← 返回论文检索
ACM Multimedia 2025Experience: Multimedia Applications

JPEG-RAE: Reversible Adversarial Example for Privacy and Copyright Protection of JPEG Images

Dahao Fu, Jiangqun Ni, Jian Zhang 0086

PDF 由论文原始站点提供,PaperCompass 不保存论文文件。DOI 10.1145/3746027.3754830 ↗

摘要

Reversible Adversarial Example (RAE) could be used to protect the privacy and copyright of images on social networks (SONs) by exploring the adversarial examples to disrupt the access of malicious AI models while ensuring recoverability with authorized users. Existing RAE methods add adversarial perturbations in spatial images which do not apply to JPEG images, the most widely adopted image format for image storage and transmission. To tackle this issue, we propose the first Reversible Adversarial Example (JPEG-RAE) generation framework for JPEG images, which consists of two primary components, i.e., JPEG-AE and G-RDH. JPEG-AE crafts the adversarial perturbations in the JPEG domain of images by leveraging chain rule of gradient propagation, so that they could effectively mislead the AI models in spatial domain when they are JPEG decompressed. And G-RDH adopts a gradient-directed bi-directional histogram shifting scheme for efficient reversible hiding of adversarial perturbations and location data in JPEG domain, where the histogram shifting is in sync with the sign of back-propagated gradients to further boost the performance of adversarial attacks. Experimental validation demonstrates that, although confined to the JPEG format such as the amount and intensity of alterable DCT coefficients, the proposed JPEG-RAE could still show superior or comparable performance, in terms of attack ability and recover ability, to its counterparts in spatial domain.