用自适应扰动保护图像,防篡改且难被逆向破解。
Perturb, Attend, Detect and Localize (PADL): Robust Proactive Image Defense
- 基于交叉注意力生成图像专属扰动,避免固定模式漏洞
- 在未见生成模型上仍保持高检测准确率,泛化性强
- 可精确定位篡改区域,适合真实场景安全防御
图像篡改检测与定位因生成模型的兴起受到广泛关注。传统被动检测方法易过拟合特定生成模型,限制实际应用。近期主动防御框架虽有进展,但仍存在两大缺陷:一是对噪声不鲁棒,易被欺骗;二是依赖固定扰动,易被攻击者逆向工程并规避检测。为此,我们提出PADL,一种基于交叉注意力编码解码机制的对称扰动生成方案,显著降低逆向风险,即使面对自适应攻击[31]也有效。此外,PADL能精准定位篡改区域,并在未见生成模型(如StarGANv2、BlendGAN、DiffAE、StableDiffusion和StableDiffusionXL)上展现更强泛化能力。实验表明,仅在属性操纵GAN模型[15]上训练,仍可覆盖多种架构设计的生成模型。我们还提出新评估协议,更公平衡量定位性能,更好反映真实场景。
原文摘要 · Abstract (English)
Image manipulation detection and localization have received considerable attention from the research community given the blooming of Generative Models (GMs). Detection methods that follow a passive approach may overfit to specific GMs, limiting their application in real-world scenarios, due to the growing diversity of generative models. Recently, approaches based on a proactive framework have shown the possibility of dealing with this limitation. However, these methods suffer from two main limitations, which raises concerns about potential vulnerabilities: i) the manipulation detector is not robust to noise and hence can be easily fooled; ii) the fact that they rely on fixed perturbations for image protection offers a predictable exploit for malicious attackers, enabling them to reverse-engineer and evade detection. To overcome this issue we propose PADL, a new solution able to generate image-specific perturbations using a symmetric scheme of encoding and decoding based on cross-attention, which drastically reduces the possibility of reverse engineering, even when evaluated with adaptive attack [31]. Additionally, PADL is able to pinpoint manipulated areas, facilitating the identification of specific regions that have undergone alterations, and has more generalization power than prior art on held-out generative models. Indeed, although being trained only on an attribute manipulation GAN model [15], our method generalizes to a range of unseen models with diverse architectural designs, such as StarGANv2, BlendGAN, DiffAE, StableDiffusion and StableDiffusionXL. Additionally, we introduce a novel evaluation protocol, which offers a fair evaluation of localisation performance in function of detection accuracy and better captures real-world scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。