Font Size: a A A

Research And Implementation Of Attack And Defense Method Of Image Retrieval System Based On Watermark

Posted on:2024-01-10Degree:MasterType:Thesis
Country:ChinaCandidate:Z DuanFull Text:PDF
GTID:2568306944970599Subject:Computer Science and Technology
Abstract/Summary:PDF Full Text Request
The deep image retrieval system takes the deep neural network as the core,and its retrieval principle is matching based on the output features of the neural network.Therefore,the watermark attack noise acting on the deep neural network will also damage the retrieval ability of the deep image retrieval system.In this paper,the problem of watermark attacking image retrieval system is studied firstly.In addition,in order to deal with the threat of watermarking attacks,targeted defense methods also have certain research value.Although the academic community has launched a series of research on watermark attack and defense,these studies focus on image classification models with known attack and defense confidence,which is difficult to apply to actual black-box scenarios.In addition,the swarm optimization algorithm involved in the research will fall into local optimum due to problems such as repeated searches and missing receptive fields.Therefore,this paper explores the attack and defense algorithms of the image retrieval system.The main contents are as follows:1、The problem of watermark attack image retrieval system and the objective function are defined.A novel algorithm is proposed for the problem of watermark parameter value selection.The algorithm takes the fitness record table as the core,selects the optimal parameter combination based on the record information in the table,and optimizes the records in the table according to the feedback score.The algorithm makes full use of query information and can greatly improve query efficiency.2.A defense algorithm against watermark attack is proposed,which reduces the attack ability of watermark noise by weakening the opacity of watermark.The algorithm makes the defense effect more pertinent by modifying the watermark area,and also avoids the impact on non-watermark attack images.3、A watermarking attack-defense image retrieval system is designed and implemented.The real-time and stability tests show that the watermarking attack system meets the requirements of black-box watermarking attacks in actual scenarios.4.This paper conducts a large number of attack and defense experiments on various image retrieval systems.Experiments show that the attack success rate of the algorithm in this paper is 12.4%higher than that of the traditional evolutionary algorithm.In the experiment of attacking Baidu cloud image retrieval API,the attack success rate of this algorithm is twice that of the comparison algorithm.The defense algorithm proposed in this paper can reduce the performance of watermark attack by 22%~57%.
Keywords/Search Tags:image retrieval system, watermark attack, evolutionary algorithm, defense algorithm
PDF Full Text Request
Related items