Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online Promotion

Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online Promotion
复制标题

DOI:
10.1109/sp.2019.00032
复制
发表时间:
2019-05
期刊:
2019 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Kan Yuan;Di Tang;Xiaojing Liao;Xiaofeng Wang;Xuan Feng;Yi Chen;Menghan Sun;Haoran Lu;Kehuan Zhang
Kan Yuan;Di Tang;Xiaojing Liao;Xiaofeng Wang;Xuan Feng;Yi Chen;Menghan Sun;Haoran Lu;Kehuan Zhang
中科院分区:
其他
文献类型:
--
作者:
Kan Yuan;Di Tang;Xiaojing Liao;Xiaofeng Wang;Xuan Feng;Yi Chen;Menghan Sun;Haoran Lu;Kehuan Zhang

文献摘要

被引文献

相似文献

近年来,深度学习(DP)取得了迅速的进展,这也使其潜在的弱点成为安全和机器学习研究的焦点。然而,随着对抗性学习研究的重要发现,令人惊讶的是,人们很少关注网络犯罪分子为逃避基于图像的检测而部署的真实世界对抗性技术。与使用几乎不可感知的扰动引起错误分类的对抗性示例不同,真实世界的对抗性图像往往不太理想,但同样有效。作为了解这种威胁的第一步,我们在论文中报告了一项关于在地下广告中广泛使用的对抗性促销色情图像(APPI)的研究。我们表明,对手今天的战略构建的APPI,以逃避明确的内容检测,同时仍然保留其性吸引力,即使引入的失真和噪音是明显可见的人类。为了理解这种真实世界的对抗性图像及其背后的地下业务,我们开发了一种新的基于DP的方法,称为Male`na,它专注于图像的区域,其中性内容最不模糊,因此对促销的目标受众可见。使用这种技术,我们已经从流行的社交媒体上抓取的4,042,690张图像中发现了4,000多个APP,并进一步揭示了它们用于逃避流行的明确内容检测器的独特技术(例如,Google Cloud Vision API,Yahoo Open NSFW模型),以及这些技术工作的原因。还研究了这种非法促销的生态系统,包括通过这些图像广告的混淆联系人,用于传播它们的受损帐户,以及涉及数千张图像的大型APPI活动。另一个有趣的发现是,网络犯罪分子显然试图窃取他人的图像用于广告。该研究强调了现实世界对抗性学习研究的重要性,并为减轻其构成的威胁迈出了第一步。
Recent years have witnessed the rapid progress in deep learning (DP), which also brings their potential weaknesses to the spotlights of security and machine learning studies. With important discoveries made by adversarial learning research, surprisingly little attention, however, has been paid to the real-world adversarial techniques deployed by the cybercriminal to evade image-based detection. Unlike the adversarial examples that induce misclassification using nearly imperceivable perturbation, real-world adversarial images tend to be less optimal yet equally effective. As a first step to understand the threat, we report in the paper a study on adversarial promotional porn images (APPIs) that are extensively used in underground advertising. We show that the adversary today’s strategically constructs the APPIs to evade explicit content detection while still preserving their sexual appeal, even though the distortions and noise introduced are clearly observable to humans. To understand such real-world adversarial images and the underground business behind them, we develop a novel DP-based methodology called Male`na, which focuses on the regions of an image where sexual content is least obfuscated and therefore visible to the target audience of a promotion. Using this technique, we have discovered over 4,000 APPIs from 4,042,690 images crawled from popular social media, and further brought to light the unique techniques they use to evade popular explicit content detectors (e.g., Google Cloud Vision API, Yahoo Open NSFW model), and the reason that these techniques work. Also studied are the ecosystem of such illicit promotions, including the obfuscated contacts advertised through those images, compromised accounts used to disseminate them, and large APPI campaigns involving thousands of images. Another interesting finding is the apparent attempt made by cybercriminals to steal others’ images for their advertising. The study highlights the importance of the research on real-world adversarial learning and makes the first step towards mitigating the threats it poses.