On the Security of the One-and-a-Half-Class Classifier for SPAM Feature-Based Image Forensics

被引:2
|
作者
Lorch, Benedikt [1 ]
Schirrmacher, Franziska [1 ]
Maier, Anatol [1 ]
Riess, Christian [1 ]
机构
[1] Friedrich Alexander Univ Erlangen Nurnberg, IT Secur Infrastruct Lab, D-91058 Erlangen, Germany
关键词
Detectors; Feature extraction; Robustness; Glass box; Security; Distortion; Quantization (signal); Image forensics; counter-forensics; adversarial examples; one-and-a-half-class classifier; MANIPULATION; TRACES;
D O I
10.1109/TIFS.2023.3266168
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Combining multiple classifiers is a promising approach to hardening forensic detectors against adversarial evasion attacks. The key idea is that an attacker must fool all individual classifiers to evade detection. The 1.5C classifier is one of these multiple-classifier detectors that is attack-agnostic, and thus even increases the difficulty for an omniscient attacker. Recent work evaluated the 1.5C classifier with SPAM features for image manipulation detection. Despite showing promising results, their security analysis leaves several aspects unresolved. Surprisingly, the results reveal that fooling only one component is often sufficient to evade detection. Additionally, the authors evaluate classifier robustness with only a black-box attack because, currently, there is no white-box attack against SPAM feature-based classifiers. This paper addresses these shortcomings and complements the previous security analysis. First, we develop a novel white-box attack against SPAM feature-based detectors. The proposed attack produces adversarial images with lower distortion than the previous attack. Second, by analyzing the 1.5C classifier's acceptance region, we identify three pitfalls that explain why the current 1.5C classifier is less robust than a binary classifier in some settings. Third, we illustrate how to mitigate these pitfalls with a simple axis-aligned split classifier. Our experimental evaluation demonstrates the increased robustness of the proposed detector for SPAM feature-based image manipulation detection.
引用
收藏
页码:2466 / 2479
页数:14
相关论文
共 50 条
  • [1] Improving the security of image manipulation detection through one-and-a-half-class multiple classification
    Barni, Mauro
    Nowroozi, Ehsan
    Tondi, Benedetta
    MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (3-4) : 2383 - 2408
  • [2] Improving the security of image manipulation detection through one-and-a-half-class multiple classification
    Mauro Barni
    Ehsan Nowroozi
    Benedetta Tondi
    Multimedia Tools and Applications, 2020, 79 : 2383 - 2408
  • [3] One-and-a-Half-Class Multiple Classifier Systems for Secure Learning Against Evasion Attacks at Test Time
    Biggio, Battista
    Corona, Igino
    He, Zhi-Min
    Chan, Patrick P. K.
    Giacinto, Giorgio
    Yeung, Daniel S.
    Roli, Fabio
    MULTIPLE CLASSIFIER SYSTEMS (MCS 2015), 2015, 9132 : 168 - 180
  • [4] Contextual Feature Based One-Class Classifier Approach for Detecting Video Response Spam on YouTube
    Chaudhary, Vidushi
    Sureka, Ashish
    2013 ELEVENTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2013, : 195 - 204
  • [5] Partitioned Feature-based Classifier Model
    Park, Dong-Chul
    2009 IEEE INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING AND INFORMATION TECHNOLOGY (ISSPIT 2009), 2009, : 412 - 417
  • [6] The Impact of Spam Reviews on Feature-based Sentiment Analysis
    Saeed, Nagwa M. K.
    Helal, Nivin A.
    Badr, Nagwa L.
    Gharib, Tarek F.
    PROCEEDINGS OF 2018 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND SYSTEMS (ICCES), 2018, : 633 - 639
  • [7] Feature Preprocessing Algorithm Based on One-Class Classifier
    Gan, Wenya
    Huang, YuanLing
    You, Ling
    PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 606 - 609
  • [8] A feature-based serial approach to classifier combination
    Last, A
    Bunke, H
    Kandel, A
    PATTERN ANALYSIS AND APPLICATIONS, 2002, 5 (04) : 385 - 398
  • [9] A Feature-Based Serial Approach to Classifier Combination
    M. Last
    H. Bunke
    A. Kandel
    Pattern Analysis and Applications, 2002, 5 : 385 - 398
  • [10] Feature-based image analysis
    Lillholm, M
    Nielsen, M
    Griffin, LD
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2003, 52 (2-3) : 73 - 95