Frequency-Domain Enhanced Adaptive Ensemble Adversarial Attack for Protecting Image Privacy
摘要
In scenarios involving social media and smart terminals, images uploaded by individuals to media platforms may be illegally extracted by deep learning models. Adversarial examples can induce incorrect model outputs by adding imperceptible perturbations to the images, without compromising image quality. This property can thus be leveraged to protect sensitive information. Ensemble adversarial attacks have been shown to enhance the transferability of adversarial examples effectively. By integrating multiple models to generate adversarial examples, these examples can bypass detection by various models. However, existing methods fail to fully exploit the unique characteristics and advantages of individual models. To address these limitations, this paper adopts a frequency-domain perspective. Through frequency domain enhancement, the sensitivity of models to perturbations of different frequencies is fully utilized. The model outputs are then weighted and fused using the Exponential Moving Average (EMA) loss, aiming to explore the individual characteristics of the models. Extensive experiments demonstrate that our method significantly improves the transferability of adversarial examples across models with different architectures, offering a solution that combines robustness and concealment for image privacy protection.