arXiv:2503.21236cs.CVcs.MM2025-03中稿 · TMM被引 2

干净图片也能被恶意利用,诱导检索出非法内容。

Clean Image May be Dangerous: Data Poisoning Attacks Against Deep Hashing

  • 通过构建代理模型模拟目标哈希模型行为
  • 设计梯度匹配策略生成可触发攻击的污染图像
  • 在多个模型和数据集上验证攻击有效性

大规模图像检索中,深度哈希因图像数据激增和深度神经网络强大的特征提取能力而日益流行。然而,深度哈希方法易受恶意攻击,如对抗攻击和后门攻击。值得注意的是,这些攻击通常需篡改查询图像,在真实场景中并不常见。本文首次提出针对深度哈希的**数据污染攻击**(PADHASH),指出即使使用干净查询图像,也可能诱导出恶意目标检索结果,如不希望或非法图像。我们首先训练一个代理模型以模拟目标深度哈希模型的行为,随后提出一种严格的梯度匹配策略生成污染图像。在不同模型、数据集、哈希方法及哈希码长度下的大量实验表明,该攻击方法具有高度有效性和通用性。

原文摘要 · Abstract (English)

Large-scale image retrieval using deep hashing has become increasingly popular due to the exponential growth of image data and the remarkable feature extraction capabilities of deep neural networks (DNNs). However, deep hashing methods are vulnerable to malicious attacks, including adversarial and backdoor attacks. It is worth noting that these attacks typically involve altering the query images, which is not a practical concern in real-world scenarios. In this paper, we point out that even clean query images can be dangerous, inducing malicious target retrieval results, like undesired or illegal images. To the best of our knowledge, we are the first to study data \textbf{p}oisoning \textbf{a}ttacks against \textbf{d}eep \textbf{hash}ing \textbf{(\textit{PADHASH})}. Specifically, we first train a surrogate model to simulate the behavior of the target deep hashing model. Then, a strict gradient matching strategy is proposed to generate the poisoned images. Extensive experiments on different models, datasets, hash methods, and hash code lengths demonstrate the effectiveness and generality of our attack method.

深度哈希数据污染安全攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。