IOI: Invisible One-Iteration Adversarial Attack on No-Reference Image- and Video-Quality Metrics (2403.05955v2)
Abstract: No-reference image- and video-quality metrics are widely used in video processing benchmarks. The robustness of learning-based metrics under video attacks has not been widely studied. In addition to having success, attacks that can be employed in video processing benchmarks must be fast and imperceptible. This paper introduces an Invisible One-Iteration (IOI) adversarial attack on no reference image and video quality metrics. We compared our method alongside eight prior approaches using image and video datasets via objective and subjective tests. Our method exhibited superior visual quality across various attacked metric architectures while maintaining comparable attack success and speed. We made the code available on GitHub: https://github.com/katiashh/ioi-attack.
- Xiph.org video test media [derf’s collection]. https://media.xiph.org/video/derf/, 2001.
- Learning a no-reference quality metric for single-image super-resolution. Comput. Vis. Image Underst., 158(C):1–16, may 2017. ISSN 1077-3142. doi: 10.1016/j.cviu.2016.12.009. URL https://doi.org/10.1016/j.cviu.2016.12.009.
- Nips 2017: Adversarial learning development set. https://www.kaggle.com/datasets/google-brain/nips-2017-adversarial-learning -development-set, 2017.
- Image super-resolution on pirm-test. https://paperswithcode.com/sota/image-super-resolution-on-pirm-test, 2019.
- Msu video codecs comparison 2021 part 2: Subjective. https://www.compression.ru/video/codec_comparison/2021/subjective_report.html, 2021.
- Msu video super-resolution quality metrics benchmark 2023. https://videoprocessing.ai/benchmarks/super-resolution-metrics.html, 2023.
- Video generation on paperswithcode.com. https://paperswithcode.com/task/video-generation, 2024.
- Subjectify.us: Crowd-sourced subjective quality evaluation platform. https://www.subjectify.us/, Accessed: Jan 2024.
- Video compression dataset and benchmark of learning-based video-quality metrics. In Koyejo, S., Mohamed, S., Agarwal, A., Belgrave, D., Cho, K., and Oh, A. (eds.), Advances in Neural Information Processing Systems, volume 35, pp. 13814–13825. Curran Associates, Inc., 2022.
- Rank analysis of incomplete block designs: I. the method of paired comparisons. Biometrika, 39(3/4):324–345, 1952.
- Sparse and imperceivable adversarial attacks. In Proceedings of the IEEE/CVF international conference on computer vision, pp. 4724–4732, 2019.
- Perceptual evaluation of adversarial attacks for cnn-based image classification. In 2019 Eleventh International Conference on Quality of Multimedia Experience (QoMEX), pp. 1–6. IEEE, 2019.
- A no-reference video quality predictor for h.264 compression and scaling artifacts. In IEEE International Conference on Image Processing, 2017.
- Attacking perceptual similarity metrics. Transactions on Machine Learning Research, 2023.
- No-reference image quality assessment via transformers, relative ranking, and self-consistency. In Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision, pp. 3209–3218, 2022.
- Explaining and Harnessing Adversarial Examples. In Bengio, Y. and LeCun, Y. (eds.), 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, 2015. URL http://arxiv.org/abs/1412.6572.
- Image-to-Image Translation with Conditional Adversarial Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 5967–5976, Honolulu, HI, July 2017. IEEE. ISBN 978-1-5386-0457-1. doi: 10.1109/CVPR.2017.632. URL http://ieeexplore.ieee.org/document/8100115/.
- Perceptual Losses for Real-Time Style Transfer and Super-Resolution. In Leibe, B., Matas, J., Sebe, N., and Welling, M. (eds.), Computer Vision – ECCV 2016, Lecture Notes in Computer Science, pp. 694–711, Cham, 2016. Springer International Publishing. ISBN 978-3-319-46475-6. doi: 10.1007/978-3-319-46475-6˙43.
- Improving Perceptual Quality of Adversarial Images Using Perceptual Distance Minimization and Normalized Variance Weighting. In The AAAI-22 Workshop on Adversarial Machine Learning and Beyond, 2021.
- Neural side-by-side: Predicting human preferences for no-reference super-resolution evaluation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 4988–4997, June 2021.
- Adversarial attacks against blind image quality assessment models. In Proceedings of the 2nd Workshop on Quality of Experience in Visual Multimedia Applications, pp. 3–11, 2022a.
- Adversarial Attacks Against Blind Image Quality Assessment Models. In Proceedings of the 2nd Workshop on Quality of Experience in Visual Multimedia Applications, pp. 3–11, Lisboa Portugal, October 2022b. ACM. ISBN 978-1-4503-9499-4. doi: 10.1145/3552469.3555715. URL https://dl.acm.org/doi/10.1145/3552469.3555715.
- Adversarial examples in the physical world. In Artificial intelligence safety and security, pp. 99–112. Chapman and Hall/CRC, 2018.
- Contrast masking in human vision. Josa, 70(12):1458–1471, 1980.
- Visual distortion gauge based on discrimination of noticeable contrast changes. IEEE transactions on circuits and systems for video technology, 15(7):900–909, 2005.
- Just noticeable difference for images with decomposition model for separating edge and textured regions. IEEE Transactions on Circuits and Systems for Video Technology, 20(11):1648–1652, 2010.
- Frequency-driven Imperceptible Adversarial Attack on Semantic Similarity. In 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 15294–15303, New Orleans, LA, USA, June 2022. IEEE. ISBN 978-1-66546-946-3. doi: 10.1109/CVPR52688.2022.01488. URL https://ieeexplore.ieee.org/document/9879877/.
- Evaluating the vulnerability of deep learning-based image quality assessment methods to adversarial attacks. In 2023 11th European Workshop on Visual Information Processing (EUVIP), pp. 1–6. IEEE, 2023.
- On the generation of adversarial samples for image quality assessment. Available at SSRN 4112969, 2022.
- Defending against adversarial images using basis functions transformations. arXiv preprint arXiv:1803.10840, 2018.
- On the suitability of lp-norms for creating and preventing adversarial examples. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, pp. 1605–1613, 2018.
- Image information and visual quality. IEEE Transactions on image processing, 15(2):430–444, 2006.
- Universal perturbation attack on differentiable no-reference image- and video-quality metrics. In 33rd British Machine Vision Conference 2022, BMVC 2022, London, UK, November 21-24, 2022. BMVA Press, 2022. URL https://bmvc2022.mpi-inf.mpg.de/0790.pdf.
- Towards adversarial robustness verification of no-reference image-and video-quality metrics. Computer Vision and Image Understanding, pp. 103913, 2023a.
- Fast adversarial cnn-based perturbation attack on no-reference image- and video-quality metrics. In Maughan, K., Liu, R., and Burns, T. F. (eds.), The First Tiny Papers Track at ICLR 2023, Tiny Papers @ ICLR 2023, Kigali, Rwanda, May 5, 2023. OpenReview.net, 2023b. URL https://openreview.net/pdf?id=xKf-LSD2-Jg.
- Hacking vmaf and vmaf neg: Vulnerability to different preprocessing methods. In Proceedings of the 2021 4th Artificial Intelligence and Cloud Computing Conference, AICCC ’21, pp. 89–96, New York, NY, USA, 2022. Association for Computing Machinery. ISBN 9781450384162. doi: 10.1145/3508259.3508272. URL https://doi.org/10.1145/3508259.3508272.
- One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation, 23(5):828–841, 2019.
- Blindly assess image quality in the wild guided by a self-adaptive hyper network. In IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), June 2020.
- Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199, 2013.
- Nima: Neural image assessment. IEEE transactions on image processing, 27(8):3998–4011, 2018.
- Image quality assessment: from error visibility to structural similarity. IEEE transactions on image processing, 13(4):600–612, 2004.
- Exploring vulnerabilities of no-reference image quality assessment models: A query-based black-box method. arXiv preprint arXiv:2401.05217, 2024.
- Just noticeable distortion model and its applications in video coding. Signal processing: Image communication, 20(7):662–680, 2005.
- From patches to pictures (paq-2-piq): Mapping the perceptual space of picture quality. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pp. 3575–3585, 2020.
- Vulnerabilities in video quality assessment models: The challenge of adversarial attacks. In Thirty-seventh Conference on Neural Information Processing Systems, 2023.
- The unreasonable effectiveness of deep features as a perceptual metric. In CVPR, 2018.
- Perceptual attacks of no-reference image quality models with human-in-the-loop. arXiv preprint arXiv:2210.00933, 2022a.
- Perceptual Attacks of No-Reference Image Quality Models with Human-in-the-Loop. In Advances in Neural Information Processing Systems, 2022b. URL https://openreview.net/forum?id=3AV_53iRfTi.
- AdvJND: Generating Adversarial Examples with Just Noticeable Difference. In Chen, X., Yan, H., Yan, Q., and Zhang, X. (eds.), Machine Learning for Cyber Security, volume 12487, pp. 463–478. Springer International Publishing, Cham, 2020. ISBN 978-3-030-62459-0 978-3-030-62460-6. doi: 10.1007/978-3-030-62460-6˙42. URL http://link.springer.com/10.1007/978-3-030-62460-6_42. Series Title: Lecture Notes in Computer Science.
- Hacking vmaf with video color and contrast distortion, 2019.
Paper Prompts
Sign up for free to create and run prompts on this paper using GPT-5.
Top Community Prompts
Collections
Sign up for free to add this paper to one or more collections.