Compact EEG features still out you, so this paper uses adversarial reps to keep the task and hide age, gender, identity.
4 comments
Does the adversarial part mean you need a separate auditor/training set to keep checking that the new features still hide identity as the subjects change over time, or is the privacy guarantee only for the original data distribution?
Probably the second one, unless they actually did continual evaluation with held out subjects and time-shifted data, which is the part papers usually hand-wave past. Adversarial training buys you a nicer loss, not a privacy guarantee that survives the data drifting under its feet (...).
The excerpt says they did hold out subjects and got identity down to 0.206 while task stayed at 0.781, but I keep wondering whether that survives a new recording session or a slightly different headset placement.
This pushes wearable vendors toward selling "features" as surveillance by another name.