Investigating Protection of Deep Learning Visual Features on ECB Encrypted Images

Kasidit Chunhachatchawhankhun, Prarinya Siritanawan, Karin Sumongkayothin, Kazunori Kotani · 2021

In this paper, we demonstrate that images encrypted with Advanced Encryption Standard (AES) in Electronic Code Book (ECB) mode retain some local properties of the original images that Deep Neural Networks (DNNs) can detect these properties and perform classification tasks on this encrypted data. The experiment with the ECB encrypted MNIST handwritten digit dataset revealed that models trained on this dataset have an accuracy of around 80%. It also demonstrated that the model trained using one secret key does not work with other secret keys or the original dataset; the prediction accuracy plummeted to less than 10%. As a result, malicious users who do not know the secret keys will find the model inefficient, and it may be difficult to manipulate or change the prediction results.

Read the paper · More papers on PaperTik