USENIX Security2019Top-tier venue
Seeing is Not Believing: Camouflage Attacks on Image Scaling Algorithms
Qixue Xiao, Yufei Chen, Chao Shen, Yu Chen, Kang Li
Abstract
Image scaling algorithms are intended to preserve the visual features before and after scaling, which is commonly used in numerous visual and image processing applications. In this paper, we demonstrate an automated attack against common scaling algorithms, i.e. to automatically generate camouflage images whose visual semantics change dramatically after scaling. To illustrate the threats from such camouflage attacks, we choose several computer vision applications as targeted victims, including multiple image classification applications based on popular deep learning frameworks, as well as mainstream web browsers. Our experimental results show that such attacks can cause different visual results after scaling and thus create evasion or data poisoning effect to these victim applications. We also present an algorithm that can successfully enable attacks against famous cloud-based image services (such as those from Microsoft Azure, Aliyun, Baidu, and Tencent) and cause obvious misclassification effects, even when the details of image processing (such as the exact scaling algorithm and scale dimension parameters) are hidden in the cloud. To defend against such attacks, this paper suggests a few potential countermeasures from attack prevention to detection. We provide a video to demonstrate the attack effects, which is available at the following URL: https://youtu.be/Vm2N0mb14Ow . This paper studies the commonly used scaling implementations, especially for image scaling algorithms employed in popular deep learning frameworks, and reveals potential threats to the image scaling process. Our contributions can be summarized as follows:
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1ec57ec6-a8ea-4190-a4d0-60350ce42310Cited by top-tier papers19
- Intriguing Properties of Adversarial ML Attacks in the Problem SpaceFabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, Lorenzo CavallaroS&P 2020 · 334 citations
- On Aliased Resizing and Surprising Subtleties in GAN EvaluationGaurav Parmar, Richard Zhang, Jun-Yan ZhuCVPR 2022 · 250 citations
- Privacy Side Channels in Machine Learning SystemsEdoardo Debenedetti, Giorgio Severi, Milad Nasr, Christopher A. Choquette-Choo et al.USENIX Security 2024 · 52 citations
- Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingXingshuo Han, Guowen Xu, Yuan Zhou, Xuehuan Yang et al.ACM MM 2022 · 48 citations
- It's Not What It Looks Like: Manipulating Perceptual Hashing based ApplicationsQingying Hao, Licheng Luo, Steve T. K. Jan, Gang WangCCS 2021 · 36 citations
Builds on2
Related papers
- Adversarial Preprocessing: Understanding and Preventing Image-Scaling Attacks in Machine LearningErwin Quiring, David Klein, Daniel Arp, Martin Johns et al.USENIX Security 2020
- Rethinking Image-Scaling Attacks: The Interplay Between Vulnerabilities in Machine Learning SystemsYue Gao, Ilia Shumailov, Kassem FawazICML 2022 · 12 citations
- Morié Attack (MA): A New Potential Risk of Screen PhotosDantong Niu, Ruohao Guo, Yisen WangNeurIPS 2021 · 14 citations
- Am I a Real or Fake Celebrity? Evaluating Face Recognition and Verification APIs under Deepfake Impersonation AttackShahroz Tariq, Sowon Jeon, Simon S. WooWWW 2022 · 33 citations
- NetGuard: Protecting Commercial Web APIs from Model Inversion Attacks using GAN-generated Fake SamplesXueluan Gong, Ziyao Wang, Yanjiao Chen, Qian Wang et al.WWW 2023 · 8 citations
