Evade Deep Image Retrieval by Stashing Private Images in the Hash Space

Evade Deep Image Retrieval by Stashing Private Images in the Hash Space
复制标题

DOI:
10.1109/cvpr42600.2020.00967
复制
发表时间:
2020-06
期刊:
2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Y. Xiao;Cong Wang;Xing Gao
Y. Xiao;Cong Wang;Xing Gao
中科院分区:
其他
文献类型:
--
作者:
Y. Xiao;Cong Wang;Xing Gao

文献摘要

相似文献

随着视觉内容的快速增长,Hash的深度学习最近在图像检索社区中越来越受欢迎。尽管它极大地促进了搜索效率,但是当网络上的图像大规模检索并被用作丰富的个人信息矿山时,隐私也有风险。对手可以通过查询任何可用模型的目标类别中的相似图像来提取私有图像。基于图像处理的现有方法以感知质量的牺牲将隐私保留。在本文中,我们提出了一种基于对抗性示例的新机制,以“将”私人图像“在深度哈希空间中藏起来”,同时保持感知相似性。我们首先发现,锤击距离最大化的简单方法对蛮力的对手并不强大。然后,我们通过将锤距不仅最大化到原始类别,而且从所有类中的中心最大化,从而开发出新的损失函数,从而将其分配为各种尺寸的群集。广泛的实验表明,拟议的防御能够使攻击者的努力在2-7个数量级上,而没有大幅度增加计算开销和感知降解代码可在以下网址找到:https://github.com/sugarruy/hashstash
With the rapid growth of visual content, deep learning to hash is gaining popularity in the image retrieval community recently. Although it greatly facilitates search efficiency, privacy is also at risks when images on the web are retrieved at a large scale and exploited as a rich mine of personal information. An adversary can extract private images by querying similar images from the targeted category for any usable model. Existing methods based on image processing preserve privacy at a sacrifice of perceptual quality. In this paper, we propose a new mechanism based on adversarial examples to "stash'' private images in the deep hash space while maintaining perceptual similarity. We first find that a simple approach of hamming distance maximization is not robust against brute-force adversaries. Then we develop a new loss function by maximizing the hamming distance to not only the original category, but also the centers from all the classes, partitioned into clusters of various sizes. The extensive experiment shows that the proposed defense can harden the attacker's efforts by 2-7 orders of magnitude, without significant increase of computational overhead and perceptual degradation. We also demonstrate 30-60% transferability in hash space with a black-box setting. The code is available at: https://github.com/sugarruy/hashstash