Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image Retrieval
Long Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen, Yunming Zhang
Abstract
Deep Hashing (DH)-based image retrieval has been widely applied to face-matching systems due to its accuracy and efficiency. However, this convenience comes with an increased risk of privacy leakage. DH models inherit the vulnerability to adversarial attacks, which can be used to prevent the retrieval of private images. Existing adversarial attacks against DH typically target a single image or a specific class of images, lacking universal adversarial perturbation for the entire hash dataset. In this paper, we propose the first universal transferable adversarial perturbation against DH-based facial image retrieval, a single perturbation can protect all images. Specifically, we explore the relationship between clusters learned by different DH models and define the optimization objective of universal perturbation as leaving from the overall hash center. To mitigate the challenge of single-objective optimization, we randomly obtain sub-cluster centers and further propose sub-task-based meta-learning to aid in overall optimization. We test our method with popular facial datasets and DH models, indicating impressive cross-image, -identity, -model, and -scheme universal anti-retrieval performance. Compared to state-of-the-art methods, our performance is competitive in white-box settings and exhibits significant improvements of 10% -70% in transferability in all black-box settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Generalized Debiased Semi-Supervised Hashing for Large-Scale Image RetrievalXingbo Liu, Xuening Zhang, Xiushan Nie, Yang Shi et al.AAAI 2025 · 4 citations
- RFNNS: Robust Fixed Neural Network Steganography with Universal Text-to-Image ModelsYu Cheng, Jiuan Zhou, Jiawei Chen, Zhaoxia Yin et al.AAAI 2026
Builds on10
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- Targeted Mismatch Adversarial Attack: Query With a Flower to Retrieve the TowerGiorgos Tolias, Filip Radenovic, Ondrej ChumICCV 2019 · 76 citations
- AdvHash: Set-to-set Targeted Attack on Deep Hashing with One Single Adversarial PatchShengshan Hu, Yechao Zhang, Xiaogeng Liu, Leo Yu Zhang et al.ACM MM 2021 · 34 citations
- Adversarial Attack on Deep Cross-Modal Hamming RetrievalChao Li, Shangqian Gao, Cheng Deng, Wei Liu et al.ICCV 2021 · 29 citations
Related papers
- Precise Target-Oriented Attack against Deep Hashing-based RetrievalWenshuo Zhao, Jingkuan Song, Shengming Yuan, Lianli Gao et al.ACM MM 2023 · 8 citations
- You See What I Want You To See: Exploring Targeted Black-Box Transferability Attack for Hash-Based Image Retrieval SystemsYanru Xiao, Cong WangCVPR 2021
- Evade Deep Image Retrieval by Stashing Private Images in the Hash SpaceYanru Xiao, Cong Wang, Xing GaoCVPR 2020
- HUANG: A Robust Diffusion Model-based Targeted Adversarial Attack Against Deep Hashing RetrievalChihan Huang, Xiaobo ShenAAAI 2025 · 5 citations
- Spectral-Adaptive Adversarial Hashing for Robust Image RetrievalGang Zhou, Shibiao Xu, Xiaolong Zheng, Daniel Dajun ZengSIGIR 2026
