Manipulation Attacks on Learned Image Compression

被引:1
|
作者
Liu K. [1 ]
Wu D. [1 ]
Wu Y. [1 ]
Wang Y. [2 ]
Feng D. [1 ]
Tan B. [3 ]
Garg S. [4 ]
机构
[1] Huazhong University of Science and Technology, Wuhan
[2] University of Waterloo, Waterloo, N2L 3G1, ON
[3] University of Calgary, Calgary, T2N 1N4, AB
[4] New York University, Brooklyn, 11201, NY
来源
IEEE Transactions on Artificial Intelligence | 2024年 / 6卷 / 3083-3097期
关键词
Adversarial machine learning; DoS attack; image compression; robustness;
D O I
10.1109/TAI.2023.3340982
中图分类号
学科分类号
摘要
Deep learning (DL) techniques have shown promising results in image compression compared to conventional methods, with competitive bitrate and image reconstruction quality from compressed latent. However, whereas learned image compression has progressed toward a higher peak signal-to-noise ratio (PSNR) and fewer bits per pixel (bpp), its robustness to adversarial images has never received deliberation. In this work, we investigate the robustness of image compression systems where imperceptibly manipulated inputs can stealthily precipitate a significant increase in the compressed bitrate without compromising reconstruction quality. Such attacks can potentially exhaust the storage or network bandwidth of computing systems and lead to service denial. We term it as a denial-of-service attack on image compressors. To characterize the robustness of state-of-the-art learned image compression, we mount white-box and black-box attacks. Our white-box attack employs a gradient ascent approach on the entropy estimation of the bitstream as its bitrate approximation. We propose discrete cosine transform-Net simulating joint photographic experts group (JPEG) compression with architectural simplicity and lightweight training as the substitute in the black-box attack, enabling fast adversarial transferability. Our results on six image compression architectures, each with six different bitrate qualities (thirty-six models in total), show that they are surprisingly fragile, where the white-box attack achieves up to 55× and black-box 2× bpp increase, respectively, revealing the devastating fragility of DL-based compression models. To improve robustness, we propose a novel compression architecture factorAtn incorporating attention modules and a basic factorized entropy model that presents a promising tradeoff between rate-distortion performance and robustness to adversarial attacks and surpasses existing learned image compressors. © 2020 IEEE.
引用
收藏
页码:3083 / 3097
页数:14
相关论文
共 50 条
  • [41] Next generation image compression and manipulation using CREW
    Boliek, M
    Gormish, MJ
    Schwartz, EL
    Keith, A
    INTERNATIONAL CONFERENCE ON IMAGE PROCESSING - PROCEEDINGS, VOL III, 1997, : 567 - 570
  • [42] Rate Controllable Learned Image Compression Based on RFL Model
    Zhang, Saiping
    Wang, Luge
    Mao, Xionghui
    Yang, Fuzheng
    Wan, Shuai
    2022 IEEE INTERNATIONAL CONFERENCE ON VISUAL COMMUNICATIONS AND IMAGE PROCESSING (VCIP), 2022,
  • [43] Revisiting Learned Image Compression With Statistical Measurement of Latent Representations
    Li, Shaohui
    Dai, Wenrui
    Fang, Yimian
    Zheng, Ziyang
    Fei, Wen
    Xiong, Hongkai
    Zhang, Wei
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (04) : 2891 - 2907
  • [44] ProxIQA: A Proxy Approach to Perceptual Optimization of Learned Image Compression
    Chen, Li-Heng
    Bampis, Christos G.
    Li, Zhi
    Norkin, Andrey
    Bovik, Alan C.
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2021, 30 : 360 - 373
  • [45] Entropy Relaxed Lattice Vector Quantization for Learned Image Compression
    Cao, Maida
    Dai, Wenrui
    Li, Shaohui
    Li, Han
    Li, Chenglin
    Zou, Junni
    Xiong, Hongkai
    2024 DATA COMPRESSION CONFERENCE, DCC, 2024, : 548 - 548
  • [46] AFEC: Adaptive Feature Extraction Modules for Learned Image Compression
    Ma, Yi
    Zhai, Yongqi
    Yang, Jiayu
    Yang, Chunhui
    Wang, Ronggang
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 5436 - 5444
  • [47] Learned Lossless Image Compression Through Interpolation With Low Complexity
    Kamisli, Fatih
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2023, 33 (12) : 7832 - 7841
  • [48] An imperceptible adversarial attack against reconstruction for learned image compression
    Ma, Jingui
    Wang, Ronggang
    2024 DATA COMPRESSION CONFERENCE, DCC, 2024, : 573 - 573
  • [49] Learned Image Compression with Mixed Transformer-CNN Architectures
    Liu, Jinming
    Sun, Heming
    Katto, Jiro
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 14388 - 14397
  • [50] An Enhanced Multi-frequency Learned Image Compression Method
    He, Lin
    Wei, Zhihui
    Xu, Yang
    Wu, Zebin
    PATTERN RECOGNITION AND COMPUTER VISION,, PT III, 2021, 13021 : 189 - 200