Bitstream Collisions in Neural Image Compression via Adversarial Perturbations
Fuente:
arXiv
Guardado en:
| Autores principales: | , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866910893155024896 |
|---|---|
| author | Madden, Jordan Dorje, Lhamo Li, Xiaohua |
| author_facet | Madden, Jordan Dorje, Lhamo Li, Xiaohua |
| contents | Neural image compression (NIC) has emerged as a promising alternative to classical compression techniques, offering improved compression ratios. Despite its progress towards standardization and practical deployment, there has been minimal exploration into it's robustness and security. This study reveals an unexpected vulnerability in NIC - bitstream collisions - where semantically different images produce identical compressed bitstreams. Utilizing a novel whitebox adversarial attack algorithm, this paper demonstrates that adding carefully crafted perturbations to semantically different images can cause their compressed bitstreams to collide exactly. The collision vulnerability poses a threat to the practical usability of NIC, particularly in security-critical applications. The cause of the collision is analyzed, and a simple yet effective mitigation method is presented. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2503_19817 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Bitstream Collisions in Neural Image Compression via Adversarial Perturbations Madden, Jordan Dorje, Lhamo Li, Xiaohua Cryptography and Security Artificial Intelligence Neural image compression (NIC) has emerged as a promising alternative to classical compression techniques, offering improved compression ratios. Despite its progress towards standardization and practical deployment, there has been minimal exploration into it's robustness and security. This study reveals an unexpected vulnerability in NIC - bitstream collisions - where semantically different images produce identical compressed bitstreams. Utilizing a novel whitebox adversarial attack algorithm, this paper demonstrates that adding carefully crafted perturbations to semantically different images can cause their compressed bitstreams to collide exactly. The collision vulnerability poses a threat to the practical usability of NIC, particularly in security-critical applications. The cause of the collision is analyzed, and a simple yet effective mitigation method is presented. |
| title | Bitstream Collisions in Neural Image Compression via Adversarial Perturbations |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2503.19817 |