节点文献
数字图像分类可逆对抗样本研究
Research on Reversible Adversarial Example for Digital Image Classification
【作者】 陈莉;
【作者基本信息】 安徽大学 , 计算机科学与技术, 2023, 硕士
【摘要】 随着人工智能技术在各个领域的应用,利用对抗样本保护图像的方法也受到广泛关注和研究。然而,对抗扰动的添加导致原始图像数据被破坏,使得图像在某些领域,特别是数字取证中失去使用价值。可逆对抗攻击的提出不仅实现了图像免受恶意模型的检索,还能保证授权模型可以恢复原始图像。目前可逆对抗攻击方法主要分为有损可逆对抗攻击和无损可逆对抗攻击。无损可逆对抗攻击主要通过可逆信息隐藏技术嵌入信息,实现原始图像的无损恢复。然而,无损可逆对抗攻击方法存在攻击性能和图像视觉质量不理想的问题。本文针对这些问题展开研究,结合对抗攻击技术和可逆信息隐藏算法提出两种可逆对抗样本生成方法,主要工作如下:(1)基于YUV颜色空间的可逆攻击针对现有无损可逆对抗攻击方法中信息嵌入对原始对抗扰动信号的影响,本文提出基于YUV颜色空间的可逆攻击方法。该方法利用YUV颜色空间中亮度通道和色度通道的相互独立性,采用对抗攻击技术在亮度通道添加对抗扰动,并引入注意力机制缩小扰动区域,然后通过可逆信息隐藏算法将对抗扰动引起的亮度通道失真可逆嵌入到色度通道中,实现可逆攻击。与现有的可逆对抗攻击方法相比,该方法不仅能够无损恢复原始图像,还进一步提高了攻击性能和图像视觉质量。(2)面向局部可视对抗扰动的可逆攻击传统的无损可逆对抗攻击方法忽视了局部可视对抗扰动的可逆性,为此,本文面向局部可视对抗扰动,提出一种无损可逆攻击方法。该方法首先利用对抗攻击技术生成对抗补丁,并通过盆地跳跃进化算法确定对抗补丁的最优位置得到对抗样本。接着,采用可逆信息隐藏算法将对抗补丁替换部分的原始图像嵌入对抗样本中。最后,将辅助信息嵌入图像左上角的矩形区域生成可逆对抗样本。在嵌入过程中引入Web P压缩和B-R-G嵌入原则来降低图像失真。此外,为了保证攻击性能,将对抗补丁以外的图像区域进行重组作为载体图像以嵌入信息。经实验验证,该方法成功实现了局部可视对抗扰动的可逆性,并且生成的可逆对抗样本具有较好的攻击性能和图像视觉质量。
【Abstract】 With the application of artificial intelligence technology in various fields,the method of image protection with adversarial examples is also widely concerned and researched.However,the addition of adversarial perturbation leads to the destruction of original image data,making the image lose its value in some fields,especially in digital forensics.The proposal of reversible adversarial attack not only realizes the retrieval of images from malicious models,but also ensures that the authorized model can restore the original images.The current reversible adversarial attack methods are mainly divided into lossy reversible adversarial attack and lossless reversible adversarial attack.The lossless reversible adversarial attack mainly embeds information through reversible data hiding to restore original images without distortion.However,the lossless reversible adversarial attack has problems of poor attack performance and image visual quality.This thesis studies these problems and proposes two reversible adversarial example generation methods by combining adversarial attack techniques and reversible data hiding algorithms.The main work is as follows:(1)Reversible attack based on YUV colorspaceThis thesis proposes a reversible attack method based on YUV colorspace to address the effect of information embedding on the original adversarial perturbation signal in existing lossless reversible adversarial attack methods.The method takes advantage of the mutual independence of the luminance and chrominance channels in the YUV colorspace,the adversarial attack technique is used to add adversarial perturbation to the luminance channel and the attention map is introduced to narrow the perturbation region,and then the reversible adversarial example is generated by reversibly embedding the distortion caused by the adversarial perturbation in the luminance channel into the chrominance channels through a reversible data hiding algorithm.Compared with existing reversible adversarial attack methods,this method not only achieve the lossless recovery of the original image,but also improve the attack performance and image visual quality.(2)Reversible attack for local visible adversarial perturbationTraditional lossless reversible adversarial attack methods ignore the reversibility of local visible adversarial perturbation.Therefore,this thesis proposes a lossless reversible attack method for local visible adversarial perturbation.In this method,the adversarial attack technique is used to generate the adversarial patch,and the basin hopping evolution algorithm is introduced to determine the optimal position of the adversarial patch,thereby generating the adversarial example.Then,the reversible data hiding algorithm is used to embed the original image of the replaced part of the adversarial patch into the adversarial example.Finally,the auxiliary information is embedded into the rectangular area in the upper left corner of the image to generate reversible adversarial examples.Web P compression and B-R-G embedding principles are introduced in the embedding process to reduce image distortion.In addition,to ensure the attack performance,the image area beyond the adversarial patch is reorganized as the carrier image to embed information.Experimental results show that this method successfully realizes the reversibility of local visible adversarial perturbation,and the generated reversible adversarial examples have better attack performance and image visual quality.
【Key words】 Deep learning; Adversarial attack; Reversible data hiding; Reversible adversarial attack;
- 【网络出版投稿人】 安徽大学 【网络出版年期】2025年 03期
- 【分类号】TP391.41;TP18