|
|
|
|
|
by orivej
1767 days ago
|
|
The attack relies on the fact that when downscaling by a large factor, the tested downscalers (except Pillow in non-nearest neighmode mode, and all of them in area averaging mode) ignore most of the pixels of the original image and compute the result based on the select few which are the same in all modes, making the result look nearly the same regardless of the mode. |
|
[0] https://www.sec.cs.tu-bs.de/pubs/2020-sec.pdf