New Method Enables High-Resolution Semantic Manipulation in Learned Image Compression
Researchers have identified a critical vulnerability in Learned Image Compression (LIC) systems, which utilize deep neural networks for efficient image storage. While LIC offers superior performance, it is susceptible to adversarial attacks that can distort images or manipulate their semantic content. Previous methods could only achieve low-resolution global semantic manipulation (GSM), leaving high-resolution GSM unexplored due to its complexity. This study introduces a novel approach called PGD²-GSM, which integrates a Periodic Geometric Decay schedule with the Projected Gradient Descent (PGD) method. Theoretical analysis reveals that successful GSM requires navigating specific stages—Lazying, Oscillating, and Refining—which standard attack schedules fail to accommodate. By addressing these limitations, the proposed method successfully achieves stable high-resolution GSM on standard datasets like Kodak. This breakthrough exposes a significant new threat to the integrity of AI-driven compression systems, demonstrating that attackers can now control the semantic view of compressed high-resolution images. The findings highlight the need for robust defense mechanisms in future LIC architectures to prevent such sophisticated adversarial manipulations.
Wire timeline
New Method Enables High-Resolution Semantic Manipulation in Learned Image Compression
Researchers have identified a critical vulnerability in Learned Image Compression (LIC) systems, which utilize deep neural networks for efficient image storage. While LIC offers superior performance, it is susceptible to adversarial attacks that can distort images or manipulate their semantic content. Previous methods could only achieve low-resolution global semantic manipulation (GSM), leaving high-resolution GSM unexplored due to its complexity. This study introduces a novel approach called PGD²-GSM, which integrates a Periodic Geometric Decay schedule with the Projected Gradient Descent (PGD) method. Theoretical analysis reveals that successful GSM requires navigating specific stages—Lazying, Oscillating, and Refining—which standard attack schedules fail to accommodate. By addressing these limitations, the proposed method successfully achieves stable high-resolution GSM on standard datasets like Kodak. This breakthrough exposes a significant new threat to the integrity of AI-driven compression systems, demonstrating that attackers can now control the semantic view of compressed high-resolution images. The findings highlight the need for robust defense mechanisms in future LIC architectures to prevent such sophisticated adversarial manipulations.
cs.AI updates on arXiv.org