Secure Detection of Image Manipulation by means of Random Feature Selection

02/02/2018
by   Zhipeng Chen, et al.
0

We address the problem of data-driven image manipulation detection in the presence of an attacker with limited knowledge about the detector. Specifically, we assume that the attacker knows the architecture of the detector, the training data and the class of features V the detector can rely on. In order to get an advantage in his race of arms with the attacker, the analyst designs the detector by relying on a subset of features chosen at random in V. Given its ignorance about the exact feature set, the adversary must attack a version of the detector based on the entire feature set. In this way, the effectiveness of the attack diminishes since there is no guarantee that attacking a detector working in the full feature space will result in a successful attack against the reduced-feature detector. We prove both theoretically and experimentally - by applying the proposed procedure to the detection of two specific kinds of image manipulations - that, thanks to random feature selection, the security of the detector increases significantly at the expense of a negligible loss of performance in the absence of attacks. We theoretically prove that, under some simplifying assumptions, the security of the detector increases significantly thanks to random feature selection. We also provide an experimental validation of the proposed procedure by focusing on the detection of two specific kinds of image manipulations. The experiments confirm the gain in security at the expense of a negligible loss of performance in the absence of attacks.

READ FULL TEXT
research
10/25/2019

Effectiveness of random deep feature selection for securing image manipulation detectors against adversarial examples

We investigate if the random feature selection approach proposed in [1] ...
research
02/22/2019

Improving the Security of Image Manipulation Detection through One-and-a-half-class Multiple Classification

Protecting image manipulation detectors against perfect knowledge attack...
research
05/25/2020

Adversarial Feature Selection against Evasion Attacks

Pattern recognition and machine learning techniques have been increasing...
research
04/21/2018

Is feature selection secure against training data poisoning?

Learning in adversarial settings is becoming an important task for appli...
research
12/15/2022

A new weighted ensemble model for phishing detection based on feature selection

A phishing attack is a sort of cyber assault in which the attacker sends...
research
04/10/2020

Higher-Order, Adversary-Aware, Double JPEG-Detection via Selected Training on Attacked Samples

In this paper we present an adversary-aware double JPEG detector which i...
research
05/15/2020

Memoryless Cumulative Sign Detector for Stealthy CPS Sensor Attacks

Stealthy false data injection attacks on cyber-physical systems introduc...

Please sign up or login with your details

Forgot password? Click here to reset