Reversible Adversarial Examples based on Self-Embedding Watermark for Image Privacy Protection
Xu Cao, Ju Liu, Jinghui Yin, Xuejun Cheng, Jing Li, Hao Ma, Guanghui Luo · 2024
Personal images shared online are susceptible to malicious collection and misuse, posing significant privacy risks. Reversible Adversarial Example (RAE) provides an effective safeguard that prevents the analysis of unauthorized models without affecting authorized models. However, the vulnerability of image content extends beyond illegal analysis to deliberate tampering. Existing RAE methods struggle to integrate with tamper defense techniques, and exhibit limited attack ability due to the trade-off between perturbation strength (i.e. attack ability) and recoverability. To this end, we propose a novel approach for generating reversible adversarial examples with self-embedding watermarks (W-RAE). Specifically, we convert the generation of RAEs into a deep steganography task and decouple the constraints between perturbation strength and recoverability to enhance RAEs’ attack performance. Additionally, by embedding crafted self-embedding watermarks during the RAE construction process, our method supports both data access control and tamper defense, thereby protecting image privacy from multiple perspectives. Extensive experiments have demonstrated its effectiveness as a privacy-preserving mechanism.