In this paper, we propose a novel generative model-based attack on learnable image encryption methods proposed for privacy-preserving deep learning. Various learnable encryption methods have been studied to protect the sensitive visual information of plain images, and some of them have been investigated to be robust enough against all existing attacks. However, previous attacks on image encryption focus only on traditional cryptanalytic attacks or reverse translation models, so these attacks cannot recover any visual information if a block-scrambling encryption step, which effectively destroys global information, is applied. Accordingly, in this paper, generative models are explored to evaluate whether such models can restore sensitive visual information from encrypted images for the first time. We first point out that encrypted images have some similarity with plain images in the embedding space. By taking advantage of leaked information from encrypted images, we propose a guided generative model as an attack on learnable image encryption to recover personally identifiable visual information. We implement the proposed attack in two ways by utilizing two state-of-the-art generative models: a StyleGAN-based model and latent diffusion-based one. Experiments were carried out on the CelebA-HQ and ImageNet datasets. Results show that images reconstructed by the proposed method have perceptual similarities to plain images.
翻译:本文提出了一种针对为隐私保护深度学习设计的可学习图像加密方法的新型生成模型攻击。已有多种可学习加密方法用于保护明文图像的敏感视觉信息,其中部分方法被证实对现存所有攻击具有足够鲁棒性。然而,以往对图像加密的攻击仅集中于传统密码分析攻击或反向翻译模型,因此当应用能有效破坏全局信息的块置乱加密步骤时,这些攻击无法恢复任何视觉信息。为此,本文首次探索生成模型能否从加密图像中恢复敏感视觉信息。我们首先指出加密图像在嵌入空间中与明文图像存在一定相似性。通过利用加密图像泄露的信息,我们提出了一种引导生成模型作为攻击可学习图像加密的方法,以恢复可识别个人身份的视觉信息。我们利用两种最先进的生成模型以两种方式实现所提出的攻击:基于StyleGAN的模型和基于潜在扩散的模型。在CelebA-HQ和ImageNet数据集上进行了实验。结果表明,所提方法重建的图像与明文图像具有感知相似性。