通过修改图像频域系数,实现隐蔽且抗净化的图像防御
DCT-Shield: A Robust Frequency Domain Defense against Malicious Image Editing
- 在频域直接扰动DCT系数,干扰扩散模型编辑
- 视觉失真更小,对JPEG压缩等净化手段保持鲁棒
- 适合需保护图像安全又不破坏观感的应用场景
扩散模型的发展使得用户可通过文本提示轻松编辑图像,引发图像安全担忧。攻击者可利用这些工具对用户图像进行恶意修改。现有防御方法通过在像素空间添加有限噪声来干扰扩散编辑模型,但其生成的对抗噪声易被肉眼察觉,且在合理像素预算下对JPEG压缩等净化技术缺乏鲁棒性。本文提出一种新型优化方法,通过修改输入图像的离散余弦变换(DCT)系数,在频域直接引入对抗扰动。该方法借助JPEG编码流程,生成能有效阻止恶意编辑的对抗图像。大量实验表明,本方法在保持与现有方法相当的编辑防护能力的同时,显著减少视觉伪影,并对噪声净化技术具有更强的鲁棒性。
原文摘要 · Abstract (English)
Advancements in diffusion models have enabled effortless image editing via text prompts, raising concerns about image security. Attackers with access to user images can exploit these tools for malicious edits. Recent defenses attempt to protect images by adding a limited noise in the pixel space to disrupt the functioning of diffusion-based editing models. However, the adversarial noise added by previous methods is easily noticeable to the human eye. Moreover, most of these methods are not robust to purification techniques like JPEG compression under a feasible pixel budget. We propose a novel optimization approach that introduces adversarial perturbations directly in the frequency domain by modifying the Discrete Cosine Transform (DCT) coefficients of the input image. By leveraging the JPEG pipeline, our method generates adversarial images that effectively prevent malicious image editing. Extensive experiments across a variety of tasks and datasets demonstrate that our approach introduces fewer visual artifacts while maintaining similar levels of edit protection and robustness to noise purification techniques.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。