2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)(2025)
被引用2|浏览4
摘要
In recent years, Learned Image Compression (LIC) has drawn significant attention because of its powerful coding ability. However, similar to most neural network-based schemes, LIC is vulnerable to adversarial attacks. To mitigate the influence of adversarial attacks, adversarial training is usually adopted to finetune the network. This paper proposes efficient adversarial attack and training methods for LIC, by proposing three losses based on the original image, adversarial image, and reconstructed image. For the attack, we study the effects of three proposed losses on four qualities of classical factorized-prior and hyperprior models. For the adversarial training, all the proposed three losses are used in the finetuning for the three attack scenarios, respectively. We find that using the loss between the adversarial output and the original image achieves strong defense performance against various attacks, improving RD cost by up to 68.6%. Furthermore, we show that updating only the decoding during adversarial training along with reducing the number of iterations, can reduce the training time by up to 82.9% without compromising the defense performance.
更多
查看译文
关键词
Learned Image Compression,Adversarial Attack,Adversarial Training