用于鲁棒学习型图像压缩的快速测试时精化
Fast Test-Time Refinement for Robust Learned Image Compression
- University of Macau(澳门大学)
- Nanyang Technological University(南洋理工大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文针对学习型图像压缩的对抗脆弱性问题,揭示其非对称对抗轨迹特性,提出快速测试时精化框架,经多系统多攻击评估验证了该框架的鲁棒性与实用性。
AI中文摘要:
学习型图像压缩(LIC)在良性场景中已展现出卓越的率失真(RD)性能,但深度神经网络(DNN)带来的高表征能力却以对抗脆弱性增加为代价,这阻碍了其作为可信标准编解码器的应用。近期研究将测试时精化(TTR)作为灰盒场景下的防御手段,尽管其初衷是提升良性RD性能。遗憾的是,TTR的大量迭代会产生过高开销,且其鲁棒性机制缺乏理论理解,此外TTR尚未在白盒场景或除ℓ₂有界率与非目标失真目标之外的攻击中得到评估。为填补这些空白,本文开展了系统性研究,揭示了LIC系统中的非对称对抗轨迹(AAT)特性:从对抗区域向良性区域的迁移比反向过程容易得多,对抗样本通常仅需1-2步即可大致恢复。本文提出二维 Tube 模型解释该现象,并基于AAT提出用于实用鲁棒LIC系统的快速测试时精化(FTTR)框架,证实其鲁棒性源于LIC系统的输入即标签属性诱导的对抗区域收缩,而非梯度混淆。通过对多个LIC系统开展多种强自适应攻击的大量评估,证明了所提FTTR框架的有效性,代码可在指定URL获取。
英文摘要:
Learned image compression (LIC) has demonstrated remarkable rate-distortion (RD) performance in benign settings. However, the high representational capacity endowed by deep neural networks (DNNs) comes at the expense of increased adversarial vulnerability. This hinders their adoption as trusted standardized codecs. Recent work has sketched test-time refinement (TTR) as a defense in gray-box scenarios, despite its original purpose of improving benign RD performance. Unfortunately, extensive iterations of TTR incur prohibitive overhead, while the robustness mechanism lacks theoretical understanding. Moreover, TTR has not been evaluated in white-box settings or against attacks beyond $\ell_2$-bounded rate and untargeted distortion objectives. To bridge these gaps, we present a systematic study. Our study reveals an Asymmetric Adversarial Trajectory (AAT) property in LIC systems: transitioning from adversarial to benign regions is significantly easier than the reverse process, where adversarial examples can often be roughly recovered within only 1-2 steps. We provide a two-dimensional Tube Model to explain this phenomenon. Based on AAT, we propose a Fast Test-Time Refinement (FTTR) framework for practical and robust LIC systems. We establish that the robustness arises from the contraction of adversarial regions induced by the Input-as-Label property of LIC systems, rather than from obfuscated gradients. Extensive evaluations with diverse strong adaptive attacks across multiple LIC systems demonstrate the promise of the proposed FTTR framework. The code is available at https://github.com/chinaliangjiaming/FTTR.git.