让数据保护扰动在全频段有效,防过滤攻击。
Full spectrum Unlearnable Examples via Spectral Equalization

- 通过频谱均等化生成跨频段鲁棒的不可学习扰动。
- 在多数据集和模型上,滤波后仍保持90%以上保护效果。
- 适合需对抗频域攻击的数据隐私保护场景。
不可学习样本(UEs)通过注入人眼难以察觉的扰动,使模型无法提取可利用的特征,从而保护训练数据。本文发现,现有UEs在应用低通滤波后会失效,表明其有效扰动主要集中在高频部分。因此,我们主张可靠的UEs应在全频谱范围内保持有效性。为此,提出基于频谱均等化的全频段不可学习样本(FUSE),通过随机移除连续频带的随机频谱掩蔽(RSM)策略,强制模型在各频段维持不可学习性;并引入跨频带引导(CBG),确保高低频成分的一致性,进一步提升低频不可学习性,同时调节高频扰动以保持图像语义保真度。在多个数据集、架构及频谱滤波条件下进行的大量实验表明,FUSE实现了强大的数据保护效果。
原文摘要 · Abstract (English)
Unlearnable examples (UEs) protect training data by injecting imperceptible perturbations so that models fail to extract exploitable representations. In this paper, we reveal that existing UEs exhibit a critical failure once low-pass filtering is applied, indicating that the effective perturbation signals for unlearnability concentrate predominantly in high frequencies. Hence, we argue that reliable UEs should remain effective across the full spectrum. To this end, we propose Full-spectrum Unlearnable examples via Spectral Equalization (FUSE), which aims to generate spectrum-agnostic perturbations by equalizing the contributions from different bands and enforcing cross-band consistency. Specifically, FUSE adopts a Random Spectral Masking (RSM) strategy during generator training, which randomly removes a contiguous frequency band, forcing the remaining bands to maintain unlearnability. In addition, FUSE further integrates Cross-Band Guidance (CBG), which enforces mutual consistency between high- and low-frequency components, thereby further enhancing low-frequency unlearnability and regulating high-frequency perturbations to preserve the semantic fidelity of images. Extensive experiments across multiple datasets, architectures, and spectral filtering demonstrate the strong protection achieved by FUSE.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。