Attack as the Best Defense: Nullifying Image-to-image Translation GANs via Limit-aware Adversarial Attack

被引:6
|
作者
Yeh, Chin-Yuan [1 ,3 ]
Chen, Hsi-Wen [1 ]
Shuai, Hong-Han [2 ]
Yang, De-Nian [3 ]
Chen, Ming-Syan [1 ]
机构
[1] Natl Taiwan Univ, Taipei, Taiwan
[2] Natl Yangming Jiaotong Univ, Taipei, Taiwan
[3] Acad Sinica, Taipei, Taiwan
来源
2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021) | 2021年
关键词
D O I
10.1109/ICCV48922.2021.01588
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the great success of image-to-image (Img2Img) translation GANs, many applications with ethics issues arise, e.g., DeepFake and DeepNude, presenting a challenging problem to prevent the misuse of these techniques. In this work, we tackle the problem by a new adversarial attack scheme, namely the Nullifying Attack, which cancels the image translation process and proposes a corresponding framework, the Limit-Aware Self-Guiding Gradient Sliding Attack (LaS-GSA) under a black-box setting. In other words, by processing the image with the proposed LaS-GSA before publishing, any image translation functions can be nullified, which prevents the images from malicious manipulations. First, we introduce the limit-aware RGF and the gradient sliding mechanism to estimate the gradient that adheres to the adversarial limit, i.e., the pixel value limitations of the adversarial example. We theoretically prove that our model is able to avoid the error caused by the projection in both the direction and the length. Then, an effective self-guiding prior is extracted solely from the threat model and the target image to efficiently leverage the prior information and guide the gradient estimation process. Extensive experiments demonstrate that LaS-GSA requires fewer queries to nullify the image translation process with higher success rates than 4 state-of-the-art methods.
引用
收藏
页码:16168 / 16177
页数:10
相关论文
共 34 条
  • [31] GAN-based image steganography for enhancing security via adversarial attack and pixel-wise deep fusion
    Chao Yuan
    Hongxia Wang
    Peisong He
    Jie Luo
    Bin Li
    Multimedia Tools and Applications, 2022, 81 : 6681 - 6701
  • [32] GAN-based image steganography for enhancing security via adversarial attack and pixel-wise deep fusion
    Yuan, Chao
    Wang, Hongxia
    He, Peisong
    Luo, Jie
    Li, Bin
    MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (05) : 6681 - 6701
  • [33] Towards Image-to-Video Translation: A Structure-Aware Approach via Multi-stage Generative Adversarial Networks
    Zhao, Long
    Peng, Xi
    Tian, Yu
    Kapadia, Mubbasir
    Metaxas, Dimitris N.
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2020, 128 (10-11) : 2514 - 2533
  • [34] Towards Image-to-Video Translation: A Structure-Aware Approach via Multi-stage Generative Adversarial Networks
    Long Zhao
    Xi Peng
    Yu Tian
    Mubbasir Kapadia
    Dimitris N. Metaxas
    International Journal of Computer Vision, 2020, 128 : 2514 - 2533