针对神经图像压缩的新型隐蔽攻击框架,提升攻击隐匿性。
T-MLA: A targeted multiscale log-exponential attack framework for neural image compression
- 在小波域聚焦不显著系数添加扰动,增强隐蔽性。
- 多尺度对数指数攻击使重建质量大幅下降,但视觉不可察觉。
- 适用于评估生成式内容传输系统的安全缺陷。
神经图像压缩(NIC)已成为率失真性能的前沿技术,但其安全漏洞远未被充分理解。现有对抗攻击多为像素空间方法的简单移植,忽略了压缩流水线特有的结构特性。本文提出首个面向目标的多尺度对数指数攻击框架T-MLA,通过在小波域引入扰动,集中于感知上不显著的系数,从而提升攻击隐蔽性。在多个主流NIC架构及标准图像压缩基准上的广泛评估表明,该方法在保持扰动视觉不可察觉的同时,显著降低重建质量。与基于PGD的基线相比,T-MLA在相近攻击成功率下实现了更高的扰动输入PSNR/VIF值,验证了其优越的隐匿性。研究揭示了生成式内容传输系统中的关键安全缺陷。
原文摘要 · Abstract (English)
Neural image compression (NIC) has become the state-of-the-art for rate-distortion performance, yet its security vulnerabilities remain significantly less understood than those of classifiers. Existing adversarial attacks on NICs are often naive adaptations of pixel-space methods, overlooking the unique, structured nature of the compression pipeline. In this work, we propose a more advanced class of vulnerabilities by introducing T-MLA, the first targeted multiscale log-exponential attack framework. We introduce adversarial perturbations in the wavelet domain that concentrate on less perceptually salient coefficients, improving the stealth of the attack. Extensive evaluation across multiple state-of-the-art NIC architectures on standard image compression benchmarks reveals a large drop in reconstruction quality while the perturbations remain visually imperceptible. On standard NIC benchmarks, T-MLA achieves targeted degradation of reconstruction quality while improving perturbation imperceptibility (higher PSNR/VIF of the perturbed inputs) compared to PGD-style baselines at comparable attack success, as summarized in our main results. Our findings reveal a critical security flaw at the core of generative and content delivery pipelines.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。