Perceptual Attacks of No-Reference Image Quality Models with Human-in-the-Loop
Weixia Zhang, Dingquan Li, Xiongkuo Min, Guangtao Zhai, Guodong Guo, Xiaokang Yang, Kede Ma
Abstract
No-reference image quality assessment (NR-IQA) aims to quantify how humans perceive visual distortions of digital images without access to their undistorted references. NR-IQA models are extensively studied in computational vision, and are widely used for performance evaluation and perceptual optimization of man-made vision systems. Here we make one of the first attempts to examine the perceptual robustness of NR-IQA models. Under a Lagrangian formulation, we identify insightful connections of the proposed perceptual attack to previous beautiful ideas in computer vision and machine learning. We test one knowledge-driven and three data-driven NR-IQA methods under four full-reference IQA models (as approximations to human perception of just-noticeable differences). Through carefully designed psychophysical experiments, we find that all four NR-IQA models are vulnerable to the proposed perceptual attack. More interestingly, we observe that the generated counterexamples are not transferable, manifesting themselves as distinct design flows of respective NR-IQA methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f482a147-363c-4c64-9ffb-cb410060f54aCited by top-tier papers8
- Vulnerabilities in Video Quality Assessment Models: The Challenge of Adversarial AttacksAoxiang Zhang, Yu Ran, Weixuan Tang, Yuan-Gen WangNeurIPS 2023 · 19 citations
- Defense Against Adversarial Attacks on No-Reference Image Quality Models with Gradient Norm RegularizationYujia Liu, Chenxi Yang, Dingquan Li, Jianhao Ding et al.CVPR 2024 · 15 citations
- IOI: Invisible One-Iteration Adversarial Attack on No-Reference Image- and Video-Quality MetricsEkaterina Shumitskaya, Anastasia Antsiferova, Dmitriy S. VatolinICML 2024 · 6 citations
- BiRQA: Bidirectional Robust Quality Assessment for ImagesAleksandr Gushchin, Dmitriy Vatolin, Anastasia AntsiferovaICML 2026 · 1 citation
- Test-Time Preference Optimization for Image RestorationBingchen Li, Xin Li, Jiaqi Xu, Jiaming Guo et al.AAAI 2026 · 1 citation
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
- Troubleshooting Blind Image Quality Models in the WildZhihua Wang, Haotao Wang, Tianlong Chen, Zhangyang Wang et al.CVPR 2021
- Understanding the Robustness of Skeleton-Based Action Recognition Under Adversarial AttackHe Wang, Feixiang He, Zhexi Peng, Tianjia Shao et al.CVPR 2021
- From Patches to Pictures (PaQ-2-PiQ): Mapping the Perceptual Space of Picture QualityZhenqiang Ying, Haoran Niu, Praful Gupta, Dhruv Mahajan et al.CVPR 2020
Related papers
- Augmenting Perceptual Super-Resolution via Image Quality PredictorsFengjia Zhang, Samrudhdhi B. Rangrej, Tristan Aumentado-Armstrong, Afsaneh Fazly et al.CVPR 2025
- Backdoor Attacks Against No-Reference Image Quality Assessment Models via a Scalable TriggerYi Yu, Song Xia, Xun Lin, Wenhan Yang et al.AAAI 2025 · 15 citations
- No-Reference Image Quality Assessment Using Dynamic Complex-Valued Neural ModelZihan Zhou, Yong Xu, Ruotao Xu, Yuhui QuanACM MM 2022 · 7 citations
- Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality MetricsAleksandr Gushchin, Khaled Abud, Georgii Bychkov, Ekaterina Shumitskaya et al.ICML 2025
- Re-IQA: Unsupervised Learning for Image Quality Assessment in the WildAvinab Saha, Sandeep Mishra, Alan C. BovikCVPR 2023
