English

Reversible Adversarial Examples with Beam Search Attack and Grayscale Invariance

Cryptography and Security 2023-06-21 v1

Abstract

Reversible adversarial examples (RAE) combine adversarial attacks and reversible data-hiding technology on a single image to prevent illegal access. Most RAE studies focus on achieving white-box attacks. In this paper, we propose a novel framework to generate reversible adversarial examples, which combines a novel beam search based black-box attack and reversible data hiding with grayscale invariance (RDH-GI). This RAE uses beam search to evaluate the adversarial gain of historical perturbations and guide adversarial perturbations. After the adversarial examples are generated, the framework RDH-GI embeds the secret data that can be recovered losslessly. Experimental results show that our method can achieve an average Peak Signal-to-Noise Ratio (PSNR) of at least 40dB compared to source images with limited query budgets. Our method can also achieve a targeted black-box reversible adversarial attack for the first time.

Keywords

Cite

@article{arxiv.2306.11322,
  title  = {Reversible Adversarial Examples with Beam Search Attack and Grayscale Invariance},
  author = {Haodong Zhang and Chi Man Pun and Xia Du},
  journal= {arXiv preprint arXiv:2306.11322},
  year   = {2023}
}

Comments

Submitted to ICICS2023

R2 v1 2026-06-28T11:09:20.243Z