高保真压缩重建图像能显著增强对抗防御,提升攻击难度。
Keep It Real: Challenges in Attacking Compression-Based Adversarial Purification
- 用强白盒攻击测试多种压缩模型的防御能力。
- 高现实感重建图像使攻击成功率下降超过60%。
- 适合关注图像压缩安全与对抗鲁棒性的研究者。
先前研究表明,通过有损压缩预处理图像可防御对抗扰动,但缺乏全面的攻击评估。本文构建了针对多种压缩模型的强白盒与自适应攻击,发现重构图像的高真实感显著增加攻击难度。在多场景严格评估中,能生成高保真、逼真重构的压缩模型对攻击表现出显著更强的鲁棒性;而低真实感压缩模型则易被攻破。分析表明,这种现象并非梯度掩蔽所致,而是由于真实重构保持了与自然图像的分布一致性,提供了内在鲁棒性。该工作揭示了未来对抗攻击面临的重要障碍,并指出提升真实感以突破防御是安全评估的关键挑战。
原文摘要 · Abstract (English)
Previous work has suggested that preprocessing images through lossy compression can defend against adversarial perturbations, but comprehensive attack evaluations have been lacking. In this paper, we construct strong white-box and adaptive attacks against various compression models and identify a critical challenge for attackers: high realism in reconstructed images significantly increases attack difficulty. Through rigorous evaluation across multiple attack scenarios, we demonstrate that compression models capable of producing realistic, high-fidelity reconstructions are substantially more resistant to our attacks. In contrast, low-realism compression models can be broken. Our analysis reveals that this is not due to gradient masking. Rather, realistic reconstructions maintaining distributional alignment with natural images seem to offer inherent robustness. This work highlights a significant obstacle for future adversarial attacks and suggests that developing more effective techniques to overcome realism represents an essential challenge for comprehensive security evaluation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。