AIセキュリティポータル K Program
Unveiling Hidden Visual Information: A Reconstruction Attack Against Adversarial Visual Information Hiding
Share
Abstract
This paper investigates the security vulnerabilities of adversarial-example-based image encryption by executing data reconstruction (DR) attacks on encrypted images. A representative image encryption method is the adversarial visual information hiding (AVIH), which uses type-I adversarial example training to protect gallery datasets used in image recognition tasks. In the AVIH method, the type-I adversarial example approach creates images that appear completely different but are still recognized by machines as the original ones. Additionally, the AVIH method can restore encrypted images to their original forms using a predefined private key generative model. For the best security, assigning a unique key to each image is recommended; however, storage limitations may necessitate some images sharing the same key model. This raises a crucial security question for AVIH: How many images can safely share the same key model without being compromised by a DR attack? To address this question, we introduce a dual-strategy DR attack against the AVIH encryption method by incorporating (1) generative-adversarial loss and (2) augmented identity loss, which prevent DR from overfitting -- an issue akin to that in machine learning. Our numerical results validate this approach through image recognition and re-identification benchmarks, demonstrating that our strategy can significantly enhance the quality of reconstructed images, thereby requiring fewer key-sharing encrypted images. Our source code to reproduce our results will be available soon.
Hiding visual information via obfuscating adversarial perturbations
Z. Su, D. Zhou, N. Wang, D. Liu, Z. Wang, X. Gao
Published: 2023
Cloud security issues and challenges: A survey
A. Singh, K. Chatterjee
Published: 2017
TransReID: Transformer-based object re-identification
S. He, H. Luo, P. Wang, F. Wang, H. Li, W. Jiang
Published: 2021
Hidden: Hiding data with deep networks
J. Zhu, R. Kaplan, J. Johnson, L. Fei-Fei
Published: 2018
Visual security evaluation of perceptually encrypted images based on image importance
T. Xiang, Y. Yang, H. Liu, S. Guo
Published: 2019
PEID: A perceptually encrypted image database for visual security evaluation
S. Guo, T. Xiang, X. Li, Y. Yang
Published: 2019
Low-complexity deep convolutional neural networks on fully homomorphic encryption using multiplexed parallel convolutions
E. Lee, J.-W. Lee, J. Lee, Y.-S. Kim, Y. Kim, J.-S. No, W. Choi
Published: 2022
Optimized privacy-preserving cnn inference with fully homomorphic encryption
D. Kim, C. Guyot
Published: 2023
Re-thinking model inversion attacks against deep neural networks
N.-B. Nguyen, K. Chandrasegaran, M. Abdollahzadeh, N.-M. Cheung
Published: 2023
The role of class information in model inversion attacks against image deep learning classifiers
Z. Tian, L. Cui, C. Zhang, S. Tan, S. Yu, Y. Tian
Published: 2023
Boosting Model Inversion Attacks with Adversarial Examples
Shuai Zhou, Tianqing Zhu, Dayong Ye, Xin Yu, Wanlei Zhou
Published: 2023.6.24
Membership inference attacks on machine learning: A survey
H. Hu, Z. Salcic, L. Sun, G. Dobbie, P. S. Yu, X. Zhang
Published: 2022
Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing
Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, Thomas Ristenpart
Published: 2014
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, Thomas Ristenpart
Published: 2015
Model inversion attacks for prediction systems: Without knowledge of non-sensitive attributes
S. Hidano, T. Murakami, S. Katsumata, S. Kiyomoto, G. Hanaoka
Published: 2017
Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy
Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, John Wensing
Published: 2016
Privacy-Preserving Machine Learning with Fully Homomorphic Encryption for Deep Neural Network
Joon-Woo Lee, HyungChul Kang, Yongwoo Lee, Woosuk Choi, Jieun Eom, Maxim Deryabin, Eunsang Lee, Junghyun Lee, Donghoon Yoo, Young-Sik Kim, Jong-Seon No
Published: 2021.6.14
Deepedn: A deep-learning-based image encryption and decryption network for internet of medical things
Y. Ding, G. Wu, D. Chen, N. Zhang, L. Gong, M. Cao, Z. Qin
Published: 2020
A gan-based image transformation scheme for privacy-preserving deep neural networks
W. Sirichotedumrong, H. Kiya
Published: 2021
A jigsaw puzzle solver-based attack on block-wise image encryption for privacy-preserving dnns
T. Chuman, H. Kiya
Published: 2023
Watermarking Vision-Language Pre-trained Models for Multi-modal Embedding as a Service
Yuanmin Tang, Jing Yu, Keke Gai, Xiangyan Qu, Yue Hu, Gang Xiong, Qi Wu
Published: 2023.11.10
A novel model watermarking for protecting generative adversarial network
T. Qiao, Y. Ma, N. Zheng, H. Wu, Y. Chen, M. Xu, X. Luo
Published: 2023
Hiding images in plain sight: Deep steganography
Shumeet Baluja
Published: 2017
Arcface: Additive angular margin loss for deep face recognition
Jiankang Deng, Jia Guo, Niannan Xue, Stefanos Zafeiriou
Published: 2019
Adaface: Quality adaptive margin for face recognition
Minchul Kim, Anil K Jain, Xiaoming Liu
Published: 2022
Generative adversarial nets
I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, Y. Bengio
Published: 2014
Labeled faces in the wild: A database for studying face recognition in unconstrained environments
Gary B. Huang, Manu Ramesh, Tamara Berg, Erik Learned-Miller
Published: 2007
AgeDB: The first manually collected, in-the-wild age database
S. Moschoglou, A. Papaioannou, C. Sagonas, J. Deng, I. Kotsia, S. Zafeiriou
Published: 2017
Frontal to profile face verification in the wild
S. Sengupta, J.-C. Chen, C. Castillo, V. M. Patel, R. Chellappa, D. W. Jacobs
Published: 2016
Deep Learning Face Attributes in the Wild
Ziwei Liu, Ping Luo, Xiaogang Wang, Xiaoou Tang
Published: 2015
U-Net: Convolutional networks for biomedical image segmentation
O. Ronneberger, P. Fischer, T. Brox
Published: 2015
CLIPScore: a reference-free evaluation metric for image captioning
J. Hessel, A. Holtzman, M. Forbes, R. L. Bras, Y. Choi
Published: 2021
Image quality assessment: from error visibility to structural similarity
Z. Wang, A. C. Bovik, H. R. Sheikh, E. P. Simoncelli
Published: 2004
PROVID: Progressive and multimodal vehicle reidentification for large-scale urban surveillance
X. Liu, W. Liu, T. Mei, H. Ma
Published: 2018
Scalable person re-identification: A benchmark
L. Zheng, L. Shen, L. Tian, S. Wang, J. Wang, Q. Tian
Published: 2015
3D object representations for fine-grained categorization
J. Krause, M. Stark, J. Deng, L. Fei-Fei
Published: 2013
Region-based quality estimation network for large-scale person re-identification
G. Song, B. Leng, Y. Liu, C. Hetang, S. Cai
Published: 2018
Share