对抗制
灰度
计算机科学
图像(数学)
人工智能
光学(聚焦)
计算机视觉
算法
理论计算机科学
物理
光学
作者
Haodong Zhang,Chi‐Man Pun,Xia Du
摘要
Reversible adversarial examples (RAE) combine adversarial attacks and reversible data hiding technology on a single image to prevent illegal access. Most RAE studies focus on achieving white-box attacks. In this paper, we propose a novel framework to generate reversible adversarial examples, which combines a novel beam search based black-box attack and reversible data hiding with grayscale invariance (RDH-GI). This RAE uses beam search to evaluate the adversarial gain of historical perturbations and guide adversarial perturbations. After the adversarial examples are generated, the framework RDH-GI embeds the secret data that can be recovered losslessly. Experimental results show that our method can achieve an average peak signal-to-noise ratio (PSNR) of at least 40dB compared to source images with limited query budgets. Our method can also achieve a targeted black-box reversible adversarial attack for the first time.
科研通智能强力驱动
Strongly Powered by AbleSci AI