paper-with-me

홈 › Papers

The Good, the Bad and the Ugly: Watermarks, Transferable Attacks and Adversarial Defenses

2024-10-11 · Grzegorz Głuch, Berkant Turan, Sai Ganesh Nagarajan, Sebastian Pokutta

We formalize and extend existing definitions of backdoor-based watermarks and adversarial defenses as interactive protocols between two players. The existence of these schemes is inherently tied to the learning tasks for which they are designed. Our main result shows that for almost every discriminative learning task, at least one of the two -- a watermark or an adversarial defense -- exists. The term "almost every" indicates that we also identify a third, counterintuitive but necessary option, i.e., a scheme we call a transferable attack. By transferable attack, we refer to an efficient algorithm computing queries that look indistinguishable from the data distribution and fool all efficient defenders. To this end, we prove the necessity of a transferable attack via a construction that uses a cryptographic tool called homomorphic encryption. Furthermore, we show that any task that satisfies our notion of a transferable attack implies a cryptographic primitive, thus requiring the underlying task to be computationally complex. These two facts imply an "equivalence" between the existence of transferable attacks and cryptography. Finally, we show that the class of tasks of bounded VC-dimension has an adversarial defense, and a subclass of them has a watermark.

📄 PDF Abstract BibTeX arXiv:2410.08864

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial Defense

Similar Papers 제목 키워드 기반

AugLy: Data Augmentations for Robustness

2022-01-17 · Zoe Papakipos, Joanna Bitton

We introduce AugLy, a data augmentation library with a focus on adversarial robustness. AugLy provides a wide array of augmentations for multiple modalities (audio, image, text, & video). These augmentations were inspire…

Adversarial RobustnessData Augmentation

Box-Free Model Watermarks Are Prone to Black-Box Removal Attacks

2024-05-16 · Haonan An, Guang Hua, Zhiping Lin, Yuguang Fang

Box-free model watermarking is an emerging technique to safeguard the intellectual property of deep learning models, particularly those for low-level image processing tasks. Existing works have verified and improved its …

Evading Defenses to Transferable Adversarial Examples by Translation-Invariant Attacks

2019-04-05 · CVPR 2019 6 · Yinpeng Dong, Tianyu Pang, Hang Su, Jun Zhu

Deep neural networks are vulnerable to adversarial examples, which can mislead classifiers by adding imperceptible perturbations. An intriguing property of adversarial examples is their good transferability, making black…

Translation

Robust Invisible Hyperlinks in Physical Photographs Based on 3D Rendering Attacks

2019-12-03 · Jun Jia, Zhongpai Gao, Kang Chen, Menghan Hu 외

In the era of multimedia and Internet, people are eager to obtain information from offline to online. Quick Response (QR) codes and digital watermarks help us access information quickly. However, QR codes look ugly and i…

Decoder

Attacking Optical Character Recognition (OCR) Systems with Adversarial Watermarks

2020-02-08 · Lu Chen, Wei Xu

Optical character recognition (OCR) is widely applied in real applications serving as a key preprocessing tool. The adoption of deep neural network (DNN) in OCR results in the vulnerability against adversarial examples w…

Optical Character RecognitionOptical Character Recognition (OCR)