Keep It Real: Challenges in Attacking Compression-Based Adversarial Purification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Räber, Samuel, Aczel, Till, Plesner, Andreas, Wattenhofer, Roger
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918181339136000
author Räber, Samuel
Aczel, Till
Plesner, Andreas
Wattenhofer, Roger
author_facet Räber, Samuel
Aczel, Till
Plesner, Andreas
Wattenhofer, Roger
contents Previous work has suggested that preprocessing images through lossy compression can defend against adversarial perturbations, but comprehensive attack evaluations have been lacking. In this paper, we construct strong white-box and adaptive attacks against various compression models and identify a critical challenge for attackers: high realism in reconstructed images significantly increases attack difficulty. Through rigorous evaluation across multiple attack scenarios, we demonstrate that compression models capable of producing realistic, high-fidelity reconstructions are substantially more resistant to our attacks. In contrast, low-realism compression models can be broken. Our analysis reveals that this is not due to gradient masking. Rather, realistic reconstructions maintaining distributional alignment with natural images seem to offer inherent robustness. This work highlights a significant obstacle for future adversarial attacks and suggests that developing more effective techniques to overcome realism represents an essential challenge for comprehensive security evaluation.
format Preprint
id arxiv_https___arxiv_org_abs_2508_05489
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Keep It Real: Challenges in Attacking Compression-Based Adversarial Purification
Räber, Samuel
Aczel, Till
Plesner, Andreas
Wattenhofer, Roger
Computer Vision and Pattern Recognition
Machine Learning
Image and Video Processing
Previous work has suggested that preprocessing images through lossy compression can defend against adversarial perturbations, but comprehensive attack evaluations have been lacking. In this paper, we construct strong white-box and adaptive attacks against various compression models and identify a critical challenge for attackers: high realism in reconstructed images significantly increases attack difficulty. Through rigorous evaluation across multiple attack scenarios, we demonstrate that compression models capable of producing realistic, high-fidelity reconstructions are substantially more resistant to our attacks. In contrast, low-realism compression models can be broken. Our analysis reveals that this is not due to gradient masking. Rather, realistic reconstructions maintaining distributional alignment with natural images seem to offer inherent robustness. This work highlights a significant obstacle for future adversarial attacks and suggests that developing more effective techniques to overcome realism represents an essential challenge for comprehensive security evaluation.
title Keep It Real: Challenges in Attacking Compression-Based Adversarial Purification
topic Computer Vision and Pattern Recognition
Machine Learning
Image and Video Processing
url https://arxiv.org/abs/2508.05489