随机深度特征选择对保护图像篡改检测器抵御对抗样本的有效性
密码学与安全
2019-12-30 v2 计算机视觉与模式识别
机器学习
图像与视频处理
摘要
我们研究文献[1]中提出的、用于提升取证检测器对定向攻击鲁棒性的随机特征选择方法,能否推广至基于深度学习特征检测器。具体地,我们研究针对原始 CNN 图像篡改检测器的对抗样本,向其他依赖从原始网络扁平层提取的特征的随机子集的检测器(一个全连接神经网络与一个线性 SVM)的可迁移性。我们考虑三种图像篡改检测任务(缩放、中值滤波与自适应直方图均衡化)、两种原始网络架构与三类攻击所得结果表明:特征随机化有助于阻碍攻击的可迁移性,即便在某些情况下,仅改变检测器架构,甚至重新训练检测器,便足以阻止攻击的迁移。
引用
@article{arxiv.1910.12392,
title = {Effectiveness of random deep feature selection for securing image manipulation detectors against adversarial examples},
author = {Mauro Barni and Ehsan Nowroozi and Benedetta Tondi and Bowen Zhang},
journal= {arXiv preprint arXiv:1910.12392},
year = {2019}
}
备注
Submitted to the ICASSP conference to be held in 2020, Barcelona, Spain