Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality Metrics

Read original: arXiv:2408.01541 - Published 8/6/2024 by Alexander Gushchin, Khaled Abud, Georgii Bychkov, Ekaterina Shumitskaya, Anna Chistyakova, Sergey Lavrushkin, Bader Rasheed, Kirill Malyshev, Dmitriy Vatolin, Anastasia Antsiferova
Total Score

0

Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality Metrics

Sign in to get full access

or

If you already have an account, we'll log you in

Overview

  • This paper presents a comprehensive benchmark for evaluating the robustness of image quality metrics against adversarial attacks.
  • The researchers test the performance of various image quality assessment models under different attack scenarios, including invisible one-iteration and score-based adversarial attacks.
  • The goal is to identify effective defenses that can protect image quality metrics from being manipulated by malicious actors.

Plain English Explanation

The paper focuses on a critical problem in the field of image processing: the vulnerability of image quality assessment models to adversarial attacks. These attacks involve making small, imperceptible changes to an image that can trick the quality assessment model into giving a different, often inaccurate, score.

The researchers wanted to understand how well different image quality models can withstand these adversarial attacks. To do this, they tested the models under various attack scenarios, including attacks that are designed to be invisible to the human eye and attacks that target the model's score directly.

By benchmarking the performance of these models, the researchers aim to identify effective defenses that can protect image quality assessment systems from being manipulated. This is important because these systems are commonly used in a variety of applications, from image compression to medical imaging, and their reliability is crucial.

Technical Explanation

The paper evaluates the robustness of several no-reference image quality assessment models against different types of adversarial attacks. The researchers first introduce a taxonomy of attack scenarios, including invisible one-iteration attacks and score-based attacks.

They then apply these attacks to a diverse set of image quality models, including BRISQUE, NIQE, and PIQE, and evaluate their robustness using a range of metrics.

The results show that while some models are more vulnerable than others, no existing model is completely immune to adversarial attacks. The researchers also introduce a novel defense mechanism called "adversarial purification," which can significantly improve the models' resilience to these attacks.

Critical Analysis

The paper provides a valuable contribution to the field of image quality assessment by systematically evaluating the robustness of existing models against adversarial attacks. The researchers' taxonomy of attack scenarios and the benchmarking framework they developed are both useful tools for further research in this area.

However, the paper also acknowledges several limitations of the study. For example, the researchers only tested the models on a limited set of attack scenarios and did not explore the transferability of the attacks across different models. Additionally, the effectiveness of the proposed "adversarial purification" defense mechanism has not been thoroughly validated on a wide range of real-world use cases.

Further research is needed to address these limitations and develop more comprehensive defenses against adversarial attacks on image quality assessment systems. It is also important to consider the broader implications of these vulnerabilities, as image quality metrics are used in a variety of critical applications where reliability is of utmost importance.

Conclusion

This paper highlights the pressing need to address the vulnerability of image quality assessment models to adversarial attacks. By systematically benchmarking the performance of various models under different attack scenarios, the researchers have laid the groundwork for developing more robust and reliable image quality assessment systems.

The findings of this study have important implications for a wide range of applications, from image compression to medical imaging, where the integrity of image quality assessments is crucial. As the use of these technologies continues to grow, it is essential that researchers and practitioners work together to identify and mitigate the risks posed by adversarial attacks.



This summary was produced with help from an AI and may contain inaccuracies - check out the links to read the original source documents!

Follow @aimodelsfyi on 𝕏 →

Related Papers

Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality Metrics
Total Score

0

Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality Metrics

Alexander Gushchin, Khaled Abud, Georgii Bychkov, Ekaterina Shumitskaya, Anna Chistyakova, Sergey Lavrushkin, Bader Rasheed, Kirill Malyshev, Dmitriy Vatolin, Anastasia Antsiferova

In the field of Image Quality Assessment (IQA), the adversarial robustness of the metrics poses a critical concern. This paper presents a comprehensive benchmarking study of various defense mechanisms in response to the rise in adversarial attacks on IQA. We systematically evaluate 25 defense strategies, including adversarial purification, adversarial training, and certified robustness methods. We applied 14 adversarial attack algorithms of various types in both non-adaptive and adaptive settings and tested these defenses against them. We analyze the differences between defenses and their applicability to IQA tasks, considering that they should preserve IQA scores and image quality. The proposed benchmark aims to guide future developments and accepts submissions of new methods, with the latest results available online: https://videoprocessing.ai/benchmarks/iqa-defenses.html.

Read more

8/6/2024

Adversarial purification for no-reference image-quality metrics: applicability study and new methods
Total Score

0

Adversarial purification for no-reference image-quality metrics: applicability study and new methods

Aleksandr Gushchin, Anna Chistyakova, Vladislav Minashkin, Anastasia Antsiferova, Dmitriy Vatolin

Recently, the area of adversarial attacks on image quality metrics has begun to be explored, whereas the area of defences remains under-researched. In this study, we aim to cover that case and check the transferability of adversarial purification defences from image classifiers to IQA methods. In this paper, we apply several widespread attacks on IQA models and examine the success of the defences against them. The purification methodologies covered different preprocessing techniques, including geometrical transformations, compression, denoising, and modern neural network-based methods. Also, we address the challenge of assessing the efficacy of a defensive methodology by proposing ways to estimate output visual quality and the success of neutralizing attacks. Defences were tested against attack on three IQA metrics -- Linearity, MetaIQA and SPAQ. The code for attacks and defences is available at: (link is hidden for a blind review).

Read more

4/11/2024

IOI: Invisible One-Iteration Adversarial Attack on No-Reference Image- and Video-Quality Metrics
Total Score

0

IOI: Invisible One-Iteration Adversarial Attack on No-Reference Image- and Video-Quality Metrics

Ekaterina Shumitskaya, Anastasia Antsiferova, Dmitriy Vatolin

No-reference image- and video-quality metrics are widely used in video processing benchmarks. The robustness of learning-based metrics under video attacks has not been widely studied. In addition to having success, attacks that can be employed in video processing benchmarks must be fast and imperceptible. This paper introduces an Invisible One-Iteration (IOI) adversarial attack on no reference image and video quality metrics. We compared our method alongside eight prior approaches using image and video datasets via objective and subjective tests. Our method exhibited superior visual quality across various attacked metric architectures while maintaining comparable attack success and speed. We made the code available on GitHub: https://github.com/katiashh/ioi-attack.

Read more

5/31/2024

Beyond Score Changes: Adversarial Attack on No-Reference Image Quality Assessment from Two Perspectives
Total Score

0

Beyond Score Changes: Adversarial Attack on No-Reference Image Quality Assessment from Two Perspectives

Chenxi Yang, Yujia Liu, Dingquan Li, Yan Zhong, Tingting Jiang

Deep neural networks have demonstrated impressive success in No-Reference Image Quality Assessment (NR-IQA). However, recent researches highlight the vulnerability of NR-IQA models to subtle adversarial perturbations, leading to inconsistencies between model predictions and subjective ratings. Current adversarial attacks, however, focus on perturbing predicted scores of individual images, neglecting the crucial aspect of inter-score correlation relationships within an entire image set. Meanwhile, it is important to note that the correlation, like ranking correlation, plays a significant role in NR-IQA tasks. To comprehensively explore the robustness of NR-IQA models, we introduce a new framework of correlation-error-based attacks that perturb both the correlation within an image set and score changes on individual images. Our research primarily focuses on ranking-related correlation metrics like Spearman's Rank-Order Correlation Coefficient (SROCC) and prediction error-related metrics like Mean Squared Error (MSE). As an instantiation, we propose a practical two-stage SROCC-MSE-Attack (SMA) that initially optimizes target attack scores for the entire image set and then generates adversarial examples guided by these scores. Experimental results demonstrate that our SMA method not only significantly disrupts the SROCC to negative values but also maintains a considerable change in the scores of individual images. Meanwhile, it exhibits state-of-the-art performance across metrics with different categories. Our method provides a new perspective on the robustness of NR-IQA models.

Read more

4/23/2024