UTDHA is proposed, the first unrestricted targeted attack for deep hashing models using contrastive-guided latent diffusion and outperforms existing targeted adversarial attack baselines for deep hashing models in both attack effectiveness and imperceptibility.
Deep hashing has emerged as an effective and widely adopted framework for similarity retrieval, owing to its computational efficiency and the powerful feature extraction capabilities of deep learning (DL). Despite their strong performance in multi-modal and high-dimensional data retrieval tasks, recent studies have exposed the susceptibility of DL models to adversarial attacks, including in retrieval scenarios. This underscores the critical need for enhancing robustness in DL models to ensure reliable inference. However, most adversarial robustness studies focus on classification tasks, where explicit labels facilitate supervised adversarial training. In contrast, retrieval tasks typically rely on similarity matrices rather than explicit labels, making direct adversarial optimization challenging and limiting its application in large-scale retrieval settings. To address this gap, we propose Deep Supervised Adversarial Robust Hashing (DSARH), an end-to-end framework that leverages similarity matrices and learnable hash codes to construct gradient-based worst-case perturbations, enabling efficient adversarial training and robust feature learning for retrieval. Extensive experiments on cross-modal and image retrieval tasks demonstrate that existing deep hashing models are highly vulnerable to adversarial perturbations, whereas DSARH achieves superior robust generalization across a wide range of adversarial scenarios. Moreover, the robust visual features learned by DSARH help mitigate modality heterogeneity, resulting in consistent improvements in both standard and adversarial performance across multiple image-text retrieval benchmarks compared to state-of-the-art baselines. These results highlight the critical role of adversarial robustness in developing reliable and effective multi-modal retrieval systems.
Xingwei Zhang, Gang Zhou, Xiaolong Zheng et al.· IEEE Transactions on Pattern...· 0 citations
Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.
Yi Pan, Jun-Jie Huang, Tianrui Liu et al.· 0 citations
Deep hashing is widely adopted in large-scale image retrieval for its efficiency, but its reliance on large-scale datasets makes it vulnerable to backdoor threats. Recently, BadHash, a clean-label backdoor attack, has shown the ability to compromise deep hashing models by generating poisoned samples via a conditional generative adversarial network. These samples appear benign but are crafted to manipulate hash codes, making existing defense methods ineffective in the hash space. To address the challenge, we propose HashRuler, a lightweight and effective hash-code-based detection framework tailored for deep hashing models. HashRuler introduces two complementary metrics, Center Similarity Deviation (CSD) and Local Sparsity (LS), which jointly capture global and local distributional anomalies of sample hash codes. CSD quantifies a sample’s deviation from the class-specific hash center, while LS measures local outlier behavior relative to its nearest neighbors. Experimental results show that HashRuler achieves up to 97% detection accuracy against BadHash attacks, with extensive evaluations across diverse datasets, attack types, and model architectures confirming its effectiveness and generalizability.
Zhenzhu Chen, Wen-Ting Xu, Rui Zhang et al.· IEEE Transactions on Informa...· 0 citations
This paper introduces DefendMal, a novel framework that synergistically combines Denoise Autoencoder with Sequence Squeezing, a Context-aware Adversarial Generator (CAG-AdvGAN), Projected Gradient Descent (PGD) adversarial training, and a Positive–Negative Detector with Variational Autoencoder (PNDetector-VAE) to enhance robustness against evolving adversarial threats.
Dennis Benedict Crasta, Vikash Kumar· Journal of Computer Virology...· 0 citations
Deep-OCR (DeepSeek-OCR) advances document recognition by treating the visual modality as an optical compression medium, enabling long-context OCR at low token cost. However, its increased complexity may introduce new security vulnerabilities. In this paper, we present, to the best of our knowledge, the first pure black-box adversarial attack against a generative OCR vision-language model, where only the decoded string can be queried and no gradients, logits, or model internals are available. We recast the attack as a zeroth-order optimization problem driven by a bounded scalar loss defined directly on the string output via sequence similarity, and estimate the gradient with a random-direction finite-difference scheme whose query cost is independent of the image dimension. An Adam update with ell_infinity projection yields imperceptible perturbations for both untargeted and targeted objectives. Pilot experiments on Deep-OCR validate the string-only attack and evaluation pipeline and expose severe qualitative decoder failures, including repetition, truncation, and prompt leakage. They also show that controlled targeted rewriting remains substantially harder than untargeted degradation; we avoid claiming targeted success until the pre-registered evaluation is complete.
Wenbo Sun, Hong-Zong Li, Yanyun Wang et al.· 0 citations
Machine learning models are increasingly adapted in various domains. However, adversarial examples pose a significant threat to the reliable deployment of these models. In recent years, some powerful adversarial example attacks have been proposed for the fast and query-efficient generation of adversarial examples, even in black-box scenarios, highlighting the need for scalable, low-cost, and powerful defenses. In this work, we present two contributions to the domain of black-box adversarial example attacks and defenses. First, we propose Random Logit Scaling (RLS), a randomization-based defense against black-box score-based adversarial example attacks. RLS is a plug-and-play, post-processing defense that can be implemented on top of any existing ML model with minimal effort. The idea behind RLS is to confuse an attacker by outputting falsified scores resulting from randomly scaled logits while maintaining the model accuracy. We show that RLS significantly reduces the success rate of state-of-the-art black-box score-based attacks while preserving the accuracy and minimizing confidence score distortion compared to state-of-the-art randomization-based defenses. Second, we introduce a novel adaptive attack against AAA, a SOTA non-randomized black-box defense against black-box score-based attacks that also modifies output logits to confuse attackers, demonstrating its vulnerability against adaptive attacks.
Hamid Dashtbani, Mehdi Dousti Gandomani, A. M. Sadeghzadeh· Trans. Mach. Learn. Res.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.