Manipulation Attacks on Learned Image Compression

被引:1
|
作者
Liu K. [1 ]
Wu D. [1 ]
Wu Y. [1 ]
Wang Y. [2 ]
Feng D. [1 ]
Tan B. [3 ]
Garg S. [4 ]
机构
[1] Huazhong University of Science and Technology, Wuhan
[2] University of Waterloo, Waterloo, N2L 3G1, ON
[3] University of Calgary, Calgary, T2N 1N4, AB
[4] New York University, Brooklyn, 11201, NY
来源
IEEE Transactions on Artificial Intelligence | 2024年 / 6卷 / 3083-3097期
关键词
Adversarial machine learning; DoS attack; image compression; robustness;
D O I
10.1109/TAI.2023.3340982
中图分类号
学科分类号
摘要
Deep learning (DL) techniques have shown promising results in image compression compared to conventional methods, with competitive bitrate and image reconstruction quality from compressed latent. However, whereas learned image compression has progressed toward a higher peak signal-to-noise ratio (PSNR) and fewer bits per pixel (bpp), its robustness to adversarial images has never received deliberation. In this work, we investigate the robustness of image compression systems where imperceptibly manipulated inputs can stealthily precipitate a significant increase in the compressed bitrate without compromising reconstruction quality. Such attacks can potentially exhaust the storage or network bandwidth of computing systems and lead to service denial. We term it as a denial-of-service attack on image compressors. To characterize the robustness of state-of-the-art learned image compression, we mount white-box and black-box attacks. Our white-box attack employs a gradient ascent approach on the entropy estimation of the bitstream as its bitrate approximation. We propose discrete cosine transform-Net simulating joint photographic experts group (JPEG) compression with architectural simplicity and lightweight training as the substitute in the black-box attack, enabling fast adversarial transferability. Our results on six image compression architectures, each with six different bitrate qualities (thirty-six models in total), show that they are surprisingly fragile, where the white-box attack achieves up to 55× and black-box 2× bpp increase, respectively, revealing the devastating fragility of DL-based compression models. To improve robustness, we propose a novel compression architecture factorAtn incorporating attention modules and a basic factorized entropy model that presents a promising tradeoff between rate-distortion performance and robustness to adversarial attacks and surpasses existing learned image compressors. © 2020 IEEE.
引用
收藏
页码:3083 / 3097
页数:14
相关论文
共 50 条
  • [21] Domain Adaptation for Learned Image Compression with Supervised Adapters
    Presta, Alberto
    Spadaro, Gabriele
    Tartaglione, Enzo
    Fiandrotti, Attilio
    Grangetto, Marco
    2024 DATA COMPRESSION CONFERENCE, DCC, 2024, : 33 - 42
  • [22] Reconstruction Distortion of Learned Image Compression with Imperceptible Perturbations
    Sui, Yang
    Li, Zhuohang
    Ding, Ding
    Pan, Xiang
    Xu, Xiaozhong
    Liu, Shan
    Chen, Zhenzhong
    2024 DATA COMPRESSION CONFERENCE, DCC, 2024, : 583 - 583
  • [23] Idempotent Learned Image Compression with Right-Inverse
    Li, Yanghao
    Xu, Tongda
    Wang, Yan
    Liu, Jingjing
    Zhang, Ya-Qin
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [24] Practical Learned Image Compression with Online Encoder Optimization
    Zhang, Haotian
    Mei, Feihong
    Liao, Junqi
    Li, Li
    Li, Houqiang
    Liu, Dong
    2024 PICTURE CODING SYMPOSIUM, PCS 2024, 2024,
  • [25] Successive learned image compression: Comprehensive analysis of instability
    Kim, Jun-Hyuk
    Jang, Soobeom
    Choi, Jun-Ho
    Lee, Jong-Seok
    NEUROCOMPUTING, 2022, 506 : 12 - 24
  • [26] FDNet: Frequency Decomposition Network for Learned Image Compression
    Wang, Jian
    Ling, Qiang
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (11) : 11241 - 11255
  • [27] Generative Adversarial Networks for Extreme Learned Image Compression
    Agustsson, Eirikur
    Tschannen, Michael
    Mentzer, Fabian
    Timofte, Radu
    Van Gool, Luc
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 221 - 231
  • [28] HYPERSPECTRAL IMAGE COMPRESSION USING LEARNED CLASSIFIED DICTIONARY
    Xu, Dawei
    Zhang, Rong
    Wu, Qian
    2015 7TH WORKSHOP ON HYPERSPECTRAL IMAGE AND SIGNAL PROCESSING: EVOLUTION IN REMOTE SENSING (WHISPERS), 2015,
  • [29] Synthetic Face Discrimination via Learned Image Compression
    Iliopoulou, Sofia
    Tsinganos, Panagiotis
    Ampeliotis, Dimitris
    Skodras, Athanassios
    ALGORITHMS, 2024, 17 (09)
  • [30] Wide format image manipulation and compression in a printing environment
    Sibade, C
    Barizien, S
    Akil, M
    Perroton, L
    MULTIMEDIA SYSTEMS AND APPLICATIONS V, 2002, 4861 : 216 - 226