RevINN: An End-to-End Invertible Neural Network for Reversible Adversarial Examples Generation
Jielun Huang, Chi-Man Pun, Guoheng Huang
摘要
Recent studies have shown that Reversible Adversarial Examples (RAE) can mislead unauthorized deep neural networks while remaining usable for authorized users, effectively preventing image data leakage. Existing RAE methods rely on reversibly embedding perturbation information into the original adversarial examples to enable restoration. However, this two-stage process often results in RAEs with inferior attack effectiveness and visual quality compared to the original versions. To solve these challenges, we propose a novel end-to-end Invertible Neural Network for Reversible Adversarial Examples Generation (RevINN), which directly generates RAEs in one stage by scrambling the intrinsic frequency information of images. Specifically, our RevINN consists of the Cross-Frequency Modulation Attack (CFMA) module and the High-Frequency Perturbation Enhancement (HFPE) module. CFMA selectively exchanges discriminative information between low-and highfrequency wavelet components to achieve adversariality. To fully alter high-frequency semantics, HFPE innovatively employs a tri-branch structure for fine-grained modulation among high-frequency subbands, enhancing perturbation strength. Finally, the modified components are recomposed into RAEs via the inverse wavelet transform. Our RevINN is optimized with adversarial, perceptual, and invertible losses, and can restore images based on the reversibility of the wavelet operations and network modules. Extensive experiments demonstrate that our RevINN achieves stateof-the-art RAE generation quality. The code is available at: https://github.com/WongJaylen/RevINN .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec 等NeurIPS 2020 · 被引用 9,171 次
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou 等ICCV 2021 · 被引用 8,921 次
- Barlow Twins: Self-Supervised Learning via Redundancy ReductionJure Zbontar, Li Jing, Ishan Misra, Yann LeCun 等ICML 2021 · 被引用 2,942 次
- HiNet: Deep Image Hiding by Invertible NetworkJunpeng Jing, Xin Deng, Mai Xu, Jianyi Wang 等ICCV 2021 · 被引用 301 次
相关 Paper
- Imperceptible Adversarial Attack via Invertible Neural NetworksZihan Chen, Ziyue Wang, Jun-Jie Huang, Wentao Zhao 等AAAI 2023 · 被引用 34 次
- IRWArt: Levering Watermarking Performance for Protecting High-quality Artwork ImagesYuanjing Luo, Tongqing Zhou, Fang Liu, Zhiping CaiWWW 2023 · 被引用 26 次
- JPEG-RAE: Reversible Adversarial Example for Privacy and Copyright Protection of JPEG ImagesDahao Fu, Jiangqun Ni, Jian ZhangACM MM 2025
- DP-RAE: A Dual-Phase Merging Reversible Adversarial Example for Image Privacy ProtectionJiajie Zhu, Xia Du, Jizhe Zhou, Chi-Man Pun 等ACM MM 2024 · 被引用 6 次
- IWRN: A Robust Blind Watermarking Method for Artwork Image Copyright Protection Against Noise AttackFeifei Kou, Yuhan Yao, Siyuan Yao, Jiahao Wang 等AAAI 2025 · 被引用 5 次
