Query-efficient Attack for Black-box Image Inpainting Forensics via Reinforcement Learning
Xianbo Mo, Shunquan Tan, Bin Li, Jiwu Huang
Abstract
Recently, image inpainting has become a common tool for manipulating nature images in a malicious manner, which has led to the rapid advancement of inpainting forensics. Although current forensics methods have shown precise location of inpainting regions and reliable robustness against image post-processing operations, it remains unclear whether they can effectively resist the possible attacks in real-world scenarios. To identify potential flaws, we propose a novel black-box anti-forensics framework to attack inpainting forensics methods, which employs reinforcement learning to generate a query-efficient countermeasure, named RLGC. To this end, we define reinforcement learning paradigm to model the Markov Decision Process of query-based black-box anti-forensics scenario. Specifically, pixel-wise agents are used to modulate anti-forensics images based on action selection and query forensics methods to obtain corresponding outputs. Later, reward function evaluates attack effect and image distortion with these outputs. To maximize the cumulative reward, policy and value networks are integrated and trained by Asynchronous Advantage Actor-Critic algorithm. Experimental results demonstrate that, without visually detectable distortion on anti-forensics images, RLGC achieves remarkable attack effects in a highly query-effcient way against various black-box inpainting forensics methods, even outperforming the most representative white-box attack method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Free-Form Image Inpainting With Gated ConvolutionJiahui Yu, Zhe Lin, Jimei Yang, Xiaohui Shen et al.ICCV 2019 · 1,990 citations
- Region Normalization for Image InpaintingTao Yu, Zongyu Guo, Xin Jin, Shilin Wu et al.AAAI 2020 · 204 citations
- Localization of Deep Inpainting Using High-Pass Fully Convolutional NetworkHaodong Li, Jiwu HuangICCV 2019 · 157 citations
- Image Inpainting Detection via Enriched Attentive Pattern with Near Original Image AugmentationWenhan Yang, Rizhao Cai, Alex C. KotACM MM 2022 · 5 citations
- SurFree: A Fast Surrogate-Free Black-Box AttackThibault Maho, Teddy Furon, Erwan Le MerrerCVPR 2021
Related papers
- Natural Black-Box Adversarial Examples against Deep Reinforcement LearningMengran Yu, Shiliang SunAAAI 2022 · 15 citations
- Reinforcement Learning-Based Black-Box Model Inversion AttacksGyojin Han, Jaehyun Choi, Haeil Lee, Junmo KimCVPR 2023
- Amnesia as a Catalyst for Enhancing Black Box Pixel Attacks in Image Classification and Object DetectionDongsu Song, Daehwa Ko, Jay Hoon JungNeurIPS 2024 · 2 citations
- Reinforcement Learning-based Adversarial Attacks on Object Detectors using Reward ShapingZhenbo Shi, Wei Yang, Zhenbo Xu, Zhidong Yu et al.ACM MM 2023 · 3 citations
- Policy-Driven Attack: Learning to Query for Hard-label Black-box Adversarial ExamplesZiang Yan, Yiwen Guo, Jian Liang, Changshui ZhangICLR 2021 · 19 citations
