Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image Retrieval
Long Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen, Yunming Zhang
摘要
Deep Hashing (DH)-based image retrieval has been widely applied to face-matching systems due to its accuracy and efficiency. However, this convenience comes with an increased risk of privacy leakage. DH models inherit the vulnerability to adversarial attacks, which can be used to prevent the retrieval of private images. Existing adversarial attacks against DH typically target a single image or a specific class of images, lacking universal adversarial perturbation for the entire hash dataset. In this paper, we propose the first universal transferable adversarial perturbation against DH-based facial image retrieval, a single perturbation can protect all images. Specifically, we explore the relationship between clusters learned by different DH models and define the optimization objective of universal perturbation as leaving from the overall hash center. To mitigate the challenge of single-objective optimization, we randomly obtain sub-cluster centers and further propose sub-task-based meta-learning to aid in overall optimization. We test our method with popular facial datasets and DH models, indicating impressive cross-image, -identity, -model, and -scheme universal anti-retrieval performance. Compared to state-of-the-art methods, our performance is competitive in white-box settings and exhibits significant improvements of 10% -70% in transferability in all black-box settings.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Generalized Debiased Semi-Supervised Hashing for Large-Scale Image RetrievalXingbo Liu, Xuening Zhang, Xiushan Nie, Yang Shi 等AAAI 2025 · 被引用 4 次
- RFNNS: Robust Fixed Neural Network Steganography with Universal Text-to-Image ModelsYu Cheng, Jiuan Zhou, Jiawei Chen, Zhaoxia Yin 等AAAI 2026
它引用的顶会 Paper10
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang 等ICLR 2020 · 被引用 765 次
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong 等ICCV 2019 · 被引用 115 次
- Targeted Mismatch Adversarial Attack: Query With a Flower to Retrieve the TowerGiorgos Tolias, Filip Radenovic, Ondrej ChumICCV 2019 · 被引用 76 次
- AdvHash: Set-to-set Targeted Attack on Deep Hashing with One Single Adversarial PatchShengshan Hu, Yechao Zhang, Xiaogeng Liu, Leo Yu Zhang 等ACM MM 2021 · 被引用 34 次
- Adversarial Attack on Deep Cross-Modal Hamming RetrievalChao Li, Shangqian Gao, Cheng Deng, Wei Liu 等ICCV 2021 · 被引用 29 次
相关 Paper
- Precise Target-Oriented Attack against Deep Hashing-based RetrievalWenshuo Zhao, Jingkuan Song, Shengming Yuan, Lianli Gao 等ACM MM 2023 · 被引用 8 次
- You See What I Want You To See: Exploring Targeted Black-Box Transferability Attack for Hash-Based Image Retrieval SystemsYanru Xiao, Cong WangCVPR 2021
- Evade Deep Image Retrieval by Stashing Private Images in the Hash SpaceYanru Xiao, Cong Wang, Xing GaoCVPR 2020
- HUANG: A Robust Diffusion Model-based Targeted Adversarial Attack Against Deep Hashing RetrievalChihan Huang, Xiaobo ShenAAAI 2025 · 被引用 5 次
- Spectral-Adaptive Adversarial Hashing for Robust Image RetrievalGang Zhou, Shibiao Xu, Xiaolong Zheng, Daniel Dajun ZengSIGIR 2026
