WAIR: Watermark Attack on Image Retrieval Systems
Zhu Duan, Xiaolong Zheng, Peilun Du, Liang Liu, Huadóng Ma · 2023
Recent studies show that image retrieval systems are vulnerable to adversarial attacks that adds imperceptible noise to the images. But the imperceptibility of noise limits the attack performance. As a commonly acceptable interference, watermark often appears in images, which can be treated as ‘‘imperceptible’’ but is unexploited. In this paper, we propose a Watermark Attack method on Image Retrieval systems (WAIR). Attacking retrieval systems is challenging due to black-box model, the absence of confidence guide, and attack failures and low efficiency caused by the randomness of traditional evolutionary algorithms. To solve these challenges, we propose a new evolutionary algorithm called Gene Joint Selecting Algorithm (GJSA) that jointly optimize the watermark parameters. We also design the Fitness Record Table (FRT), a new data structure that records the historical attack effect to guide the following evolution and avoid local optimal solutions. Thanks to FRT, WAIR can also reduce the duplicate searching caused by algorithm randomness. The extensive experiments show that WAIR can attack the black-box image retrieval system with a successful rate of 0.806, which is 12.4% higher than the traditional evolutionary algorithm. Moreover, for attacking commercial image retrieval system, we achieve 2$\times$ higher attack success rate on Baidu Image Retrieval API than the existing methods.