JPEG-RAE: Reversible Adversarial Example for Privacy and Copyright Protection of JPEG Images
Dahao Fu, Jiangqun Ni, Jian Zhang
摘要
Reversible Adversarial Example (RAE) could be used to protect the privacy and copyright of images on social networks (SONs) by exploring the adversarial examples to disrupt the access of malicious AI models while ensuring recoverability with authorized users. Existing RAE methods add adversarial perturbations in spatial images which do not apply to JPEG images, the most widely adopted image format for image storage and transmission. To tackle this issue, we propose the first Reversible Adversarial Example (JPEG-RAE) generation framework for JPEG images, which consists of two primary components, i.e., JPEG-AE and G-RDH. JPEG-AE crafts the adversarial perturbations in the JPEG domain of images by leveraging chain rule of gradient propagation, so that they could effectively mislead the AI models in spatial domain when they are JPEG decompressed. And G-RDH adopts a gradient-directed bi-directional histogram shifting scheme for efficient reversible hiding of adversarial perturbations and location data in JPEG domain, where the histogram shifting is in sync with the sign of back-propagated gradients to further boost the performance of adversarial attacks. Experimental validation demonstrates that, although confined to the JPEG format such as the amount and intensity of alterable DCT coefficients, the proposed JPEG-RAE could still show superior or comparable performance, in terms of attack ability and recover ability, to its counterparts in spatial domain.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- DP-RAE: A Dual-Phase Merging Reversible Adversarial Example for Image Privacy ProtectionJiajie Zhu, Xia Du, Jizhe Zhou, Chi-Man Pun 等ACM MM 2024 · 被引用 6 次
- Stealthy-AE: Generating Stealthy Adversarial Examples through Online Social NetworksZiming Zhao, Zhaoxuan Li, Tingting Li, Fan ZhangACM MM 2025 · 被引用 1 次
- RAEncoder: A Label-Free Reversible Adversarial Examples Encoder for Dataset Intellectual Property ProtectionFan Xing, Zhuo Tian, Xuefeng Fan, Xiaoyi ZhouCVPR 2025
- RevINN: An End-to-End Invertible Neural Network for Reversible Adversarial Examples GenerationJielun Huang, Chi-Man Pun, Guoheng HuangCVPR 2026
- BlurGuard: A Simple Approach for Robustifying Image Protection Against AI-Powered EditingJinsu Kim, Yunhun Nam, Minseon Kim, Sangpil Kim 等NeurIPS 2025 · 被引用 7 次
