MTISA: Multi-Target Image-Scaling Attack

被引:0
|
作者
He, Jiaming [1 ,2 ]
Li, Hongwei [1 ]
Jiang, Wenbo [1 ]
Zhang, Yuan [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu, Peoples R China
[2] Chengdu Univ Technol, Oxford Brookes Coll, Coll Comp Sci & Cyber Secur, Chengdu, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Image-scaling attack; Deep learning; SinGAN;
D O I
10.1109/ICC51166.2024.10622983
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Image scaling is one of the most common operations in image processing. For instance, it is often conducted before image transferring to preserve resources, image classifiers also require images to be input at a specified size. However, potential threats may come out with the image scaling operation. A recent work called image-scaling attack can change the semantic information of the input image when it is scaled to a specific size. For example, a manipulated image of a sheep may become an image of a wolf when it scales to a specific size. Many works have already demonstrated the effectiveness of this attack and the security risks it poses. However, existing image-scaling attacks only focus on single target with single specific size, and are not applicable to multi-target image-scaling attack. In this paper, we present a multi-target image-scaling attack (MTISA). MTISA can be trained with a single image performs diverse and semantically distinct outputs to fool both human vision and image classifiers. Specifically, to fool human vision, we employ SinGAN to generate semantically different but background-similar samples to serve as the attack target samples. To mislead image classifiers, we employ adversarial attacks to construct adversarial examples to serve as the attack target samples. Finally, we evaluate MTISA on chest X-rays dataset and ImageNet dataset, respectively. The experimental results demonstrate that MTISA achieves high attack success rate against both human vision and image classifiers.
引用
收藏
页码:2191 / 2196
页数:6
相关论文
共 50 条
  • [1] Generative Adversarial Network Based Image-Scaling Attack and Defense Modeling
    Li, Junjian
    Chen, Honglong
    Li, Zhe
    Zhang, Anqing
    Wang, Xiaomeng
    Wang, Xingang
    Xia, Feng
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2025, 9 (01): : 861 - 873
  • [2] Target Threat Assessment in Multi-object Multi-target Attack
    Mou, Zhi-ying
    Tang, Shu-juan
    Wang, Shu-qian
    Wang, Nan
    INTERNATIONAL CONFERENCE ON MATERIALS, MANUFACTURING AND MECHANICAL ENGINEERING (MMME 2016), 2016, : 146 - 150
  • [3] Call White Black: Enhanced Image-Scaling Attack in Industrial Artificial Intelligence Systems
    Li, Junjian
    Chen, Honglong
    Sun, Peng
    Wang, Zhibo
    Ni, Zhichen
    Liu, Weifeng
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (04) : 6222 - 6233
  • [4] Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network Once
    Han, Jiangfan
    Dong, Xiaoyi
    Zhang, Ruimao
    Chen, Dongdong
    Zhang, Weiming
    Yu, Nenghai
    Luo, Ping
    Wang, Xiaogang
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 5157 - 5166
  • [5] On the Detection of Image-Scaling Attacks in Machine Learning
    Quiring, Erwin
    Mueller, Andreas
    Rieck, Konrad
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 506 - 520
  • [6] Image-Scaling Attack on Image Signal Processing Pipelines in Deep Neural Networks-Based Outdoor Vision Applications
    Li, Junjian
    Chen, Honglong
    Ni, Zhichen
    Gao, Yudong
    Liu, Weifeng
    Jiang, Nan
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (04) : 7044 - 7055
  • [7] MulTIR: Deep Multi-Target Image Retargeting
    Sun, Di
    Guo, Yitong
    Yao, Chaojie
    Mei, Yijing
    Chen, Dufeng
    Pan, Gang
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT VII, ICIC 2024, 2024, 14868 : 124 - 133
  • [8] Resolving power of optoelectronic converters in the image-scaling regime
    Bykov, E
    Tsao, F
    JOURNAL OF OPTICAL TECHNOLOGY, 2002, 69 (08) : 558 - 561
  • [9] Decamouflage: A Framework to Detect Image-Scaling Attacks on CNN
    Kim, Bedeuro
    Abuadbba, Alsharif
    Gao, Yansong
    Zheng, Yifeng
    Ahmed, Muhammad Ejaz
    Nepal, Surya
    Kim, Hyoungshick
    51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN 2021), 2021, : 63 - 74
  • [10] Development of an Electronic Attack (EA) System in Multi-Target Tracking
    Tuerkcue, Oezlem
    Leblebicioglu, M. Kemal
    2008 IEEE 16TH SIGNAL PROCESSING, COMMUNICATION AND APPLICATIONS CONFERENCE, VOLS 1 AND 2, 2008, : 132 - +