Adversarial Optical Character Recognition to Protect Character Content: A Universal Adversarial Image Generation Scheme
摘要
With the rapid development of network technology, the presentation form of digital content is gradually converted from traditional media to digital documents, and it becomes crucial to protect digital content from unauthorized access and misuse. Malicious attackers use optical character recognition(OCR) to intercept and identify digital content, but various protection methods, including digital watermarking, make it difficult to prevent malicious exploitation of digital content. Since most of the OCR models are based on neural networks that are susceptible to adversarial perturbations, this paper proposes a relatively universal perturbation generation method for OCR, which first compresses and downsizes the original image using singular value decomposition, and generates adversarial perturbations using generative adversarial networks (GAN) to obtain an adversarial image ultimately. Moreover, the method proposed in this paper does not need to know any detailed parameters of the model in advance and does not need to output specific digital content. The method requires no specific target labels; its effectiveness is demonstrated as long as the target model outputs incorrect characters. Comparative experiments are conducted on multiple datasets for multiple complex and diverse optical character recognition models, and several commercial OCR services are also utilized to validate the effectiveness of the generated perturbations, demonstrating the effectiveness and universality of the proposed method in this paper.