Towards the Transferable Reversible Adversarial Example via Distribution-Relevant Attack
摘要
Creating and labeling datasets on a large scale is a costly process, and such datasets should be considered the intellectual property (IP) of the dataset creators. How to ensure the dataset is legally trained by authorized users rather than by unauthorized DNNs, is a challenging topic. Reversible Adversarial Example (RAE) offers an efficient solution that can mislead the classification of unauthorized DNNs without impacting authorized users. In this paper, we present a novel method to create reversible adversarial examples using data distribution and image camouflage. By deviating the image from its original distribution, we enhance the transferability of reversible adversarial examples while improving attack performance. To further improve the visual quality of these examples, we utilize a feature pooling module to optimize the distribution of adversarial perturbation. The proposed method is tesed on Caltech-256 and TinyImageNet datasets, the experiment results demonstrated its effectiveness.