On the Security of the One-and-a-Half-Class Classifier for SPAM Feature-Based Image Forensics

被引:2
|
作者
Lorch, Benedikt [1 ]
Schirrmacher, Franziska [1 ]
Maier, Anatol [1 ]
Riess, Christian [1 ]
机构
[1] Friedrich Alexander Univ Erlangen Nurnberg, IT Secur Infrastruct Lab, D-91058 Erlangen, Germany
关键词
Detectors; Feature extraction; Robustness; Glass box; Security; Distortion; Quantization (signal); Image forensics; counter-forensics; adversarial examples; one-and-a-half-class classifier; MANIPULATION; TRACES;
D O I
10.1109/TIFS.2023.3266168
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Combining multiple classifiers is a promising approach to hardening forensic detectors against adversarial evasion attacks. The key idea is that an attacker must fool all individual classifiers to evade detection. The 1.5C classifier is one of these multiple-classifier detectors that is attack-agnostic, and thus even increases the difficulty for an omniscient attacker. Recent work evaluated the 1.5C classifier with SPAM features for image manipulation detection. Despite showing promising results, their security analysis leaves several aspects unresolved. Surprisingly, the results reveal that fooling only one component is often sufficient to evade detection. Additionally, the authors evaluate classifier robustness with only a black-box attack because, currently, there is no white-box attack against SPAM feature-based classifiers. This paper addresses these shortcomings and complements the previous security analysis. First, we develop a novel white-box attack against SPAM feature-based detectors. The proposed attack produces adversarial images with lower distortion than the previous attack. Second, by analyzing the 1.5C classifier's acceptance region, we identify three pitfalls that explain why the current 1.5C classifier is less robust than a binary classifier in some settings. Third, we illustrate how to mitigate these pitfalls with a simple axis-aligned split classifier. Our experimental evaluation demonstrates the increased robustness of the proposed detector for SPAM feature-based image manipulation detection.
引用
收藏
页码:2466 / 2479
页数:14
相关论文
共 50 条
  • [21] Multiresolution feature-based image registration
    Hsu, CT
    Beuker, RA
    VISUAL COMMUNICATIONS AND IMAGE PROCESSING 2000, PTS 1-3, 2000, 4067 : 1490 - 1498
  • [22] Feature-Based Image Stitching Algorithms
    Bonny, Moushumi Zaman
    Uddin, Mohammad Shorif
    2016 INTERNATIONAL WORKSHOP ON COMPUTATIONAL INTELLIGENCE (IWCI), 2016, : 198 - 203
  • [23] Feature-Based Transfer Learning for Network Security
    Zhao, Juan
    Shetty, Sachin
    Pan, Jan Wei
    MILCOM 2017 - 2017 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2017, : 17 - 22
  • [24] Feature-based recommendations for one-to-one marketing
    Weng, SS
    Liu, MJ
    EXPERT SYSTEMS WITH APPLICATIONS, 2004, 26 (04) : 493 - 508
  • [25] Recaptured Image Forensics Algorithm Based on Image Texture Feature
    Sun, Yanjun
    Shen, Xuanjing
    Liu, Changming
    Zhao, Yongzhe
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2020, 34 (03)
  • [26] Vehicle Detection and Counting using Haar Feature-Based Classifier
    Choudhury, Shaif
    Chattopadhyay, Soummyo Priyo
    Hazra, Tapan Kumar
    2017 8TH ANNUAL INDUSTRIAL AUTOMATION AND ELECTROMECHANICAL ENGINEERING CONFERENCE (IEMECON), 2017, : 106 - 109
  • [27] Semantic feature-based Korean classifier module for MT systems
    Hwang, Soonhee
    Yoon, Aesun
    Kwon, Hyuk-Chul
    ALPIT 2007: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON ADVANCED LANGUAGE PROCESSING AND WEB INFORMATION TECHNOLOGY, 2007, : 146 - +
  • [28] Feature-based nonrigid image registration using multi-class Hausdorff fractions
    Peng, Xiaoming
    Chen, Wufan
    Ma, Qian
    MIPPR 2007: AUTOMATIC TARGET RECOGNITION AND IMAGE ANALYSIS; AND MULTISPECTRAL IMAGE ACQUISITION, PTS 1 AND 2, 2007, 6786
  • [29] Feature-Based Multi-Object Tracking With Maximally One Object per Class
    Krejci, Jan
    Straka, Ondrej
    Vyskocil, Jiri
    Jirik, Miroslav
    Dahmen, Uta
    2022 25TH INTERNATIONAL CONFERENCE ON INFORMATION FUSION (FUSION 2022), 2022,
  • [30] A heterogeneous feature-based image alignment method
    Rao, Cen
    Guo, Yanlin
    Sawhney, Harpreet
    Kumar, Rakesh
    18TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION, VOL 2, PROCEEDINGS, 2006, : 345 - +