Reversible Attack Based on Adversarial Perturbation and Reversible Data Hiding in YUV Colorspace

Zhaoxia Yin,Li Chen,Wanli Lyu,Bin Luo
DOI: https://doi.org/10.1016/j.patrec.2022.12.018
IF: 4.757
2023-01-01
Pattern Recognition Letters
Abstract:Recent research on using adversarial perturbation to prevent malicious models from accessing image data has led to the corruption of image data, making images useless in other fields, especially in digital foren-sics. To prevent malicious models from retrieving images and ensure that authorized models can recover original image data without distortion, the reversible attack technique is rising. However, attack ability, reversibility, and image visual quality are three major challenges for existing reversible attack techniques. In this paper, a novel reversible attack method based on adversarial perturbation and reversible data hiding in YUV colorspace is proposed. We first add adversarial perturbation into the luminance channel. Then, the luminance channel distortion caused by adversarial perturbation is embedded into chrominance channels by reversible data hiding to achieve the reversible attack. In particular, the class activation map-ping module is introduced to narrow the perturbation region to reduce the amount of embedded data. Experimental results on the ImageNet dataset demonstrated that the proposed method achieves better at-tack ability and image visual quality and ensures that original images can be recovered without distortion.(c) 2023 Elsevier B.V. All rights reserved.
What problem does this paper attempt to address?