Defense Against Adversarial Attacks on No-Reference Image Quality Models with Gradient Norm Regularization
Yujia Liu, Chenxi Yang, Dingquan Li, Jianhao Ding, Tingting Jiang
Abstract
The task of No-Reference Image Quality Assessment (NR-IQA) is to estimate the quality score of an input image without additional information. NR-IQA models play a crucial role in the media industry, aiding in performance evaluation and optimization guidance. However, these models are found to be vulnerable to adversarial attacks, which introduce imperceptible perturbations to input images, re-sulting in significant changes in predicted scores. In this paper, we propose a defense method to improve the stability in predicted scores when attacked by small perturbations, thus enhancing the adversarial robustness of NR-IQA models. To be specific, we present theoretical evidence showing that the magnitude of score changes is related to the g 1 norm of the model's gradient with respect to the input image. Building upon this theoretical foundation, we propose a norm regularization training strategy aimed at reducing the g 1 norm of the gradient, thereby boosting the robustness of NR-IQA models. Experiments conducted on four NR-IQA baseline models demonstrate the effectiveness of our strategy in reducing score changes in the presence of adversarial attacks. To the best of our knowledge, this work marks the first attempt to defend against adversarial attacks on NR-IQA models. Our study offers valuable insights into the adversarial robustness of NR-IQA models and provides a foundation for future research in this area.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- BiRQA: Bidirectional Robust Quality Assessment for ImagesAleksandr Gushchin, Dmitriy Vatolin, Anastasia AntsiferovaICML 2026 · 1 citation
- Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality MetricsAleksandr Gushchin, Khaled Abud, Georgii Bychkov, Ekaterina Shumitskaya et al.ICML 2025
- Augmenting Perceptual Super-Resolution via Image Quality PredictorsFengjia Zhang, Samrudhdhi B. Rangrej, Tristan Aumentado-Armstrong, Afsaneh Fazly et al.CVPR 2025
Builds on12
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- MUSIQ: Multi-scale Image Quality TransformerJunjie Ke, Qifei Wang, Yilin Wang, Peyman Milanfar et al.ICCV 2021 · 1,325 citations
- FreeLB: Enhanced Adversarial Training for Natural Language UnderstandingChen Zhu, Yu Cheng, Zhe Gan, Siqi Sun et al.ICLR 2020 · 502 citations
- RankSRGAN: Generative Adversarial Networks With Ranker for Image Super-ResolutionWenlong Zhang, Yihao Liu, Chao Dong, Yu QiaoICCV 2019 · 406 citations
- Learned Video CompressionOren Rippel, Sanjay Nair, Carissa Lew, Steve Branson et al.ICCV 2019 · 258 citations
Related papers
- Perceptual Attacks of No-Reference Image Quality Models with Human-in-the-LoopWeixia Zhang, Dingquan Li, Xiongkuo Min, Guangtao Zhai et al.NeurIPS 2022 · 55 citations
- Backdoor Attacks Against No-Reference Image Quality Assessment Models via a Scalable TriggerYi Yu, Song Xia, Xun Lin, Wenhan Yang et al.AAAI 2025 · 15 citations
- Comparing the Robustness of Modern No-Reference Image- and Video-Quality Metrics to Adversarial AttacksAnastasia Antsiferova, Khaled Abud, Aleksandr Gushchin, Ekaterina Shumitskaya et al.AAAI 2024 · 21 citations
- Vulnerabilities in Video Quality Assessment Models: The Challenge of Adversarial AttacksAoxiang Zhang, Yu Ran, Weixuan Tang, Yuan-Gen WangNeurIPS 2023 · 19 citations
- Adaptive Feature Selection for No-Reference Image Quality Assessment by Mitigating Semantic Noise SensitivityXudong Li, Timin Gao, Runze Hu, Yan Zhang et al.ICML 2024 · 12 citations
