Targeted Attack and Defense for Deep Hashing

被引:12
|
作者
Wang, Xunguang [1 ]
Zhang, Zheng [1 ,2 ]
Lu, Guangming [1 ]
Xu, Yong [1 ,2 ]
机构
[1] Harbin Inst Technol, Shenzhen Key Lab Visual Object Detect & Recognit, Shenzhen 518055, Peoples R China
[2] Peng Cheng Lab, Shenzhen 518055, Peoples R China
基金
中国国家自然科学基金;
关键词
deep hashing; similarity retrieval; adversarial example; targeted attack; adversarial defense; adversarial training;
D O I
10.1145/3404835.3463233
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep hashing methods have been intensively studied and successfully applied in massive fast image retrieval. However, inherited from the deficiency of deep neural networks, deep hashing models can be easily fooled by adversarial examples, which brings a serious security risk to hashing based retrieval. In this paper, we propose a novel targeted attack method and the first defense scheme for deep hashing based retrieval. Specifically, a simple yet effective PrototypeNet is designed to generate category-level semantic embedding (dubbed prototype code) regarded as the semantic representative of the target label, which preserves the semantic similarity with relevant labels and dissimilarity with irrelevant labels. Subsequently, we conduct the targeted attack by minimizing the Hamming distance between the hash code of the adversarial sample and the prototype code. Moreover, we provide an adversarial training algorithm to improve the adversarial robustness of deep hashing networks. Extensive experiments demonstrate our method can produce high-quality adversarial samples with the benefit of superior targeted attack performance over state-of-the-arts. Importantly, our adversarial defense framework can significantly boost the robustness of hashing networks against adversarial attacks on deep hashing based retrieval. The code is available at https://github.com/xunguangwang/Targeted- Attack-and-Defense-for-Deep-Hashing.
引用
收藏
页码:2298 / 2302
页数:5
相关论文
共 50 条
  • [1] Prototype-supervised Adversarial Network for Targeted Attack of Deep Hashing
    Wang, Xunguang
    Zhang, Zheng
    Wu, Baoyuan
    Shen, Fumin
    Lu, Guangming
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 16352 - 16361
  • [2] Targeted Adversarial Attack Against Deep Cross-Modal Hashing Retrieval
    Wang, Tianshi
    Zhu, Lei
    Zhang, Zheng
    Zhang, Huaxiang
    Han, Junwei
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2023, 33 (10) : 6159 - 6172
  • [3] Efficient Non-Targeted Attack for Deep Hashing Based Image Retrieval
    Qin, Chuan
    Wu, Liang
    Zhang, Xinpeng
    Feng, Guorui
    IEEE SIGNAL PROCESSING LETTERS, 2021, 28 : 1893 - 1897
  • [4] Targeted Attack of Deep Hashing Via Prototype-Supervised Adversarial Networks
    Zhang, Zheng
    Wang, Xunguang
    Lu, Guangming
    Shen, Fumin
    Zhu, Lei
    IEEE TRANSACTIONS ON MULTIMEDIA, 2021, 24 : 3392 - 3404
  • [5] All Points Guided Adversarial Generator for Targeted Attack Against Deep Hashing Retrieval
    Tu, Rongxin
    Kang, Xiangui
    Tan, Chee Wei
    Chi, Chi-Hung
    Lam, Kwok-Yan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 1695 - 1709
  • [6] AdvHash: Set-to-set Targeted Attack on Deep Hashing with One Single Adversarial Patch
    Hu, Shengshan
    Zhang, Yechao
    Liu, Xiaogeng
    Zhang, Leo Yu
    Li, Minghui
    Jin, Hai
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 2335 - 2343
  • [7] Generative Collision Attack on Deep Image Hashing
    Ying, Luyang
    Xiong, Cheng
    Qin, Chuan
    Luo, Xiangyang
    Qian, Zhenxing
    Zhang, Xinpeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 2748 - 2762
  • [8] Semantic-Aware Attack and Defense on Deep Hashing Networks for Remote-Sensing Image Retrieval
    Li, Yansheng
    Hao, Mengze
    Liu, Rongjie
    Zhang, Zhichao
    Zhu, Hu
    Zhang, Yongjun
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2023, 61 : 1 - 14
  • [9] Adversarial Attack and Defense in Deep Ranking
    Zhou, Mo
    Wang, Le
    Niu, Zhenxing
    Zhang, Qilin
    Zheng, Nanning
    Hua, Gang
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (08) : 5306 - 5324
  • [10] A Smart Adversarial Attack on Deep Hashing Based Image Retrieval
    Lu, Junda
    Chen, Mingyang
    Sun, Yifang
    Wang, Wei
    Wang, Yi
    Yang, Xiaochun
    PROCEEDINGS OF THE 2021 INTERNATIONAL CONFERENCE ON MULTIMEDIA RETRIEVAL (ICMR '21), 2021, : 227 - 235