An Explainable Adversarial Attacks on Privacy-Preserving Image Classification

Guoming Chen,Zeduo Yuan,Qiang Chen,Yi Teng,Ruilin Zhang,Jiachen Zhang
DOI: https://doi.org/10.1109/icdh57206.2022.00008
2022-01-01
Abstract:Adversarial attacks inject imperceptible perturbations to images, they have the advantage of defending against other attacks while have the disadvantage of deteriorating the performance of deep classifier. We proposed a Gray and block chaotic scrambling based scheme for image encryption (Gray + Block Chaotic Scrambling, GBCS), and apply it to privacy-preserve robust classification. Security evaluation has been made in terms of image histogram, information entropy, and robustness against various attacks. It is interesting to find that the bit-planes of combined GBCS and Hilbert scrambling give robustness to classifier against the FGSM, CW, JSMA and DEEP FOOL adversarial attacks. We also use Grad-CAM for interpretability analysis.
What problem does this paper attempt to address?