Evade Deep Image Retrieval by Stashing Private Images in the Hash Space
Yanru Xiao, Cong Wang, Xing Gao
摘要
With the rapid growth of visual content, deep learning to hash is gaining popularity in the image retrieval community recently. Although it greatly facilitates search efficiency, privacy is also at risks when images on the web are retrieved at a large scale and exploited as a rich mine of personal information. An adversary can extract private images by querying similar images from the targeted category for any usable model. Existing methods based on image processing preserve privacy at a sacrifice of perceptual quality. In this paper, we propose a new mechanism based on adversarial examples to "stash" private images in the deep hash space while maintaining perceptual similarity. We first find that a simple approach of hamming distance maximization is not robust against brute-force adversaries. Then we develop a new loss function by maximizing the hamming distance to not only the original category, but also the centers from all the classes, partitioned into clusters of various sizes. The extensive experiment shows that the proposed defense can harden the attacker's efforts by 2-7 orders of magnitude, without significant increase of computational overhead and perceptual degradation. We also demonstrate 30-60% transferability in hash space with a black-box setting.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- A Study of Face Obfuscation in ImageNetKaiyu Yang, Jacqueline H. Yau, Li Fei-Fei, Jia Deng 等ICML 2022 · 被引用 163 次
- Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalLong Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen 等AAAI 2024 · 被引用 13 次
- You See What I Want You To See: Exploring Targeted Black-Box Transferability Attack for Hash-Based Image Retrieval SystemsYanru Xiao, Cong WangCVPR 2021
它引用的顶会 Paper1
相关 Paper
- Precise Target-Oriented Attack against Deep Hashing-based RetrievalWenshuo Zhao, Jingkuan Song, Shengming Yuan, Lianli Gao 等ACM MM 2023 · 被引用 8 次
- HUANG: A Robust Diffusion Model-based Targeted Adversarial Attack Against Deep Hashing RetrievalChihan Huang, Xiaobo ShenAAAI 2025 · 被引用 5 次
- CgAT: Center-Guided Adversarial Training for Deep Hashing-Based RetrievalXunguang Wang, Yiqun Lin, Xiaomeng LiWWW 2023 · 被引用 10 次
- Prototype-Supervised Adversarial Network for Targeted Attack of Deep HashingXunguang Wang, Zheng Zhang, Baoyuan Wu, Fumin Shen 等CVPR 2021
- AdvHash: Set-to-set Targeted Attack on Deep Hashing with One Single Adversarial PatchShengshan Hu, Yechao Zhang, Xiaogeng Liu, Leo Yu Zhang 等ACM MM 2021 · 被引用 34 次
