On the Security of the One-and-a-Half-Class Classifier for SPAM Feature-Based Image Forensics

被引:2
|
作者
Lorch, Benedikt [1 ]
Schirrmacher, Franziska [1 ]
Maier, Anatol [1 ]
Riess, Christian [1 ]
机构
[1] Friedrich Alexander Univ Erlangen Nurnberg, IT Secur Infrastruct Lab, D-91058 Erlangen, Germany
关键词
Detectors; Feature extraction; Robustness; Glass box; Security; Distortion; Quantization (signal); Image forensics; counter-forensics; adversarial examples; one-and-a-half-class classifier; MANIPULATION; TRACES;
D O I
10.1109/TIFS.2023.3266168
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Combining multiple classifiers is a promising approach to hardening forensic detectors against adversarial evasion attacks. The key idea is that an attacker must fool all individual classifiers to evade detection. The 1.5C classifier is one of these multiple-classifier detectors that is attack-agnostic, and thus even increases the difficulty for an omniscient attacker. Recent work evaluated the 1.5C classifier with SPAM features for image manipulation detection. Despite showing promising results, their security analysis leaves several aspects unresolved. Surprisingly, the results reveal that fooling only one component is often sufficient to evade detection. Additionally, the authors evaluate classifier robustness with only a black-box attack because, currently, there is no white-box attack against SPAM feature-based classifiers. This paper addresses these shortcomings and complements the previous security analysis. First, we develop a novel white-box attack against SPAM feature-based detectors. The proposed attack produces adversarial images with lower distortion than the previous attack. Second, by analyzing the 1.5C classifier's acceptance region, we identify three pitfalls that explain why the current 1.5C classifier is less robust than a binary classifier in some settings. Third, we illustrate how to mitigate these pitfalls with a simple axis-aligned split classifier. Our experimental evaluation demonstrates the increased robustness of the proposed detector for SPAM feature-based image manipulation detection.
引用
收藏
页码:2466 / 2479
页数:14
相关论文
共 50 条
  • [41] A Robust Feature-based Image Watermarking Scheme
    Lai, Chih-Chin
    Chan, Chi-Feng
    Ouyang, Chen-Sen
    Chiang, Hui-Fen
    2013 14TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD 2013), 2013, : 581 - 585
  • [42] FEATURE-BASED PHASE CORRELATION IN IMAGE REGISTRATION
    Tsai, Victor J. D.
    2019 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM (IGARSS 2019), 2019, : 3101 - 3104
  • [43] Feature-based image automatic mosaicing algorithm
    Hu, Shejiao
    Hu, Yaling
    Chen, Zonghai
    Jiang, Ping
    WCICA 2006: SIXTH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-12, CONFERENCE PROCEEDINGS, 2006, : 761 - 761
  • [44] A Textural Feature-Based Image Retrieval Algorithm
    Song, Xiaoyi
    Li, Yongjie
    Chen, Wufan
    ICNC 2008: FOURTH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, VOL 4, PROCEEDINGS, 2008, : 71 - 75
  • [45] A feature-based scalable codec for image compression
    Kuo, LC
    Wang, SJ
    AINA 2005: 19TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 2, 2005, : 87 - 90
  • [46] Geometric feature-based skin image classification
    Yang, Jinfeng
    Shi, Yihua
    Xiao, Mingliang
    ADVANCED INTELLIGENT COMPUTING THEORIES AND APPLICATIONS: WITH ASPECTS OF THEORETICAL AND METHODOLOGICAL ISSUES, 2007, 4681 : 1158 - +
  • [47] THE IMPROVEMENT OF A FEATURE-BASED IMAGE MOSAICS ALGORITHM
    Zhang, Xiaoru
    Xiao, Ke
    Gao, Guandong
    Teng, Guifa
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2008, 4 (10): : 2759 - 2764
  • [48] Textual case-based reasoning for spam filtering: a comparison of feature-based and feature-free approaches
    Sarah Jane Delany
    Derek Bridge
    Artificial Intelligence Review, 2006, 26 : 75 - 87
  • [49] A Feature-Based Coding Algorithm for Face Image
    Li, Henan
    Wang, Shigang
    Zhao, Yan
    Yang, Chuxi
    Wang, Aobo
    IMAGE AND GRAPHICS (ICIG 2017), PT II, 2017, 10667 : 299 - 309
  • [50] Textual case-based reasoning for spam filtering: a comparison of feature-based and feature-free approaches
    Delany, Sarah Jane
    Bridge, Derek
    ARTIFICIAL INTELLIGENCE REVIEW, 2006, 26 (1-2) : 75 - 87