RevINN: An End-to-End Invertible Neural Network for Reversible Adversarial Examples Generation
Jielun Huang, Chi-Man Pun, Guoheng Huang
Abstract
Recent studies have shown that Reversible Adversarial Examples (RAE) can mislead unauthorized deep neural networks while remaining usable for authorized users, effectively preventing image data leakage. Existing RAE methods rely on reversibly embedding perturbation information into the original adversarial examples to enable restoration. However, this two-stage process often results in RAEs with inferior attack effectiveness and visual quality compared to the original versions. To solve these challenges, we propose a novel end-to-end Invertible Neural Network for Reversible Adversarial Examples Generation (RevINN), which directly generates RAEs in one stage by scrambling the intrinsic frequency information of images. Specifically, our RevINN consists of the Cross-Frequency Modulation Attack (CFMA) module and the High-Frequency Perturbation Enhancement (HFPE) module. CFMA selectively exchanges discriminative information between low-and highfrequency wavelet components to achieve adversariality. To fully alter high-frequency semantics, HFPE innovatively employs a tri-branch structure for fine-grained modulation among high-frequency subbands, enhancing perturbation strength. Finally, the modified components are recomposed into RAEs via the inverse wavelet transform. Our RevINN is optimized with adversarial, perceptual, and invertible losses, and can restore images based on the reversibility of the wavelet operations and network modules. Extensive experiments demonstrate that our RevINN achieves stateof-the-art RAE generation quality. The code is available at: https://github.com/WongJaylen/RevINN .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d6f5c58f-19aa-4e30-90ed-6fd112f6d9e1Builds on17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec et al.NeurIPS 2020 · 9,171 citations
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou et al.ICCV 2021 · 8,921 citations
- Barlow Twins: Self-Supervised Learning via Redundancy ReductionJure Zbontar, Li Jing, Ishan Misra, Yann LeCun et al.ICML 2021 · 2,942 citations
- HiNet: Deep Image Hiding by Invertible NetworkJunpeng Jing, Xin Deng, Mai Xu, Jianyi Wang et al.ICCV 2021 · 301 citations
Related papers
- Imperceptible Adversarial Attack via Invertible Neural NetworksZihan Chen, Ziyue Wang, Jun-Jie Huang, Wentao Zhao et al.AAAI 2023 · 34 citations
- IRWArt: Levering Watermarking Performance for Protecting High-quality Artwork ImagesYuanjing Luo, Tongqing Zhou, Fang Liu, Zhiping CaiWWW 2023 · 26 citations
- JPEG-RAE: Reversible Adversarial Example for Privacy and Copyright Protection of JPEG ImagesDahao Fu, Jiangqun Ni, Jian ZhangACM MM 2025
- DP-RAE: A Dual-Phase Merging Reversible Adversarial Example for Image Privacy ProtectionJiajie Zhu, Xia Du, Jizhe Zhou, Chi-Man Pun et al.ACM MM 2024 · 6 citations
- IWRN: A Robust Blind Watermarking Method for Artwork Image Copyright Protection Against Noise AttackFeifei Kou, Yuhan Yao, Siyuan Yao, Jiahao Wang et al.AAAI 2025 · 5 citations
