arXiv:2503.19817cs.CRcs.AI2025-03被引 3

神经图像压缩存在比特流碰撞漏洞,不同图像可生成完全相同的压缩数据。

Bitstream Collisions in Neural Image Compression via Adversarial Perturbations

  • 设计白盒对抗攻击,让语义不同的图像生成相同比特流。
  • 实验验证多种图像在扰动下确实产生完全一致的压缩结果。
  • 提出简单有效缓解方案,适合安全敏感场景使用。

神经图像压缩(NIC)作为经典压缩技术的有前景替代方案,提供了更优的压缩比。尽管其正迈向标准化与实际部署,但对其鲁棒性与安全性却极少研究。本研究揭示了NIC中一种意外的脆弱性——比特流碰撞:语义不同的图像可产生完全相同的压缩比特流。通过一种新颖的白盒对抗攻击算法,本文证明对语义不同的图像施加精心设计的扰动,可使其压缩后的比特流完全一致。该碰撞漏洞对NIC在安全关键应用中的实用性构成威胁。论文分析了碰撞成因,并提出一种简单而有效的缓解方法。

原文摘要 · Abstract (English)

Neural image compression (NIC) has emerged as a promising alternative to classical compression techniques, offering improved compression ratios. Despite its progress towards standardization and practical deployment, there has been minimal exploration into it's robustness and security. This study reveals an unexpected vulnerability in NIC - bitstream collisions - where semantically different images produce identical compressed bitstreams. Utilizing a novel whitebox adversarial attack algorithm, this paper demonstrates that adding carefully crafted perturbations to semantically different images can cause their compressed bitstreams to collide exactly. The collision vulnerability poses a threat to the practical usability of NIC, particularly in security-critical applications. The cause of the collision is analyzed, and a simple yet effective mitigation method is presented.

图像压缩对抗攻击安全漏洞

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。