[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125746-en":3,"doc-seo-125746-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125746,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","On the Detection of Image-Scaling Attacks in Machine Learning - Research focus","Image scaling is a core preprocessing step in machine learning and computer vision, yet it is vulnerable to image-scaling attacks that introduce subtle changes so a rescaled image becomes attacker-controlled. These attacks can mislead predictions and strengthen poisoning or backdoor threats, but detection methods have lacked rigorous study. This work systematizes and analyzes detection approaches, identifies two key paradigms, and proposes simple defenses that substantially outperform prior techniques across major platforms and scaling algorithms.","————————————– Accepted at the Annual Computer Security Applications Conference (ACSAC) 2023 ————————————–  \nOn the Detection of Image-Scaling Attacks in Machine Learning  \nErwin Quiring  \nICSI Berkeley, United States Ruhr University Bochum Bochum, Germany  \nAndreas Müller  \nRuhr University Bochum Bochum, Germany  \nKonrad Rieck  \nTU Berlin Berlin, Germany  \narXiv :2310 . 15085v1 [ cs .CR] 23 Oct 2023  \nABSTRACT  \nImage scaling is an integral part of machine learning and computer vision systems. Unfortunately, this preprocessing step is vulnerable to so-called image-scaling attacks where an attacker makes unnoticeable changes to an image so that it becomes a new image after scaling. This opens up new ways for attackers to control the prediction or to improve poisoning and backdoor attacks. While effective techniques exist to prevent scaling attacks, their detection has not been rigorously studied yet. Consequently, it is currently not possible to reliably spot these attacks in practice.  \nThis paper presents the first in-depth systematization and analysis of detection methods for image-scaling attacks. We identify two general detection paradigms and derive novel methods from them that are simple in design yet significantly outperform previous work. We demonstrate the efficacy of these methods in a comprehensive evaluation with all major learning platforms and scaling algorithms. First, we show that image-scaling attacks modifying the entire scaled image can be reliably detected even under an adaptive adversary. Second, we find that our methods provide strong detection performance even if only minor parts of the image are manipulated. As a result, we can introduce a novel protection layer against image-scaling attacks.  \nKEYWORDS  \nMachine Learning, Preprocessing, Adversarial Learning, Defense  \n1 INTRODUCTION  \nImage scaling is a ubiquitous preprocessing step in many machine learning and computer vision systems. Before an image is fed toa learning model for inference, it is usually scaled down to fixed dimensions. For example, the popular neural networks VGG19 [22] and ResNet [8] for object recognition expect fixed inputs of 224×224 pixels. While an extensive body of research has explored vulnerabilities in learning models [1, 14], the attack surface of preprocessing has received little attention so far. An exception is recent work on image-scaling attacks [17, 24], a novel class of attacks that enable an adversary to tamper with the result of the scaling process (see Figure 1) . These attacks exploit that most scaling algorithms process only a minor fraction of the pixels in an image, so that a few perturbations allow for full control of its scaled version [17] .  \nACSAC’23, December 4–8, 2023, Austin, TX, USA 2023.  \nIn contrast to other security threats to machine learning, imagescaling attacks are agnostic to the employed learning models. Successful attacks only require knowledge about the scaling algorithm and the target dimensions. Compared to the parameters of a neural network, these details are limited in the number of possible configurations and can also be inferred through remote queries to the model [24] . As a result, image-scaling attacks pose a notable threat to practical systems: They enable misleading classifiers without access to the learning model and allow hiding backdoor triggers or poisoning attacks in training data [15] . Figure 1 illustrates both cases. In the top row, the adversary misleads the classification by changing the entire image during scaling. In the bottom row, the adversary induces local changes in the lower left corner of the scaled image (black square). If this modification is performed on training data, it allows concealing an otherwise noticeable backdoor trigger. Hence, there is a need for effective safeguards that complement existing security mechanisms for machine learning.  \nTwo defense strategies have been explored for addressing this threat: prevention and detection. In the first cas","cbCaicEBQdv31Hsy","https://ap.wps.com/l/cbCaicEBQdv31Hsy","pdf",16025234,1,15,"English","en",105,"# Introduction\n## Detection paradigms\n## Global vs local change cases\n# Proposed detection approach","[{\"question\":\"What is an image-scaling attack in machine learning?\",\"answer\":\"An image-scaling attack introduces unnoticeable modifications to an image so that after scaling, the resulting scaled image is attacker-controlled. This can occur through changes that affect the whole scaled image or only a local region.\"},{\"question\":\"Why is detection of image-scaling attacks important?\",\"answer\":\"Detection complements prevention because some scenarios require spotting ongoing attacks, performing one-time checks when robust methods are slower, or protecting systems where preprocessing components cannot be modified.\"},{\"question\":\"What are the two general detection paradigms identified in the paper?\",\"answer\":\"The paper identifies frequency analysis and spatial analysis. Frequency analysis searches for conspicuous traces in the frequency spectrum, while spatial analysis leverages adversarial modifications or remaining clean pixels for further evaluation.\"}]","On the Detection of Image-Scaling Attacks in Machine Learning - Research focus | PDF",1785900995,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"on-the-detection-of-image-scaling-attacks-in-machine-learning-research-focus","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/on-the-detection-of-image-scaling-attacks-in-machine-learning-research-focus/125746/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is an image-scaling attack in machine learning?","Question",{"text":75,"@type":76},"An image-scaling attack introduces unnoticeable modifications to an image so that after scaling, the resulting scaled image is attacker-controlled. This can occur through changes that affect the whole scaled image or only a local region.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why is detection of image-scaling attacks important?",{"text":80,"@type":76},"Detection complements prevention because some scenarios require spotting ongoing attacks, performing one-time checks when robust methods are slower, or protecting systems where preprocessing components cannot be modified.",{"name":82,"@type":73,"acceptedAnswer":83},"What are the two general detection paradigms identified in the paper?",{"text":84,"@type":76},"The paper identifies frequency analysis and spatial analysis. Frequency analysis searches for conspicuous traces in the frequency spectrum, while spatial analysis leverages adversarial modifications or remaining clean pixels for further evaluation.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]