首次系统评估JPEG AI在对抗攻击下的鲁棒性,揭示其安全短板。
Exploring adversarial robustness of JPEG AI: methodology, comparison and new methods
- 构建新评测方法,量化神经图像压缩的对抗脆弱性
- 首次大规模对比测试,发现JPEG AI易受特定扰动影响
- 开源代码与数据,助力安全研究者复现与改进
神经网络的对抗鲁棒性是当前研究热点,涵盖计算机视觉模型、大语言模型等。随着JPEG AI作为首个端到端神经图像压缩(NIC)国际标准发布,其安全性问题日益突出。该技术已嵌入消费级设备,但现有针对NIC的鲁棒性研究仅限于开源编码器和有限攻击类型。本文提出一种新的衡量NIC对抗鲁棒性的方法,首次开展大规模评估,比较JPEG AI与其他NIC模型的表现。评估结果及代码已公开(链接隐藏以满足盲审要求)。
原文摘要 · Abstract (English)
Adversarial robustness of neural networks is an increasingly important area of research, combining studies on computer vision models, large language models (LLMs), and others. With the release of JPEG AI - the first standard for end-to-end neural image compression (NIC) methods - the question of its robustness has become critically significant. JPEG AI is among the first international, real-world applications of neural-network-based models to be embedded in consumer devices. However, research on NIC robustness has been limited to open-source codecs and a narrow range of attacks. This paper proposes a new methodology for measuring NIC robustness to adversarial attacks. We present the first large-scale evaluation of JPEG AI's robustness, comparing it with other NIC models. Our evaluation results and code are publicly available online (link is hidden for a blind review).
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。