Residential College | false |
Status | 已發表Published |
Frequency-constrained transferable adversarial attack on image manipulation detection and localization | |
Zeng, Yijia; Pun, Chi Man | |
2024-06-05 | |
Source Publication | The Visual Computer |
ISSN | 0178-2789 |
Volume | 40Issue:7Pages:4817-4828 |
Abstract | Recent works have demonstrated the great performance of forgery image forensics based on deep learning, but there is still a risk that detectors could be susceptible to unknown illegal attacks, raising growing security concerns. This paper starts from the perspective of reverse forensics and explores the vulnerabilities of current image manipulation detectors to achieve targeted attacks. We present a novel reverse decision aggregate gradient attack under low-frequency constraints (RevAggAL). Specifically, we first propose a novel pixel reverse content decision-making (PRevCDm) loss to optimize perturbation generation with a specific principle more suitable for segmenting manipulated regions. Then, we introduce the low-frequency component to constrain the perturbation into more imperceptible details, significantly avoiding the degradation of image quality. We also consider aggregating gradients on model-agnostic features to enhance the transferability of adversarial examples in black-box scenarios. We evaluate the effectiveness of our method on three representative detectors (ResFCN, MVSSNet, and OSN) with five widely used forgery datasets (COVERAGE, COLUMBIA, CASIA1, NIST 2016, and Realistic Tampering). Experimental results show that our method improves the attack success rate (ASR) while ensuring better image quality. |
Keyword | Adversarial Attack Forgery Image Detection And Localization Reverse Image Forensics Transferability |
DOI | 10.1007/s00371-024-03482-4 |
URL | View the original |
Indexed By | SCIE |
Language | 英語English |
WOS Research Area | Computer Science |
WOS Subject | Computer Science, Software Engineering |
WOS ID | WOS:001242155100004 |
Publisher | SPRINGER, ONE NEW YORK PLAZA, SUITE 4600 , NEW YORK, NY 10004, UNITED STATES |
Scopus ID | 2-s2.0-85195200334 |
Fulltext Access | |
Citation statistics | |
Document Type | Journal article |
Collection | Faculty of Science and Technology DEPARTMENT OF COMPUTER AND INFORMATION SCIENCE |
Corresponding Author | Pun, Chi Man |
Affiliation | Department of Computer and Information Science, University of Macau, Macao |
First Author Affilication | University of Macau |
Corresponding Author Affilication | University of Macau |
Recommended Citation GB/T 7714 | Zeng, Yijia,Pun, Chi Man. Frequency-constrained transferable adversarial attack on image manipulation detection and localization[J]. The Visual Computer, 2024, 40(7), 4817-4828. |
APA | Zeng, Yijia., & Pun, Chi Man (2024). Frequency-constrained transferable adversarial attack on image manipulation detection and localization. The Visual Computer, 40(7), 4817-4828. |
MLA | Zeng, Yijia,et al."Frequency-constrained transferable adversarial attack on image manipulation detection and localization".The Visual Computer 40.7(2024):4817-4828. |
Files in This Item: | There are no files associated with this item. |
Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.
Edit Comment