Attack as the Best Defense: Nullifying Image-to-image Translation GANs via Limit-aware Adversarial Attack

被引:6
|
作者
Yeh, Chin-Yuan [1 ,3 ]
Chen, Hsi-Wen [1 ]
Shuai, Hong-Han [2 ]
Yang, De-Nian [3 ]
Chen, Ming-Syan [1 ]
机构
[1] Natl Taiwan Univ, Taipei, Taiwan
[2] Natl Yangming Jiaotong Univ, Taipei, Taiwan
[3] Acad Sinica, Taipei, Taiwan
来源
2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021) | 2021年
关键词
D O I
10.1109/ICCV48922.2021.01588
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the great success of image-to-image (Img2Img) translation GANs, many applications with ethics issues arise, e.g., DeepFake and DeepNude, presenting a challenging problem to prevent the misuse of these techniques. In this work, we tackle the problem by a new adversarial attack scheme, namely the Nullifying Attack, which cancels the image translation process and proposes a corresponding framework, the Limit-Aware Self-Guiding Gradient Sliding Attack (LaS-GSA) under a black-box setting. In other words, by processing the image with the proposed LaS-GSA before publishing, any image translation functions can be nullified, which prevents the images from malicious manipulations. First, we introduce the limit-aware RGF and the gradient sliding mechanism to estimate the gradient that adheres to the adversarial limit, i.e., the pixel value limitations of the adversarial example. We theoretically prove that our model is able to avoid the error caused by the projection in both the direction and the length. Then, an effective self-guiding prior is extracted solely from the threat model and the target image to efficiently leverage the prior information and guide the gradient estimation process. Extensive experiments demonstrate that LaS-GSA requires fewer queries to nullify the image translation process with higher success rates than 4 state-of-the-art methods.
引用
收藏
页码:16168 / 16177
页数:10
相关论文
共 34 条
  • [21] Backdoor attack and defense in federated generative adversarial network-based medical image synthesis
    Jin, Ruinan
    Li, Xiaoxiao
    MEDICAL IMAGE ANALYSIS, 2023, 90
  • [22] A Comprehensive Review and Analysis of Deep Learning-Based Medical Image Adversarial Attack and Defense
    Muoka, Gladys W.
    Yi, Ding
    Ukwuoma, Chiagoziem C.
    Mutale, Albert
    Ejiyi, Chukwuebuka J.
    Mzee, Asha Khamis
    Gyarteng, Emmanuel S. A.
    Alqahtani, Ali
    Al-antari, Mugahed A.
    MATHEMATICS, 2023, 11 (20)
  • [23] Uncertainty-Aware Diffusion-Based Adversarial Attack for Realistic Colonoscopy Image Synthesis
    Jeong, Minjae
    Cho, Hyuna
    Jung, Sungyoon
    Kim, Won Hwa
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION - MICCAI 2024, PT IX, 2024, 15009 : 647 - 658
  • [24] Exact Adversarial Attack to Image Captioning via Structured Output Learning with Latent Variables
    Xu, Yan
    Wu, Baoyuan
    Shen, Fumin
    Fan, Yanbo
    Zhang, Yong
    Shen, Heng Tao
    Liu, Wei
    2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 4130 - 4139
  • [25] Experimental Exploration of the Power of Conditional GAN in Image Reconstruction-Based Adversarial Attack Defense Strategies
    Zhang, Haibo
    Sakurai, Kouichi
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 3, AINA 2024, 2024, 201 : 151 - 162
  • [26] Semantic-Aware Attack and Defense on Deep Hashing Networks for Remote-Sensing Image Retrieval
    Li, Yansheng
    Hao, Mengze
    Liu, Rongjie
    Zhang, Zhichao
    Zhu, Hu
    Zhang, Yongjun
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2023, 61 : 1 - 14
  • [27] Image-to-image translation with Generative Adversarial Networks via retinal masks for realistic Optical Coherence Tomography imaging of Diabetic Macular Edema disorders
    Vidal, Placido L.
    de Moura, Joaquim
    Novo, Jorge
    Penedo, Manuel G.
    Ortega, Marcos
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2023, 79
  • [28] Reputation Defender: Local Black-Box Adversarial Attack against Image-Translation-Based DeepFake
    Yang, Wang
    Zhao, Lingchen
    Ye, Dengpan
    2024 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME 2024, 2024,
  • [29] CIT-GAN: Cyclic Image Translation Generative Adversarial Network With Application in Iris Presentation Attack Detection
    Yadav, Shivangi
    Ross, Arun
    2021 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION WACV 2021, 2021, : 2411 - 2420
  • [30] High-transferability black-box attack of binary image segmentation via adversarial example augmentation
    Zhu, Xuebiao
    Chen, Wu
    Jiang, Qiuping
    DISPLAYS, 2025, 87