CycleGAN, a Master of Steganography
arXiv:1712.02950
Abstract
CycleGAN (Zhu et al. 2017) is one recent successful approach to learn a transformation between two image distributions. In a series of experiments, we demonstrate an intriguing property of the model: CycleGAN learns to "hide" information about a source image into the images it generates in a nearly imperceptible, high-frequency signal. This trick ensures that the generator can recover the original sample and thus satisfy the cyclic consistency requirement, while the generated image remains realistic. We connect this phenomenon with adversarial attacks by viewing CycleGAN's training procedure as training a generator of adversarial examples and demonstrate that the cyclic consistency loss causes CycleGAN to be especially vulnerable to adversarial attacks.
NIPS 2017, workshop on Machine Deception
References in corpus (3)
Cited by in corpus (12)
- A Review on Generative Adversarial Networks: Algorithms, Theory, and Applications
- NTIRE 2020 Challenge on Real-World Image Super-Resolution: Methods and Results
- RL-CycleGAN: Reinforcement Learning Aware Simulation-To-Real
- Latent Translation: Crossing Modalities by Bridging Generative Models
- EncryptGAN: Image Steganography with Domain Transform
- Recent Advances of Image Steganography with Generative Adversarial Networks
- Unsupervised Adversarial Image Inpainting
- Steganography GAN: Cracking Steganography with Cycle Generative Adversarial Networks
- Irregular Convolutional Auto-Encoder on Point Clouds
- MCMI: Multi-Cycle Image Translation with Mutual Information Constraints
- Generating Object Stamps
- Generating and Aligning from Data Geometries with Generative Adversarial Networks