Adversarial Example Quality Assessment: A Large-scale Dataset and Strong Baseline
Jia-Li Yin, Menghao Chen, Jin Han, Bo-Hao Chen, Ximeng Liu
Abstract
Adversarial examples (AEs), which are maliciously hand-crafted by adding perturbations to benign images, reveal the vulnerability of deep neural networks (DNNs) and have been used as a benchmark for evaluating model robustness. With great efforts have been devoted to generating AEs with stronger attack ability, the visual quality of AEs is generally neglected in previous studies. The lack of a good quality measure of AEs makes it very hard to compare the relative merits of attack techniques and is hindering technological advancement. How to evaluate the visual quality of AEs remains an understudied and unsolved problem. In this work, we make the first attempt to fill the gap by presenting an image quality assessment method specifically designed for AEs. Towards this goal, we first construct a new database, called AdvDB, developed on diverse adversarial examples with elaborated annotations. We also propose a detection-based structural similarity index (AdvDSS) for adversarial example perceptual quality assessment. Specifically, the visual saliency for capturing the near-threshold adversarial distortions is first detected via human visual system (HVS) techniques and then the structural similarity is extracted to predict the quality score. Moreover, we further propose AEQA for overall adversarial example quality assessment by integrating the perceptual quality and attack intensity of AEs. Extensive experiments validate that the proposed AdvDSS achieves state-of-the-art performance which is more consistent with human opinions.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Discriminator-free Generative Adversarial AttackShaohao Lu, Yuqiao Xian, Ke Yan, Yi Hu et al.ACM MM 2021 · 21 citations
- Detecting Adversarial Examples from Sensitivity Inconsistency of Spatial-Transform DomainJinyu Tian, Jiantao Zhou, Yuanman Li, Jia DuanAAAI 2021 · 72 citations
- Stealthy-AE: Generating Stealthy Adversarial Examples through Online Social NetworksZiming Zhao, Zhaoxuan Li, Tingting Li, Fan ZhangACM MM 2025 · 1 citation
- What You See is Not What the Network Infers: Detecting Adversarial Examples Based on Semantic ContradictionYijun Yang, Ruiyuan Gao, Yu Li, Qiuxia Lai et al.NDSS 2022
- Be Your Own Neighborhood: Detecting Adversarial Examples by the Neighborhood Relations Built on Self-Supervised LearningZhiyuan He, Yijun Yang, Pin-Yu Chen, Qiang Xu et al.ICML 2024 · 11 citations
