错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ISWP: Novel high-fidelity adversarial examples generated by incorporating invisible and secure watermark perturbations

  • Jinchao Liang,
  • Yang Liu,
  • Lu Gao,
  • Ze Zhang,
  • Xiaolong Liu

摘要

Invisible watermarking is widely used for tracking and holding accountable unauthorized usage of copyrighted content, but it does not prevent attackers from obtaining illegal access to digital assets. Consequently, user privacy and security are significantly compromised. Recent investigations have revealed that adversarial attacks are capable of misleading state-of-the-art deep learning models by inducing incorrect classifications. The generated adversarial examples can dramatically mitigate malicious access to protected content. To integrate invisible watermarking with adversarial attacks in a unified task, we explore the potential of creating meaningful perturbations in adversarial examples that combine adversarial attacks with secure watermark perturbations. A novel method called ISWP (invisible and secure watermark perturbations) for embedding meaningful perturbations into input images is proposed in this paper to accomplish both adversarial attacks and copyright protection. ISWP employs the discrete wavelet transform (DWT) and basin hopping (BH) in its adversarial attack process, resulting in the creation of imperceptible adversarial watermark perturbations. Furthermore, encryption technologies are incorporated into the adversarial attack process to safeguard against unauthorized malicious access. The experimental results show that the generated adversarial examples exhibit benign visual performance while achieving remarkable attack capacity and robustness on different DNN models, and the embedded watermarks are extracted as powerful tools for copyright certification, which demonstrates their effectiveness as a protection mechanism for private content.