Reversible Adversarial Attack based on Pixel Smoothing in HSV Colorspace

Wanli Lyu, Xinming Sun, Zhaoxia Yin · 2024

As adversarial attack technology advances rapidly, more individuals are employing it to safeguard crucial and private images. Adversarial attacks modify the pixel values of images to achieve the result of misleading neural network decisions. However, modifying pixels can seriously weaken the effectiveness of digital forensics of pictures in the military and medical fields. Therefore, there is a need to safeguard images and have the capability to restore them to their original state in these fields. Currently, methods for generating reversible adversarial examples exhibit significant limitations, such as the inability to fully embed perturbation information, resulting in unsatisfactory image recovery and protected images with poor visual quality. In this paper, we use reversible information hiding techniques and pixel smoothing operations in the HSV colorspace to produce higher-quality protected images while ensuring the lossless recovery of protected images. Experiments show that the method generates reversible adversarial examples with excellent visual quality compared to existing methods.

Read the paper · More papers on PaperTik