Finally, section 4 draws some closing remarks
and states future research opportunities.
      </p>
    </sec>
    <sec id="sec-2">
      <title>PROPOSED METHOD DESCRIPTION</title>
      <p>The de-identi cation method applies di erent lters
depending on the privacy sensitivity of the region of
interest. All the types of regions of interest were categorised in
three possible levels, each carrying more sensitive
information than the previous one.</p>
      <p>But before going into details of the de-identi cation method
and each of the levels, it is important to note that an
important feature of this lter is the ability to re-identify suspects
of criminal activities. This allows CCTV operators to
perform the surveillance activity in a more e ective way. As
soon as one actor is known to be committing a suspicious
activity, the lter is switched o only for that actor
performing the illicit activity but keeping the privacy of the other
actors intact. The current actions for which the lter is
deactivated are \ ghting", \stealing", and \bad drop". This
allows to e ectively re-identify the criminals in the scene.
This is an important feature of de-identi cation lters: the
ability to reverse the lter if it is required by the users of
the system.</p>
      <p>As stated previously, the lter applies 3 di erent process
depending on the privacy sensitivity of the region of interest.
The sensitivity is given to the lter and it decides which
process to apply.</p>
      <p>The rst level of privacy is the one with the less
sensitivity and the lightest lter is applied here. In this case it was
decided to use a Gaussian Blur with a kernel size of 21
pixels. The second level might carry some additional personal
information which might harm the privacy of the subjects.
For this level, a pixelisation lter with a new pixel size of 10
is applied.</p>
      <p>The third and nal level carries the most personal
information (such as faces and skin tone) and has to be ltered
the most. For this level the pixelisation lter was also
selected, but with a new pixel size of 20 pixels. In addition
to this, the colour of the region of interested is removed,
leaving a pixelated grey-scale region.
2.1</p>
    </sec>
    <sec id="sec-3">
      <title>Method Discussion</title>
      <p>The rst thing we want to achieve is to provide privacy to
law-abiding citizens. The second goal of the lter is to allow
the re-identi cation of suspects of crimes. With this in mind,
and since the meta-data of the actions of the actors in the
scene was available, it was decided that the lter would be
deactivated to allow the surveillance task to be carried away
with much more information than if it was ltered. This
lter has thus two parts: the de-identi cation of innocent
people and the re-identi cation of suspects of crimes.</p>
      <p>
        In the de-identi cation part of the lter, for the top
levels of privacy sensitivity, the pixelisation lter has been
selected because it has shown to have a very good balance
of privacy and intelligibility[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Additionally, Skin tone is
regarded as one of the most important features when
identifying humans[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], which is why an additional step was added
to conceal the person's real skin tone. Figure 1 shows the
lter applied to a CCTV scene.
3.
      </p>
    </sec>
    <sec id="sec-4">
      <title>EVALUATION RESULTS</title>
      <p>
        Evaluation was performed in with the DataSet and
methodology presented in [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] and [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] respectively. Figure 2 presents
      </p>
      <p>(a) Stream 1
(b) Stream 2
(c) Stream 3
the results. It includes the results for Stream 1 (nave
subjects - sub gure 2a), Stream 2 (video surveillance sta
sub gure 2b), and Stream 3 (online subjective evaluations
sub gure 2c).</p>
      <p>It can be seen that the results in Intelligibility and
Pleasantness are right around the median of the other results
(except for pleasantness in Stream 1, where it is actually
higher). But in all of the Streams, it is evident that the
privacy score is signi cantly lower than the other approaches.
This is a result of the lter not concealing the identity of
the subjects (thus, NOT protecting their privacy) in the
case where they are engaging in potentially illicit activity as
speci ed by the meta-data.
4.</p>
    </sec>
    <sec id="sec-5">
      <title>CONCLUSIONS AND FUTURE WORK</title>
      <p>We have developed a de-identi cation method for the
MediaEval 2014 Visual Privacy Task, which applies di erent
lters to di erent regions of interest according to it's
privacy sensitivity. Most importantly, the lter allows the
reidenti cation of a suspect by removing all relevant lters
when a crime is detected. This allows us to keep the privacy
of innocent citizens' intact, while exposing the full identity
of crime suspects, facilitating the labour of law enforcement
to the authorities.</p>
      <p>Because of the nature of this lter, a low privacy score was
actually achieved. We hope that this development leads to
a wider discussion about the adequate way to address
citizens' privacy concerns while still generating useful data for
law enforcement. We think the best solution is a multi-tiered
approach where there are di erent levels of de-identi cation
depending on the relevance of the person. This discussion
must include the fact that it would be a machine
determining the \guilt" of a subject and thus revealing it's identity.
Among other ethical issues, what would happen for example
with false negatives or false positives?</p>
      <p>In the future we expect to adjust the de-identi cation
lter to get better results in Intelligibility and Pleasantness.
The usefulness of removing the lter in case of suspicious
activities has to be further evaluated as well.
5.</p>
    </sec>
    <sec id="sec-6">
      <title>ACKNOWLEDGMENTS</title>
      <p>The research presented in this paper was supported by
the European Commission under contract FP7-SEC 261743
VideoSense and FP7-SEC 285024 Advise.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Badii</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Ebrahimi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Fedorczak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Korshunov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Piatrik</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Eiselein</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A</given-names>
            .
            <surname>Al-Obaidi</surname>
          </string-name>
          .
          <article-title>Overview of the mediaeval 2014 visual privacy task</article-title>
          .
          <source>In MediaEval 2014 Workshop</source>
          , Barcelona, Spain, October
          <volume>16</volume>
          -17
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Demirkus</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Garg</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Guler</surname>
          </string-name>
          .
          <article-title>Automated person categorization for video surveillance using soft biometrics</article-title>
          .
          <source>Proc. SPIE</source>
          ,
          <volume>7667</volume>
          :76670P{
          <fpage>76670P</fpage>
          {
          <fpage>12</fpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>P.</given-names>
            <surname>Korshunov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Araimo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>De Simone</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Velardo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dugelay</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Ebrahimi</surname>
          </string-name>
          .
          <article-title>Subjective study of privacy lters in video surveillance</article-title>
          .
          <source>In Multimedia Signal Processing (MMSP)</source>
          ,
          <source>2012 IEEE 14th International Workshop on</source>
          , pages
          <volume>378</volume>
          {
          <fpage>382</fpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>P.</given-names>
            <surname>Korshunov</surname>
          </string-name>
          and
          <string-name>
            <given-names>T.</given-names>
            <surname>Ebrahimi</surname>
          </string-name>
          .
          <article-title>PEViD: privacy evaluation video dataset</article-title>
          .
          <source>In SPIE Applications of Digital Image Processing XXXVI</source>
          , volume
          <volume>8856</volume>
          , San Diego, California, USA, Aug.
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>