SIA-GAN: Scrambling Inversion Attack Using Generative Adversarial Network

Koki Madono*, Masayuki Tanaka, Masaki Onishi, Tetsuji Ogawa


研究成果: Article査読

14 被引用数 (Scopus)


This paper presents a scrambling inversion attack using a generative adversarial network (SIA-GAN). This method aims to evaluate the privacy protection level achieved by image scrambling method. For privacy-preserving machine learning, scrambled images are often used to protect visual information, assuming that searching the scramble parameters is highly difficult for an attacker due to the application of complex image scrambling operations. However, the security of such methods has not been thoroughly investigated. SIA-GAN learns the mapping between pairs of scrambled images and original images, then attempts to invert image scrambling. Therefore, the attacker is assumed to have real images whose domain is the same as that of scrambled images. Experimental results demonstrate that scrambled images cannot be recovered if block shuffling is applied as a scrambling operation. The experimental code of SIA-GAN is available at

ジャーナルIEEE Access
出版ステータスPublished - 2021

ASJC Scopus subject areas

  • コンピュータサイエンス一般
  • 材料科学一般
  • 工学一般


「SIA-GAN: Scrambling Inversion Attack Using Generative Adversarial Network」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。