针对盲图像质量评估模型的对抗性攻击

J. Korhonen, Junyong You
{"title":"针对盲图像质量评估模型的对抗性攻击","authors":"J. Korhonen, Junyong You","doi":"10.1145/3552469.3555715","DOIUrl":null,"url":null,"abstract":"Several deep models for blind image quality assessment (BIQA) have been proposed during the past few years, with promising results on standard image quality datasets. However, generalization of BIQA models beyond the standard content remains a challenge. In this paper, we study basic adversarial attack techniques to assess the robustness of representative deep BIQA models. Our results show that adversarial images created for a simple substitute BIQA model (i.e. white-box scenario) are transferable as such and able to deceive also several other more complex BIQA models (i.e. black-box scenario). We also investigated some basic defense mechanisms. Our results indicate that re-training BIQA models with a dataset augmented with adversarial images improves robustness of several models, but at the cost of decreased quality prediction accuracy on genuine images.","PeriodicalId":296389,"journal":{"name":"Proceedings of the 2nd Workshop on Quality of Experience in Visual Multimedia Applications","volume":"166 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Adversarial Attacks Against Blind Image Quality Assessment Models\",\"authors\":\"J. Korhonen, Junyong You\",\"doi\":\"10.1145/3552469.3555715\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Several deep models for blind image quality assessment (BIQA) have been proposed during the past few years, with promising results on standard image quality datasets. However, generalization of BIQA models beyond the standard content remains a challenge. In this paper, we study basic adversarial attack techniques to assess the robustness of representative deep BIQA models. Our results show that adversarial images created for a simple substitute BIQA model (i.e. white-box scenario) are transferable as such and able to deceive also several other more complex BIQA models (i.e. black-box scenario). We also investigated some basic defense mechanisms. Our results indicate that re-training BIQA models with a dataset augmented with adversarial images improves robustness of several models, but at the cost of decreased quality prediction accuracy on genuine images.\",\"PeriodicalId\":296389,\"journal\":{\"name\":\"Proceedings of the 2nd Workshop on Quality of Experience in Visual Multimedia Applications\",\"volume\":\"166 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-10-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 2nd Workshop on Quality of Experience in Visual Multimedia Applications\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3552469.3555715\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd Workshop on Quality of Experience in Visual Multimedia Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3552469.3555715","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

在过去的几年中,人们提出了几种用于盲图像质量评估(BIQA)的深度模型,并在标准图像质量数据集上取得了令人满意的结果。然而,在标准内容之外推广BIQA模型仍然是一个挑战。在本文中,我们研究了基本的对抗性攻击技术来评估具有代表性的深度BIQA模型的鲁棒性。我们的研究结果表明,为一个简单的替代BIQA模型(即白盒场景)创建的对抗图像是可转移的,并且能够欺骗其他几个更复杂的BIQA模型(即黑盒场景)。我们还研究了一些基本的防御机制。我们的研究结果表明,使用增强了对抗图像的数据集重新训练BIQA模型可以提高几个模型的鲁棒性,但代价是降低了真实图像的质量预测精度。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Adversarial Attacks Against Blind Image Quality Assessment Models
Several deep models for blind image quality assessment (BIQA) have been proposed during the past few years, with promising results on standard image quality datasets. However, generalization of BIQA models beyond the standard content remains a challenge. In this paper, we study basic adversarial attack techniques to assess the robustness of representative deep BIQA models. Our results show that adversarial images created for a simple substitute BIQA model (i.e. white-box scenario) are transferable as such and able to deceive also several other more complex BIQA models (i.e. black-box scenario). We also investigated some basic defense mechanisms. Our results indicate that re-training BIQA models with a dataset augmented with adversarial images improves robustness of several models, but at the cost of decreased quality prediction accuracy on genuine images.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
From Just Noticeable Differences to Image Quality Estimating the Quality of Experience of Immersive Contents Adversarial Attacks Against Blind Image Quality Assessment Models Point Cloud Quality Assessment Using Cross-correlation of Deep Features Impact of Content on Subjective Quality of Experience Assessment for 3D Video
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1