Effectiveness of random deep feature selection for securing image manipulation detectors against adversarial examples

10/25/2019
by   M. Barni, et al.
0

We investigate if the random feature selection approach proposed in [1] to improve the robustness of forensic detectors to targeted attacks, can be extended to detectors based on deep learning features. In particular, we study the transferability of adversarial examples targeting an original CNN image manipulation detector to other detectors (a fully connected neural network and a linear SVM) that rely on a random subset of the features extracted from the flatten layer of the original network. The results we got by considering three image manipulation detection tasks (resizing, median filtering and adaptive histogram equalization), two original network architectures and three classes of attacks, show that feature randomization helps to hinder attack transferability, even if, in some cases, simply changing the architecture of the detector, or even retraining the detector is enough to prevent the transferability of the attacks.

READ FULL TEXT
research
11/05/2018

On the Transferability of Adversarial Examples Against CNN-Based Image Forensics

Recent studies have shown that Convolutional Neural Networks (CNN) are r...
research
02/02/2018

Secure Detection of Image Manipulation by means of Random Feature Selection

We address the problem of data-driven image manipulation detection in th...
research
05/12/2020

Increased-confidence adversarial examples for improved transferability of Counter-Forensic attacks

Transferability of adversarial examples is a key issue to study the secu...
research
02/22/2019

Improving the Security of Image Manipulation Detection through One-and-a-half-class Multiple Classification

Protecting image manipulation detectors against perfect knowledge attack...
research
01/16/2017

Vulnerability of Deep Reinforcement Learning to Policy Induction Attacks

Deep learning classifiers are known to be inherently vulnerable to manip...
research
07/29/2021

Feature Importance-aware Transferable Adversarial Attacks

Transferability of adversarial examples is of central importance for att...
research
12/06/2018

ForensicTransfer: Weakly-supervised Domain Adaptation for Forgery Detection

Distinguishing fakes from real images is becoming increasingly difficult...

Please sign up or login with your details

Forgot password? Click here to reset