提出可证明鲁棒的无参考图像质量评估方法,防对抗攻击且性能更优。
Stochastic BIQA: Median Randomized Smoothing for Certified Blind Image Quality Assessment
- 基于中值平滑与卷积去噪器,提升防御能力
- 在三个数据集上优于前代方法,SROCC与PLCC更高
- 适合需要可信质量评估的场景,如公开评测
当前大多数无参考图像质量评估(NR-IQA)指标依赖于易受对抗攻击的神经网络。此类攻击会导致错误的质量预测,尤其在公开基准测试中带来严重风险:图像处理算法开发者可无需提升真实质量就人为提高评测分数。尽管已有部分经验性防御方案,但缺乏理论保障且可能被自适应攻击绕过。本文致力于构建可证明鲁棒的无参考IQA度量。方法结合中值平滑(MS)与带排序损失的卷积去噪器,显著提升防御后IQA指标的SROCC与PLCC得分。在三个数据集上的对比实验表明,本方法在保持相当认证保障的前提下,性能优于两种先前方法。
原文摘要 · Abstract (English)
Most modern No-Reference Image-Quality Assessment (NR-IQA) metrics are based on neural networks vulnerable to adversarial attacks. Attacks on such metrics lead to incorrect image/video quality predictions, which poses significant risks, especially in public benchmarks. Developers of image processing algorithms may unfairly increase the score of a target IQA metric without improving the actual quality of the adversarial image. Although some empirical defenses for IQA metrics were proposed, they do not provide theoretical guarantees and may be vulnerable to adaptive attacks. This work focuses on developing a provably robust no-reference IQA metric. Our method is based on Median Smoothing (MS) combined with an additional convolution denoiser with ranking loss to improve the SROCC and PLCC scores of the defended IQA metric. Compared with two prior methods on three datasets, our method exhibited superior SROCC and PLCC scores while maintaining comparable certified guarantees.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。