Security assessment method of perceptual hash function based on antagonistic machine learning

The security of the perceived hash function is evaluated through adversarial machine learning generation and adversarial samples, which solves the problem of feature extraction limitations and attack vulnerability of perceived hash function in multimedia data processing, and improves the security and reliability of multimedia data.

CN120277642APending Publication Date: 2025-07-08LIAONING UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510114196.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing perceptual hash functions have feature extraction limitations, hash conflicts and attack vulnerability in multimedia data processing, making it difficult to ensure the security and accuracy of data in complex multimedia environments.

Method used

Adversarial machine learning is adopted to evaluate the security of perceived hash functions by generating adversarial samples, design generators and discriminators, train a generative adversarial network using specific loss functions, generate adversarial samples that can deceive the perceived hash functions, and evaluate its security through success rate and similarity indicators.

Benefits of technology

It reveals potential vulnerabilities in perceived hash functions, improves the security and reliability of multimedia data, can effectively resist attacks, and ensures the authenticity and integrity of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005257416050000041
    Figure BDA0005257416050000041
  • Figure BDA0005257416050000071
    Figure BDA0005257416050000071
  • Figure FDA0005257416040000021
    Figure FDA0005257416040000021
Patent Text Reader

Abstract

The invention relates to a security assessment method of a perceptual hash function based on antagonistic machine learning, and belongs to the field of security of machine learning. The method comprises the following steps of 1, collecting a data set which can be used for training a generative adversarial network; 2, designing a generator, a discriminator and a loss function of the generative adversarial network; and 3, judging the security of the perceptual hash function through the success rate and the similarity index. According to the method, the security of the perceptual hash function is evaluated through antagonistic machine learning. The perceptual hash function is a hash function for computing multimedia data. By generating adversarial samples, the perceptual hash functions are spoofed, so that the perceptual hash functions cannot correctly identify or compare similar multimedia data, and if the spoofing samples are rich enough, the perceptual hash functions are considered to be unsafe. Therefore, potential vulnerabilities of the multimedia perceptual hash function are revealed, and valuable guidance is provided for further enhancing the security and credibility of multimedia data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for evaluating the security of a perceptual hash function based on adversarial machine learning, and belongs to the field of the security of machine learning. Background Art

[0002] A perceptual hash function is a technology used for similarity comparison and retrieval of multimedia data such as images and audio. By applying machine learning algorithms, it converts the input multimedia data into a hash value of a fixed length, such that similar data has similar hash values. The development background of the perceptual hash function is the limitation of traditional hash functions in processing multimedia data. Traditional hash functions usually directly map the input data into a binary code of a fixed length, unable to consider the semantic and perceptual differences of the data, resulting in the possibility that similar data may have completely different hash values. This limits the application of traditional hash functions in multimedia data similarity comparison and retrieval.

[0003] The perceptual hash function has wide applications in fields such as images and audio. For example, in the field of images, it can be used for tasks such as similar picture search, copyright protection, and picture deduplication; in the field of audio, it can be used for tasks such as music fingerprint recognition and copyright detection. By applying machine learning algorithms, the perceptual hash function can effectively process multimedia data and provide efficient similarity comparison and retrieval functions.

[0004] In the current era of rapid digital development, the perceptual hash function technology has occupied an important position in the field of multimedia data processing and has been extremely widely applied. However, like any technology, the perceptual hash function technology is not perfect and has many disadvantages and deficiencies.

[0005] Firstly, there are obvious limitations in the feature extraction link. When faced with multimedia data of various forms and rich contents, existing feature extraction methods often have difficulty comprehensively and accurately capturing the key features of the data, resulting in the subsequent generated hash values being unable to fully reflect the uniqueness of the data. Moreover, the possibility of hash collisions is always an unavoidable problem. Due to the mapping characteristics of the hash function, different multimedia data may be mapped to the same hash value, and the probability of this situation occurring in a multimedia environment with a large and complex data volume cannot be underestimated, thus bringing great trouble to the accurate identification and differentiation of data.

[0006] In particular, perceptual hash functions exhibit relatively high vulnerability when faced with attacks. In the current complex and ever-changing network environment, malicious attackers often attempt to attack hash functions through various means for the malicious purposes of tampering with, forging, or stealing multimedia data. At the same time, the diversity of multimedia data also poses a huge challenge to perceptual hash functions. Especially for multimedia data such as videos with high dynamics, continuity, and rich spatio-temporal information, and 3D models with complex geometric structures and texture features, the current perceptual hash functions still perform relatively weakly when dealing with these complex multimedia data and are difficult to meet the high requirements in practical applications.

[0007] In addition, since the operation of perceptual hash functions highly depends on key steps such as feature extraction and quantization, their performance is greatly affected by factors such as data quality and noise. When there are quality problems in multimedia data, such as low resolution, blurred images, distorted audio, etc., or when it is affected by noise interference, the accuracy of feature extraction will be greatly reduced, thereby affecting the generation and accuracy of hash values, and seriously questioning the reliability of perceptual hash functions in practical applications.

[0008] In terms of the security of hash functions, this has always been a focus area of concern for researchers. They continuously conduct in-depth research on the collision resistance and security of hash functions, strive to find possible new attack methods, and are committed to improving the design of hash functions, hoping to significantly improve the reliability and stability of hash functions in the field of information security through these efforts, and ensure the security of multimedia data during storage, transmission, and processing.

[0009] Generally speaking, although perceptual hash function technology has shown broad application prospects in the field of multimedia data processing and provided effective solutions for many aspects such as the management, retrieval, and copyright protection of multimedia data, it is undeniable that it still has a series of limitations and challenges. This urgently requires researchers to persevere in in-depth research and exploration, continuously innovate and optimize perceptual hash function technology, so that it can better adapt to the increasingly complex multimedia data processing tasks and play a greater role in ensuring data security and efficient utilization.

[0010] Among the attack techniques against hash functions, the second pre-image attack is one of them. This attack method is highly targeted. Its goal is to find another input with exactly the same hash value for a specific known input with all efforts. Implementing the second pre-image attack is by no means easy. The process is extremely complex and requires the attacker to deeply and thoroughly understand the design principle and specific implementation details of the hash function. Only in this way is it possible to find the weak links of the hash function and then successfully implement the attack. Just because of this, researchers in this field deeply realize the importance of the security of hash functions. They are sparing no effort to explore more secure and reliable hash function design methods, aiming to further improve the security and reliability of hash functions, effectively resist various potential attacks, and escort the security of multimedia data. Since hash functions play important roles in many key fields, such as financial transactions, e-government, information encryption, etc., and have extremely high requirements for security, evaluating the security of hash functions naturally becomes a crucial and urgent key issue that needs to be deeply studied. The research results will be directly related to the stability and reliability of the entire information security system. Summary of the Invention

[0011] To solve the above technical problems, the present invention provides a method for evaluating the security of a perceptual hash function based on adversarial machine learning, which evaluates the security of the perceptual hash function through adversarial machine learning.

[0012] The object of the present invention is achieved by the following technical solutions: A method for evaluating the security of a perceptual hash function based on adversarial machine learning, characterized in that the steps are as follows:

[0013] Step 1: Collect a data set that can be used to train a generative adversarial network;

[0014] Step 2: Design a generator, a discriminator and a loss function of the generative adversarial network;

[0015] Step 3: Judge the security of the perceptual hash function through success rate and similarity metrics.

[0016] Among them, the data set described in Step 1 includes data sets of different modalities (such as images, audio, videos); the data set is downloaded from public data sets and covers various scenarios and contents.

[0017] The loss function includes a generator loss function and a discriminator loss function;

[0018] The generator loss function described above includes the following two parts:

[0019] Adversarial Loss: By minimizing the probability that the generated adversarial samples are judged as forgeries by the discriminator, the generated adversarial samples are made closer to the real data.

[0020] The adversarial loss can be represented using a binary classification loss function:

[0021] L_adv = -log(D(x)) - log(1 - D(G(z))) (1)

[0022] Where x represents the real data and z represents the input random noise.

[0023] However, only using the adversarial loss may not be able to fully capture the distribution characteristics of the real data, resulting in a certain gap between the samples generated by the generator and the real data;

[0024] Similarity Loss: By minimizing the similarity distance between the generated data and the original data, the generated adversarial samples are made closer to the original data; it can be represented using the Mean Squared Error loss function:

[0025] L_sim = ||G(z) - x|| 2 (2)

[0026] Where x represents the real data and G(z) represents the adversarial samples generated by the generator.

[0027] The discriminator loss function described above includes the following two parts:

[0028] Adversarial Loss: By maximizing the probability of judging the real data as true and the probability of judging the generated adversarial samples as forgeries, the discriminator can identify the generated adversarial samples;

[0029] Penalty Term: By restricting the gradient norm of the discriminator output, the occurrence of gradient explosion and disappearance phenomena is prevented;

[0030] To prevent the occurrence of gradient explosion and disappearance phenomena, a gradient penalty term can be used to constrain the output of the discriminator; the penalty term adopted is the gradient penalty term in the Wasserstein distance

[0031]

[0032] Where ε is a random number uniformly sampled from [0,1], λ is the penalty coefficient, is the gradient of the discriminator D with respect to the input data.

[0033] The described generator and discriminator are constructed through GAN; the goal of the generator is to generate adversarial samples that are similar to the original data but have different hash values, while the goal of the discriminator is to distinguish the generated adversarial samples from the original data. The specific training process is as follows:

[0034] Train the GAN model using the defined loss function; first, use random noise as input and generate adversarial samples through the generator; then, input the generated adversarial samples and the real data into the discriminator for discrimination, calculate the loss function of the discriminator; then backpropagate to update the weight parameters of the discriminator; next, use the adversarial samples generated by the generator as input, recalculate the loss function and backpropagate to update the weight parameters of the generator; iterate the training like this until the adversarial samples generated by the generator can deceive the multimedia perceptual hash function;

[0035] The optimization goal of the generator is to minimize the adversarial loss and the similarity loss:

[0036] min G =L - adv+α*L_Sim (4)

[0037] where α is the weight coefficient of the similarity loss

[0038] The optimization goal of the discriminator is to maximize the adversarial loss and minimize the penalty term:

[0039] max D =L_adv-γ*L_penalty (5)

[0040] where γ is the weight coefficient of the penalty term.

[0041] The success rate and similarity metrics in step three are specifically as follows:

[0042] (1) Success rate metric: Assume the success rate of the attack is a, and we set the threshold as k. Then, if a > k, it is considered that there is a security risk of the hash function being attacked;

[0043] (2) Similarity metric: Assume the set of all adversarial samples for which the attack is successful is Z, and the set of their corresponding hash function values is U. Then we define the similarity function, SIM, as follows:

[0044]

[0045] Set the threshold as sk. Then, if SIM(Z, U) > k, it is considered that there is a similarity security risk of the hash function being attacked.

[0046] Advantages of the present invention: The method of the present invention aims to deceive these perceptual hash functions by generating adversarial samples, making them unable to correctly identify or compare similar multimedia data. If the deceptive samples are rich enough, the perceptual hash function is considered insecure. We will reveal the potential vulnerabilities of multimedia perceptual hash functions and provide valuable guidance for further enhancing the security and credibility of multimedia data.

[0047] The method of the present invention generates adversarial samples based on a profound analysis of the principles of perceptual hash functions and a precise grasp of their possible weak points. By applying adversarial sample generation techniques and deeply mining the characteristics of multimedia data, various features of multimedia data are skillfully tampered with and disguised. These specially processed adversarial samples seemingly look no different from ordinary multimedia data, but they contain carefully designed interference factors inside, and their ultimate goal is to precisely deceive these perceptual hash functions.

[0048] When these adversarial samples are input into the operating system of the perceptual hash function, they will skillfully avoid the original recognition mechanism of the function, resulting in serious deviations when the function performs its key task of accurately identifying or precisely comparing similar multimedia data. Multimedia data that should have been clearly determined to be highly similar may be wrongly determined by the perceptual hash function to be unrelated under the interference of adversarial samples; conversely, those significantly different multimedia data that should have been easily distinguished may be misjudged as very similar.

[0049] This deceptive effect is not an accidental individual phenomenon, but is systematically achieved by constructing a sufficient number and diverse types of deceptive samples. Only when we can successfully generate a large number of deceptive samples covering various possible situations, and these samples continuously and stably exhibit deceptive capabilities during the interaction with the perceptual hash function, causing the perceptual hash function to frequently make incorrect judgments, do we have sufficient reason to conclude that the perceptual hash function has serious security vulnerabilities and cannot reliably guarantee the authenticity and integrity of multimedia data in practical applications.

[0050] Furthermore, our research work does not merely stay on the surface phenomenon of discovering that perceptual hash functions can be deceived. Instead, we delve deep into it and reveal the potential vulnerabilities of multimedia perceptual hash functions from all aspects and multiple angles. These vulnerabilities may be hidden in seemingly insignificant feature extraction details, may also be concealed in the complex algorithms for generating hash values, or even may exist in the final comparison logic link. By carefully sorting out and accurately locating these potential vulnerabilities, we will provide highly targeted and practical guidance for further strengthening the security and credibility of multimedia data. Whether it is for the R & D teams of perceptual hash functions, it can provide them with key improvement directions to help them optimize existing technologies and fill security loopholes; or for users and enterprises that rely on multimedia data for various business activities, it helps them make more informed choices among numerous hash function technologies, thus better ensuring the secure and reliable application of their own multimedia data. Our research results will play a key role in the field of multimedia data security protection and promote the entire industry to develop towards a more secure, stable, and trustworthy direction. Detailed implementation manners

[0051] The specific idea of the technical solution of the present invention is as follows: First, collect a data set that can be used to train a generative adversarial network. Then, generate adversarial samples by designing a generator, a discriminator, a loss function, etc. of the generative adversarial network. Finally, evaluate the security of the perceptual hash function through success rate and similarity metrics.

[0052] (1) Data set preparation: First, we need to collect a data set containing different modalities (such as images, audio, videos). It can be downloaded from public data sets, such as ImageNet, CIFAR-10, MNIST, etc. To attack multimedia perceptual hash functions, it is necessary to ensure that the data set covers various scenarios and contents to ensure the wide applicability of the attack.

[0053] (2) Generator and discriminator design: Next, we need to design a generator and a discriminator. The goal of the generator is to generate adversarial samples that are similar to the original data but have different hash values, while the goal of the discriminator is to distinguish the generated adversarial samples from the original data. Usually, a GAN is used to construct the generator and the discriminator.

[0054] (3) Loss function design: To train the generative adversarial network, we need to define an appropriate loss function.

[0055] (a) The loss function of the generator usually consists of two parts:

[0056] Adversarial Loss: By minimizing the probability that the generated adversarial samples are judged as forged by the discriminator, the generated adversarial samples are made closer to the real data.

[0057] The adversarial loss can be represented using a binary classification loss function:

[0058] L_adv = -log(D(x)) - log(1 - D(G(z))) (1)

[0059] where x represents the real data and z represents the input random noise.

[0060] However, using only the adversarial loss may not be able to fully capture the distribution characteristics of the real data, resulting in a certain gap between the samples generated by the generator and the real data.

[0061] Similarity Loss: By minimizing the similarity distance between the generated data and the original data, the generated adversarial samples are made closer to the original data. It can be represented using the Mean Squared Error loss function:

[0062] L 一 sim = ||G(z") - x||² (2)

[0063] where x represents the real data and G(z) represents the adversarial samples generated by the generator.

[0064] (b) The loss function of the discriminator usually consists of two parts:

[0065] Adversarial loss: By maximizing the probability of judging the real data as true and the probability of judging the generated adversarial samples as fake, the discriminator can identify the generated adversarial samples.

[0066] Penalty Term: By restricting the gradient norm of the discriminator output, the occurrence of gradient explosion and disappearance phenomena is prevented.

[0067] To prevent the occurrence of gradient explosion and disappearance phenomena, a gradient penalty term can be used to constrain the output of the discriminator. The penalty term adopted is the gradient penalty term in the Wasserstein distance

[0068]

[0069] where ε is a random number uniformly sampled from [0, 1], λ is the penalty coefficient, is the gradient of the discriminator D with respect to the input data.

[0070] (4) Training the generator and discriminator: Train the GAN model using the defined loss function. First, use random noise as the input and generate adversarial samples through the generator. Then, input the generated adversarial samples and the real data into the discriminator for discrimination, and calculate the loss function of the discriminator. Next, update the weight parameters of the discriminator through backpropagation. Then, use the adversarial samples generated by the generator as the input, recalculate the loss function, and update the weight parameters of the generator through backpropagation. Iteratively train like this until the adversarial samples generated by the generator can deceive the multimedia perceptual hashing function.

[0071] The optimization objective of the generator is to minimize the adversarial loss and the similarity loss:

[0072] min G = L_adv + α * L_sim (4)

[0073] where α is the weight coefficient of the similarity loss

[0074] The optimization objective of the discriminator is to maximize the adversarial loss and minimize the penalty term:

[0075] max D = L_adv - γ * L_penalty (5)

[0076] where γ is the weight coefficient of the penalty term.

[0077] (5) Evaluating the attack effect: Evaluate the multimedia perceptual hashing function using the generated adversarial samples. We will examine the success rate of the adversarial samples, the difference in hash values after the attack, and the impact of the attack on the similarity calculation of multimedia data. This will help us evaluate the effectiveness and feasibility of the attack.

[0078] · Success rate metric

[0079] Assume the success rate of the attack is a, and we set the threshold as k. Then, if a > k, it is considered that there is a security risk of the hashing function being attacked.

[0080] · Similarity metric

[0081] Assume the set of all adversarial samples for a successful attack is Z, and the set of their corresponding hashing function values is U. Then we define the similarity function, SIM, as follows:

[0082]

[0083] We set the threshold as sk. Then, if SIM(Z, U) > k, it is considered that there is a similarity security risk of the hashing function being attacked.

[0084] If the success rate and similarity metrics of the algorithm are both greater than the threshold, then the algorithm is considered a high-risk algorithm, and it is not recommended to use this algorithm for applications.

Claims

1. A security evaluation method for perceptual hash functions based on adversarial machine learning, characterized in that: Here are the steps: Step 1: Collect a dataset that can be used to train a generative adversarial network; Step 2: Design the generator, discriminator and loss function of the generative adversarial network; Step 3: Evaluate the security of the perceived hash function through success rate and similarity indicators.

2. The security evaluation method of the perceptual hash function based on adversarial machine learning according to claim 1, characterized in that: The dataset described in step 1 includes datasets of different modalities (such as images, audio, and video); the dataset is downloaded from a public dataset and covers various scenarios and contents.

3. The security evaluation method of the perceptual hash function based on adversarial machine learning according to claim 1, characterized in that: The loss function includes a generator loss function and a discriminator loss function.

4. The security evaluation method of the perceptual hash function based on adversarial machine learning according to claim 3, characterized in that: The generator loss function consists of the following two parts: Adversarial Loss: By minimizing the probability that the generated adversarial sample is judged as forged by the discriminator, the generated adversarial sample is closer to the real data; The adversarial loss can be expressed using a binary classification loss function: L_adv=-log(D(x)-log(1-D(G(z))) (1) Among them, x represents the real data and z represents the input random noise. However, using only adversarial loss may not fully capture the distribution characteristics of real data, resulting in a certain gap between the samples generated by the generator and the real data; Similarity Loss: By minimizing the similarity distance between the generated data and the original data, the generated adversarial sample is made closer to the original data; it can be expressed using the mean squared error loss function: L_sim = ||G(z) - x|| 2 (2) Among them, x represents real data, and G(z) represents the adversarial sample generated by the generator.

5. The security evaluation method of the perceptual hash function based on adversarial machine learning according to claim 3, characterized in that: The discriminator loss function consists of the following two parts: Adversarial loss: By maximizing the probability of judging real data as real and the probability of judging generated adversarial samples as forged, the discriminator can identify the generated adversarial samples; Penalty Term: Prevents gradient explosion and vanishing by limiting the gradient norm of the discriminator output; In order to prevent the occurrence of gradient explosion and vanishing phenomena, a gradient penalty term can be used to constrain the output of the discriminator; the penalty term used is the gradient penalty term in the Wasserstein distance where ε is a random number uniformly sampled from [0, 1], λ is the penalty coefficient, is the gradient of the discriminator D with respect to the input data.

6. The security evaluation method of the perceptual hash function based on adversarial machine learning according to claim 4 or 5, characterized in that: The generator and discriminator are constructed through GAN; the goal of the generator is to generate adversarial samples that are similar to the original data but have different hash values, while the goal of the discriminator is to distinguish the generated adversarial samples from the original data. The specific training process is as follows: Use the defined loss function to train the GAN model; first, use random noise as input to generate adversarial samples through the generator; then, input the generated adversarial samples and real data together to the discriminator for discrimination, and calculate the loss function of the discriminator; then back-propagate to update the weight parameters of the discriminator; then, use the adversarial samples generated by the generator as input, recalculate the loss function and back-propagate to update the weight parameters of the generator; iterate the training until the adversarial samples generated by the generator can deceive the multimedia perception hash function; The optimization goal of the generator is to minimize the adversarial loss and similarity loss: min G = L_adv + α * L_sim (4) Among them, α is the weight coefficient of similarity loss The optimization objective of the discriminator is to maximize the adversarial loss and minimize the penalty term: max D = L_adv - γ * L_penalty (5) where γ is the weight coefficient of the penalty term.

7. The security evaluation method of the perceptual hash function based on adversarial machine learning according to claim 1, wherein: The success rate and similarity metrics in the third step are specifically as follows: (1) Success rate metric: Assume the success rate of the attack is a, and we set the threshold as k. Then, if a > k, it is considered that the hash function has a security risk of being attacked. (2) Similarity metric: Assume the set of all adversarial samples for a successful attack is Z, and the corresponding set of hash function values is U. Then, we define the similarity function, SIM, as follows: Set the threshold as sk. Then, if SIM(Z, U) > k, it is considered that the hash function has a similarity security risk of being attacked. ​