Universal Adversarial Perturbations Through the Lens of Deep Steganography: Towards a Fourier Perspective
Chaoning Zhang, Philipp Benz, Adil Karjauv, In So Kweon
Abstract
The booming interest in adversarial attacks stems from a misalignment between human vision and a deep neural network (DNN), i.e. a human imperceptible perturbation fools the DNN. Moreover, a single perturbation, often called universal adversarial perturbation (UAP), can be generated to fool the DNN for most images. A similar misalignment phenomenon has recently also been observed in the deep steganography task, where a decoder network can retrieve a secret image back from a slightly perturbed cover image. We attempt explaining the success of both in a unified manner from the Fourier perspective. We perform task-specific and joint analysis and reveal that (a) frequency is a key factor that influences their performance based on the proposed entropy metric for quantifying the frequency distribution; (b) their success can be attributed to a DNN being highly sensitive to high-frequency content. We also perform feature layer analysis for providing deep insight on model generalization and robustness. Additionally, we propose two new variants of universal perturbations: (1) Universal Secret Adversarial Perturbation (USAP) that simultaneously achieves attack and hiding; (2) high-pass UAP (HP-UAP) that is less visible to the human eye. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f6b513cb-21ea-49d2-81f4-b6a82e044480Cited by top-tier papers5
- Data-free Universal Adversarial Perturbation and Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonICCV 2021 · 83 citations
- Investigating Top-k White-Box and Transferable Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, Jae-Won Cho et al.CVPR 2022 · 34 citations
- Towards Nonlinear Sparse AUC Maximization via Compositional Stochastic Hard ThresholdingWenkang Wang, Dongxu Liu, Bin GuAAAI 2026
- RFNNS: Robust Fixed Neural Network Steganography with Universal Text-to-Image ModelsYu Cheng, Jiuan Zhou, Jiawei Chen, Zhaoxia Yin et al.AAAI 2026
- Compositional Targeted Multi-Label Universal PerturbationsHassan Mahmood, Ehsan ElhamifarCVPR 2025
Builds on5
- CD-UAP: Class Discriminative Universal Adversarial PerturbationChaoning Zhang, Philipp Benz, Tooba Imtiaz, In-So KweonAAAI 2020 · 64 citations
- Video Panoptic SegmentationDahun Kim, Sanghyun Woo, Joon-Young Lee, In So KweonCVPR 2020
- Unsupervised Intra-Domain Adaptation for Semantic Segmentation Through Self-SupervisionFei Pan, Inkyu Shin, François Rameau, Seokju Lee et al.CVPR 2020
- Understanding Adversarial Examples From the Mutual Influence of Images and PerturbationsChaoning Zhang, Philipp Benz, Tooba Imtiaz, In So KweonCVPR 2020
- High-Frequency Component Helps Explain the Generalization of Convolutional Neural NetworksHaohan Wang, Xindi Wu, Zeyi Huang, Eric P. XingCVPR 2020
Related papers
- UDH: Universal Deep Hiding for Steganography, Watermarking, and Light Field MessagingChaoning Zhang, Philipp Benz, Adil Karjauv, Geng Sun et al.NeurIPS 2020 · 198 citations
- Democratic Training Against Universal Adversarial PerturbationsBing Sun, Jun Sun, Wei ZhaoICLR 2025
- Enabling Fast and Universal Audio Adversarial Attack Using Generative ModelYi Xie, Zhuohang Li, Cong Shi, Jian Liu et al.AAAI 2021 · 77 citations
- Leveraging Frequency Analysis for Deep Fake Image RecognitionJoel Frank, Thorsten Eisenhofer, Lea Schönherr, Asja Fischer et al.ICML 2020 · 848 citations
- Learning Universal Adversarial Perturbation by Adversarial ExampleMaosen Li, Yanhua Yang, Kun Wei, Xu Yang et al.AAAI 2022 · 44 citations
