强化深度感知哈希以抵御规避攻击且无需重新训练
Double Down on Defense: Strengthening Deep Perceptual Hashes against Evasion Attacks without Retraining
浏览论文内容
中文总结 AI 辅助
针对深度感知哈希易受规避攻击的问题,提出无需重新训练的插件式防御机制DualShield,结合匹配时随机平滑与发布时加固,可大幅降低攻击成功率且保持低碰撞率。
中文摘要 AI 辅助
近重复图像匹配对于信任与安全、来源验证、版权执行及大规模视觉搜索至关重要,现代平台愈发依赖深度感知哈希,该技术能在常见图像变换下将视觉相似图像映射为邻近表示。然而,对抗性扰动可导致近重复图像规避匹配。本文提出DualShield,这是一种插件式防御机制,无需重新训练或修改底层模型即可提升现有深度感知哈希的鲁棒性。DualShield结合了匹配时的随机平滑与发布时的加固:匹配时的随机平滑通过聚合受扰动参考-查询对的决策来实现,发布时的加固则在每个参考图像发布前添加优化后的不可感知扰动。这些机制共同提供了可验证的鲁棒性与经验鲁棒性,DualShield实现了约0.3的可验证ℓ₂半径,保证查询扰动在该半径内无法规避匹配。我们进一步针对自适应白盒、黑盒及图像变换攻击对其进行评估,在8种深度感知哈希和3个数据集上,DualShield大幅降低了攻击成功率,同时保持了低碰撞率。这些结果表明,通过优化匹配流程并在发布前加固参考图像,无需昂贵的重新训练即可强化深度感知哈希。
英文摘要
Near-duplicate image matching is crucial for trust and safety, provenance verification, copyright enforcement, and large-scale visual search. Modern platforms increasingly rely on deep perceptual hashes, which map visually similar images to nearby representations despite common image transformations. However, adversarial perturbations can cause near-duplicates to evade matching. We present DualShield, a plug-in defense that improves the robustness of existing deep perceptual hashes without retraining or modifying their underlying models. DualShield combines matching-time randomized smoothing, which aggregates decisions over perturbed reference-query pairs, with publication-time hardening, which adds an optimized imperceptible perturbation to each reference image before publication. Together, these mechanisms provide certified and empirical robustness. DualShield achieves a certified $\ell_2$ radius of approximately 0.3, guaranteeing that query perturbations within this radius cannot evade matching. We further evaluate it against adaptive white-box, black-box, and image-transformation attacks. Across eight deep perceptual hashes and three datasets, DualShield substantially reduces attack success rates while preserving low collision rates. These results show that deep perceptual hashes can be strengthened without costly retraining by improving the matching procedure and hardening reference images before publication.