Frequency-aware GAN for Adversarial Manipulation Generation
Peifei Zhu, Genki Osada, Hirokatsu Kataoka, Tsubasa Takahashi
Abstract
Image manipulation techniques have drawn growing concerns as manipulated images might cause morality and security problems. Various methods have been proposed to detect manipulations and achieved promising performance. However, these methods might be vulnerable to adversarial attacks. In this work, we design an Adversarial Manipulation Generation (AMG) task to explore the vulnerability of image manipulation detectors. We first propose an optimal loss function and extend existing attacks to generate adversarial examples. We observe that existing spatial attacks cause large degradation in image quality and find the loss of high-frequency detailed components might be its major reason. Inspired by this observation, we propose a novel adversarial attack that incorporates both spatial and frequency features into the GAN architecture to generate adversarial examples. We further design an encoder-decoder architecture with skip connections of high-frequency components to preserve fine details. We evaluated our method on three image manipulation detectors (FCN, ManTra-Net and MVSS-Net) with three benchmark datasets (DEFACTO, CASIAv2 and COVER). Experiments show that our method generates adversarial examples significantly fast (0.01s per image), preserves better image quality (PSNR 30% higher than spatial attacks), and achieves a high attack success rate. We also observe that the examples generated by AMG can fool both classification and segmentation models, which indicates better transferability among different tasks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on13
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- FaceForensics++: Learning to Detect Manipulated Facial ImagesAndreas Rössler, Davide Cozzolino, Luisa Verdoliva, Christian Riess et al.ICCV 2019 · 2,966 citations
- Image Manipulation Detection by Multi-View Multi-Scale SupervisionXinru Chen, Chengbo Dong, Jiaqi Ji, Juan Cao et al.ICCV 2021 · 271 citations
- Localization of Deep Inpainting Using High-Pass Fully Convolutional NetworkHaodong Li, Jiwu HuangICCV 2019 · 157 citations
- Frequency-driven Imperceptible Adversarial Attack on Semantic SimilarityCheng Luo, Qinliang Lin, Weicheng Xie, Bizhu Wu et al.CVPR 2022 · 132 citations
Related papers
- Fourier Spectrum Discrepancies in Deep Network Generated ImagesTarik Dzanic, Karan Shah, Freddie D. WitherdenNeurIPS 2020 · 235 citations
- Exploring Frequency Adversarial Attacks for Face Forgery DetectionShuai Jia, Chao Ma, Taiping Yao, Bangjie Yin et al.CVPR 2022 · 78 citations
- Naturalistic Physical Adversarial Patch for Object DetectorsYu-Chih-Tuan Hu, Jun-Cheng Chen, Bo-Han Kung, Kai-Lung Hua et al.ICCV 2021 · 224 citations
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang et al.ACM MM 2020 · 40 citations
- Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network OnceJiangfan Han, Xiaoyi Dong, Ruimao Zhang, Dongdong Chen et al.ICCV 2019 · 31 citations
