Adversarial Screen Protection Against AI Image Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting data displayed on electronic screens from automated image or video analysis, especially with the rise of AI and IoT devices, are inadequate against espionage and industrial espionage, as they fail to effectively defend against artificial intelligence-driven attacks on visual data.

Innovation Solution

The implementation of adversarial noise or patches on computer-controlled screens/devices, which are designed to deceive machine learning models used in automated media analysis, by adding noise or patches to the displayed data, thereby preventing accurate parsing and analysis by image classifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional screen protection methods are used, then basic privacy protection is provided, but they fail against AI-driven automated media analysis

Engineering Contradiction:
Improveprivacy protection effectivenessVSAvoiddefense against AI attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary anti-action by proactively adding adversarial noise and patches to displayed content before AI-driven media analysis can occur. This preemptive modification of visual data confuses automated image classifiers and video analysis systems, preventing them from accurately extracting information. The defense is established in advance to counter future AI attacks before they can succeed.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the harmful capability of AI media analysis into a beneficial defense mechanism. By using adversarial examples that exploit vulnerabilities in AI models, the system creates a protective shield. The same AI technology that could be used to attack the screen is instead harnessed to generate protective adversarial noise and patches, turning the attack vector into a defensive tool.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If adversarial noise and patches are added to displayed content, then protection against automated analysis is improved, but the quality and usability of displayed content deteriorates

Engineering Contradiction:
Improvesecurity against automated analysisVSAvoidusability of displayed content
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by strategically placing adversarial patches and noise only in specific regions of the displayed content rather than uniformly across the entire screen. The adversarial modifications are concentrated in areas that are less visually salient or less critical for the user experience, while preserving the overall quality and usability of the displayed information. This localized approach minimizes the impact on content quality while maintaining security effectiveness.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by carefully adjusting the intensity, frequency, and distribution of adversarial noise and patches to maintain an optimal balance between security and usability. The adversarial modifications are applied at minimal effective levels that confuse AI models while remaining imperceptible or acceptable to human users. Parameters such as noise magnitude, patch size, and density are optimized to achieve this balance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11288408B2Providing adversarial protection for electronic screen displays
Publication Date: 2022.03.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11288408B2 patent drawing
  • US11288408B2 patent drawing
  • US11288408B2 patent drawing

AI summary

Embodiments for providing adversarial protection to computing display devices by a processor. Security defenses may be provided on one or more image display devices against automated media analysis by using adversarial noise, an adversarial patch, or a combination thereof.