{"id":"https://openalex.org/W4389584550","doi":"https://doi.org/10.1109/tai.2023.3340982","title":"Manipulation Attacks on Learned Image Compression","display_name":"Manipulation Attacks on Learned Image Compression","publication_year":2023,"publication_date":"2023-12-11","ids":{"openalex":"https://openalex.org/W4389584550","doi":"https://doi.org/10.1109/tai.2023.3340982"},"language":"en","primary_location":{"id":"doi:10.1109/tai.2023.3340982","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tai.2023.3340982","pdf_url":null,"source":{"id":"https://openalex.org/S4210169448","display_name":"IEEE Transactions on Artificial Intelligence","issn_l":"2691-4581","issn":["2691-4581"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100389879","display_name":"Kang Liu","orcid":"https://orcid.org/0000-0001-7231-8315"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Kang Liu","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102018774","display_name":"Di Wu","orcid":"https://orcid.org/0009-0008-5912-6683"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Di Wu","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102896677","display_name":"Yangyu Wu","orcid":"https://orcid.org/0009-0006-0859-7464"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yangyu Wu","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100319146","display_name":"Yiru Wang","orcid":"https://orcid.org/0009-0008-5385-7813"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Yiru Wang","raw_affiliation_strings":["University of Waterloo, Waterloo, ON, Canada"],"affiliations":[{"raw_affiliation_string":"University of Waterloo, Waterloo, ON, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5057421680","display_name":"Dan Feng","orcid":"https://orcid.org/0000-0002-4674-6006"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dan Feng","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069388936","display_name":"Benjamin Tan","orcid":"https://orcid.org/0000-0002-7642-3638"},"institutions":[{"id":"https://openalex.org/I168635309","display_name":"University of Calgary","ror":"https://ror.org/03yjb2x39","country_code":"CA","type":"education","lineage":["https://openalex.org/I168635309"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Benjamin Tan","raw_affiliation_strings":["University of Calgary, Calgary, AB, Canada","University of Calgary, Calgary, Alberta, Canada"],"affiliations":[{"raw_affiliation_string":"University of Calgary, Calgary, AB, Canada","institution_ids":["https://openalex.org/I168635309"]},{"raw_affiliation_string":"University of Calgary, Calgary, Alberta, Canada","institution_ids":["https://openalex.org/I168635309"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5010950688","display_name":"Siddharth Garg","orcid":"https://orcid.org/0000-0002-6158-9512"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Siddharth Garg","raw_affiliation_strings":["New York University, Brooklyn, NY, USA"],"affiliations":[{"raw_affiliation_string":"New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5100389879"],"corresponding_institution_ids":["https://openalex.org/I47720641"],"apc_list":null,"apc_paid":null,"fwci":1.5991,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.87086678,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"5","issue":"6","first_page":"3083","last_page":"3097"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9498000144958496,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.945900022983551,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7658720016479492},{"id":"https://openalex.org/keywords/image-compression","display_name":"Image compression","score":0.6198976039886475},{"id":"https://openalex.org/keywords/lossy-compression","display_name":"Lossy compression","score":0.5737689137458801},{"id":"https://openalex.org/keywords/lossless-compression","display_name":"Lossless compression","score":0.5659159421920776},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5181454420089722},{"id":"https://openalex.org/keywords/jpeg","display_name":"JPEG","score":0.5065828561782837},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.48549917340278625},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.4736786186695099},{"id":"https://openalex.org/keywords/image-quality","display_name":"Image quality","score":0.46683943271636963},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.3880820572376251},{"id":"https://openalex.org/keywords/data-compression","display_name":"Data compression","score":0.3868573307991028},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.34937015175819397},{"id":"https://openalex.org/keywords/image-processing","display_name":"Image processing","score":0.2774102985858917},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.17679426074028015}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7658720016479492},{"id":"https://openalex.org/C13481523","wikidata":"https://www.wikidata.org/wiki/Q412438","display_name":"Image compression","level":4,"score":0.6198976039886475},{"id":"https://openalex.org/C165021410","wikidata":"https://www.wikidata.org/wiki/Q55564","display_name":"Lossy compression","level":2,"score":0.5737689137458801},{"id":"https://openalex.org/C81081738","wikidata":"https://www.wikidata.org/wiki/Q55542","display_name":"Lossless compression","level":3,"score":0.5659159421920776},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5181454420089722},{"id":"https://openalex.org/C198751489","wikidata":"https://www.wikidata.org/wiki/Q2195","display_name":"JPEG","level":3,"score":0.5065828561782837},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.48549917340278625},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.4736786186695099},{"id":"https://openalex.org/C55020928","wikidata":"https://www.wikidata.org/wiki/Q3813865","display_name":"Image quality","level":3,"score":0.46683943271636963},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3880820572376251},{"id":"https://openalex.org/C78548338","wikidata":"https://www.wikidata.org/wiki/Q2493","display_name":"Data compression","level":2,"score":0.3868573307991028},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.34937015175819397},{"id":"https://openalex.org/C9417928","wikidata":"https://www.wikidata.org/wiki/Q1070689","display_name":"Image processing","level":3,"score":0.2774102985858917},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.17679426074028015},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tai.2023.3340982","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tai.2023.3340982","pdf_url":null,"source":{"id":"https://openalex.org/S4210169448","display_name":"IEEE Transactions on Artificial Intelligence","issn_l":"2691-4581","issn":["2691-4581"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1162797831","display_name":null,"funder_award_id":"62202190","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G260740727","display_name":null,"funder_award_id":"2023AFB237","funder_id":"https://openalex.org/F4320336744","funder_display_name":"Science and Technology Program of Hubei Province"},{"id":"https://openalex.org/G3477952923","display_name":null,"funder_award_id":"77191","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"},{"id":"https://openalex.org/G5601515516","display_name":null,"funder_award_id":"U22B2017","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320336744","display_name":"Science and Technology Program of Hubei Province","ror":null},{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":61,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W2030265202","https://openalex.org/W2146395539","https://openalex.org/W2162552722","https://openalex.org/W2166816543","https://openalex.org/W2408141691","https://openalex.org/W2535690855","https://openalex.org/W2552465432","https://openalex.org/W2597747080","https://openalex.org/W2620038827","https://openalex.org/W2785562966","https://openalex.org/W2892090366","https://openalex.org/W2893920456","https://openalex.org/W2938908220","https://openalex.org/W2942091739","https://openalex.org/W2962676454","https://openalex.org/W2962891349","https://openalex.org/W2962933288","https://openalex.org/W2963149687","https://openalex.org/W2963542245","https://openalex.org/W2963771536","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2964098744","https://openalex.org/W2966658324","https://openalex.org/W2981613960","https://openalex.org/W2982853315","https://openalex.org/W2997572967","https://openalex.org/W3034214559","https://openalex.org/W3034339621","https://openalex.org/W3034469748","https://openalex.org/W3034885317","https://openalex.org/W3088142143","https://openalex.org/W3097448661","https://openalex.org/W3175457126","https://openalex.org/W3213748123","https://openalex.org/W4223425316","https://openalex.org/W4247200422","https://openalex.org/W4287605633","https://openalex.org/W4288079630","https://openalex.org/W4293846201","https://openalex.org/W4310988119","https://openalex.org/W4311005685","https://openalex.org/W4312597589","https://openalex.org/W4367313930","https://openalex.org/W4376607895","https://openalex.org/W4386065641","https://openalex.org/W4386075611","https://openalex.org/W4386083143","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6684011098","https://openalex.org/W6694251005","https://openalex.org/W6714069269","https://openalex.org/W6745272055","https://openalex.org/W6754634825","https://openalex.org/W6755487101","https://openalex.org/W6758681311","https://openalex.org/W6761436890","https://openalex.org/W6780365925"],"related_works":["https://openalex.org/W3210332869","https://openalex.org/W2385628723","https://openalex.org/W2547124190","https://openalex.org/W2013943429","https://openalex.org/W4327499886","https://openalex.org/W3180760233","https://openalex.org/W2096442341","https://openalex.org/W2751842002","https://openalex.org/W4210455546","https://openalex.org/W3080614128"],"abstract_inverted_index":{"Deep":[0],"learning":[1],"(DL)":[2],"techniques":[3],"have":[4],"shown":[5],"promising":[6,237],"results":[7,169],"in":[8,75,160,183],"image":[9,19,28,62,109,118,172,251],"compression":[10,29,63,150,173,211,220],"compared":[11],"to":[12,47,98,197,244],"conventional":[13],"methods,":[14],"with":[15,151,176],"competitive":[16],"bitrate":[17,78,143,179],"and":[18,39,96,123,154,199,228,242,247],"reconstruction":[20,81],"quality":[21],"from":[22],"compressed":[23,77],"latent.":[24],"However,":[25],"whereas":[26],"learned":[27,117,250],"has":[30,50],"progressed":[31],"towards":[32],"a":[33,72,105,130,218,229,236],"higher":[34],"peak":[35],"signal-to-noise":[36],"ratio":[37],"(PSNR)":[38],"fewer":[40],"bits":[41],"per":[42],"pixel":[43],"(bpp),":[44],"its":[45,142],"robustness":[46,60,114,243],"adversarial":[48,166,245],"images":[49],"never":[51],"received":[52],"deliberation.":[53],"In":[54],"this":[55],"work,":[56],"we":[57,120,216],"investigate":[58],"the":[59,76,88,113,135,139,158,161,192,206],"of":[61,93,115,138,209],"systems":[64,95],"where":[65,191],"imperceptibly":[66],"manipulated":[67],"inputs":[68],"can":[69,85],"stealthily":[70],"precipitate":[71],"significant":[73],"increase":[74],"without":[79],"compromising":[80],"quality.":[82],"Such":[83],"attacks":[84,246],"potentially":[86],"exhaust":[87],"storage":[89],"or":[90],"network":[91],"bandwidth":[92],"computing":[94],"lead":[97],"service":[99],"denial.":[100],"We":[101,145],"term":[102],"it":[103],"as":[104,141,157],"DoS":[106],"attack":[107,128,194],"on":[108,134,170],"compressors.":[110,252],"To":[111,213],"characterize":[112],"state-of-the-art":[116],"compression,":[119],"mount":[121],"white-box":[122,127,193],"black-box":[124,162,200],"attacks.":[125],"Our":[126,168],"employs":[129],"gradient":[131],"ascent":[132],"approach":[133],"entropy":[136,232],"estimation":[137],"bitstream":[140],"approximation.":[144],"propose":[146,217],"DCT-Net":[147],"simulating":[148],"JPEG":[149],"architectural":[152],"simplicity":[153],"lightweight":[155],"training":[156],"substitute":[159],"attack,":[163],"enabling":[164],"fast":[165],"transferability.":[167],"six":[171,177],"architectures,":[174],"each":[175],"different":[178],"qualities":[180],"(thirty-six":[181],"models":[182],"total),":[184],"show":[185],"that":[186,234],"they":[187],"are":[188],"surprisingly":[189],"fragile,":[190],"achieves":[195],"up":[196],"55\u00d7":[198],"2\u00d7":[201],"bpp":[202],"increase,":[203],"respectively,":[204],"revealing":[205],"devastating":[207],"fragility":[208],"DL-based":[210],"models.":[212],"improve":[214],"robustness,":[215],"novel":[219],"architecture":[221],"<monospace":[222],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[223],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">factorAtn</monospace>":[224],"incorporating":[225],"attention":[226],"modules":[227],"basic":[230],"factorized":[231],"model":[233],"presents":[235],"trade-off":[238],"between":[239],"rate-distortion":[240],"performance":[241],"surpasses":[248],"existing":[249]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":1}],"updated_date":"2026-03-09T08:58:05.943551","created_date":"2025-10-10T00:00:00"}
