Skip to content
Review

Privacy-Preserving Action Recognition: Taxonomy, Methods, and Privacy-Utility Trade-offs

Aug 2026 · 0 citations · 124 references
Computer Science

TL;DR

It is argued PPAR can move from prototypes toward deployment, with lessons extending to face recognition and medical imaging, and a roadmap centered on benchmark standardization is contributed.

Abstract

Video surveillance in public safety, healthcare, and smart environments has made continuous human monitoring routine, raising real risks to personal identity and appearance. Privacy-preserving action recognition (PPAR) tackles the tension between the utility of video understanding and this exposure, and has drawn fast-growing interest. However, existing surveys remain narrow. Most catalog a single mechanism family, predate recent adversarial and hybrid work, or barely address evaluation. The result is a fragmented literature with incompatible threat models, inconsistent metrics, and no shared evaluation standard. We address this with a PRISMA-guided review of 32 peer-reviewed papers (2018--2026) drawn from 885 screened records. Methods sort into five families, namely adversarial learning (52%), skeleton-based (20%), cryptographic (12%), differential privacy (8%), and hybrid (8%), each with distinct privacy, utility, and efficiency trade-offs. Evaluation is the weak point. Only 10% of papers adopt a formal privacy definition, 65% rely on ad-hoc metrics, and 40% report an inconsistently defined cMAP. The trade-offs are steep. Skeleton methods reach about 85% accuracy but drop appearance, adversarial methods hold near 80% utility at moderate privacy (cMAP 0.9 to 0.3--0.5), and differential privacy often falls below 70%. Harder conditions stay under-tested, with fewer than 15% of papers checking cross-dataset generalization, under 10% testing adaptive attackers, and real-time edge deployment nearly untouched. We contribute a two-dimensional privacy-space taxonomy, a formal threat model, a comparative trade-off analysis, the PPAR Unified Evaluation Protocol, and a roadmap centered on benchmark standardization. With this grounding, we argue PPAR can move from prototypes toward deployment, with lessons extending to face recognition and medical imaging.

View source

Similar papers

2026

PI-SAFE: Practical Privacy-Preserving LLM Inference With Adversarial Fine-Tuning for Optimized Utility

Cloud-based Large Language Model (LLM) inference services typically require users to submit plain-text inputs, thereby posing severe privacy risks. Existing privacy-preserving paradigms are mostly task-specific and often necessitate pervasive modifications to the entire server-side model. This reliance introduces subst...

Wentao Zhong, Yu-Ting Li, Di-Cong Yu et al. · 0 citations
Review Sep 2026

Privacy-preserving methodologies against privacy attacks on deep learning: a survey

The analysis finds that noise-based methods such as DP remain the practical baseline but offer only partial protection; cryptographic approaches provide stronger theoretical guarantees at substantially higher cost; and LLM/multimodal leakage remains an urgent, under-benchmarked gap.

Subhasish Ghosh, A. K. Mandal · 0 citations
#explainable ai Open access Sep 2026

Privacy-aware adversarial defense with explainable AI for adversarial robustness in AI model

The Attention Concentration Score (ACS) is introduced, which measures how DP training shifts Transformer attention away from task-critical features toward non-functional ones, providing a mechanistic explanation of the trade-off.

Bilal Sardar, Shareeful Islam, Stefano Silvestri et al. · 0 citations
#software testing Preprint Sep 2026

Zero-Knowledge Remote Adversarial Attack against Wi-Fi-based Human Activity Recognition for Privacy Protection

This work proposes GRAW, an adversary system, acting as a privacy defender, that degrades the human activity recognition (HAR) system at the user device by perturbing the router's signals that the device uses to estimate CSI.

Byungjun Kim, Amogh Panchagatti, Peter Gerstoft et al. · 0 citations
Open access Sep 2026

A PRIVACY-PRESERVING FRAMEWORK FOR INSIDER THREAT DETECTION USING PROCESS MINING, MACHINE LEARNING, AND DIFFERENTIAL PRIVACY

The results establish that formal (ε,δ)-differential privacy and operationally effective insider-threat detection can be achieved simultaneously when process mining is performed at the appropriate (per-user) granularity.

Walter Maanyere, Xian-Wen Fang, Palvine Ngob Enow et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.