Adversarial Watermark Based Image Privacy Protection Algorithm

Yangjie Cao, Mingli Lu, Shuling Li, Yan Zhuang, Aosong Yang · 2022 2nd International Conference on Consumer Electronics and Computer Engineering (ICCECE) · 2022

In the era of rapid growth of visual information, deep hash learning is becoming more and more popular in the image retrieval community, which greatly improves search efficiency. However, privacy risks become prominent when online images are retrieved at scale and used as a rich repository of personal information. An attacker could extract a private image by querying for similar images of any available model from the target category. Existing privacy protection methods hide key information through image processing, which is at the expense of visual effects and the practicability of images. In this paper, we propose an image privacy protection method, which is based on adversarial attack and digital watermark, to provide image practicability and postmortem copyright security while maintains visual perception. We firstly convert the way of adding digital watermarking used as adversarial perturbation into an optimization problem to determine the best adding region and transparency. Then we add adversarial noise in watermark in order to improve the attacking effect meanwhile to make it more transparent to keep its visual imperceptibility. Extensive experiments demonstrate that MI-PriAWM can successfully make a given watermark with small perturbations to mislead hash retrieval models. The perceptibility of these adversarial watermarks in various settings is also considered.

Read the paper · More papers on PaperTik