Defense Against Adversarial Attacks on No-Reference Image Quality Models with Gradient Norm Regularization
Yujia Liu, Chenxi Yang, Dingquan Li, Jianhao Ding, Tingting Jiang
摘要
The task of No-Reference Image Quality Assessment (NR-IQA) is to estimate the quality score of an input image without additional information. NR-IQA models play a crucial role in the media industry, aiding in performance evaluation and optimization guidance. However, these models are found to be vulnerable to adversarial attacks, which introduce imperceptible perturbations to input images, re-sulting in significant changes in predicted scores. In this paper, we propose a defense method to improve the stability in predicted scores when attacked by small perturbations, thus enhancing the adversarial robustness of NR-IQA models. To be specific, we present theoretical evidence showing that the magnitude of score changes is related to the g 1 norm of the model's gradient with respect to the input image. Building upon this theoretical foundation, we propose a norm regularization training strategy aimed at reducing the g 1 norm of the gradient, thereby boosting the robustness of NR-IQA models. Experiments conducted on four NR-IQA baseline models demonstrate the effectiveness of our strategy in reducing score changes in the presence of adversarial attacks. To the best of our knowledge, this work marks the first attempt to defend against adversarial attacks on NR-IQA models. Our study offers valuable insights into the adversarial robustness of NR-IQA models and provides a foundation for future research in this area.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- BiRQA: Bidirectional Robust Quality Assessment for ImagesAleksandr Gushchin, Dmitriy Vatolin, Anastasia AntsiferovaICML 2026 · 被引用 1 次
- Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality MetricsAleksandr Gushchin, Khaled Abud, Georgii Bychkov, Ekaterina Shumitskaya 等ICML 2025
- Augmenting Perceptual Super-Resolution via Image Quality PredictorsFengjia Zhang, Samrudhdhi B. Rangrej, Tristan Aumentado-Armstrong, Afsaneh Fazly 等CVPR 2025
它引用的顶会 Paper12
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- MUSIQ: Multi-scale Image Quality TransformerJunjie Ke, Qifei Wang, Yilin Wang, Peyman Milanfar 等ICCV 2021 · 被引用 1,325 次
- FreeLB: Enhanced Adversarial Training for Natural Language UnderstandingChen Zhu, Yu Cheng, Zhe Gan, Siqi Sun 等ICLR 2020 · 被引用 502 次
- RankSRGAN: Generative Adversarial Networks With Ranker for Image Super-ResolutionWenlong Zhang, Yihao Liu, Chao Dong, Yu QiaoICCV 2019 · 被引用 406 次
- Learned Video CompressionOren Rippel, Sanjay Nair, Carissa Lew, Steve Branson 等ICCV 2019 · 被引用 258 次
相关 Paper
- Perceptual Attacks of No-Reference Image Quality Models with Human-in-the-LoopWeixia Zhang, Dingquan Li, Xiongkuo Min, Guangtao Zhai 等NeurIPS 2022 · 被引用 55 次
- Backdoor Attacks Against No-Reference Image Quality Assessment Models via a Scalable TriggerYi Yu, Song Xia, Xun Lin, Wenhan Yang 等AAAI 2025 · 被引用 15 次
- Comparing the Robustness of Modern No-Reference Image- and Video-Quality Metrics to Adversarial AttacksAnastasia Antsiferova, Khaled Abud, Aleksandr Gushchin, Ekaterina Shumitskaya 等AAAI 2024 · 被引用 21 次
- Vulnerabilities in Video Quality Assessment Models: The Challenge of Adversarial AttacksAoxiang Zhang, Yu Ran, Weixuan Tang, Yuan-Gen WangNeurIPS 2023 · 被引用 19 次
- Adaptive Feature Selection for No-Reference Image Quality Assessment by Mitigating Semantic Noise SensitivityXudong Li, Timin Gao, Runze Hu, Yan Zhang 等ICML 2024 · 被引用 12 次
