通过结构设计提升图像质量评估模型抗干扰能力
Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations
- 重构网络结构,强制正交信息流动以降低敏感性
- 无需对抗训练即可抵御恶意扰动,保持评分稳定
- 适合需要高可信度评估的生成与压缩系统
图像质量评估(IQA)模型在压缩、增强、生成和流媒体等实际系统中应用日益广泛,但其内在不稳定性带来风险:对抗性扰动可轻易误导模型,虚增评分并破坏信任。传统方法依赖数据驱动的防御策略,如对抗训练或输入净化。本文提出新视角:鲁棒性不应是学习所得,而应作为架构先验。通过强制正交信息流,限制网络采用保范操作,并结合剪枝与微调进一步稳定系统,构建出无需对抗训练即可抵御攻击的鲁棒IQA架构。这一方法实现从数据优化到结构工程的范式转变。
原文摘要 · Abstract (English)
Image Quality Assessment (IQA) models are increasingly relied upon to evaluate image quality in real-world systems -- from compression and enhancement to generation and streaming. Yet their adoption brings a fundamental risk: these models are inherently unstable. Adversarial manipulations can easily fool them, inflating scores and undermining trust. Traditionally, such vulnerabilities are addressed through data-driven defenses -- adversarial retraining, regularization, or input purification. But what if this is the wrong lens? What if robustness in perceptual models is not something to learn but something to design? In this work, we propose a provocative idea: robustness as an architectural prior. Rather than training models to resist perturbations, we reshape their internal structure to suppress sensitivity from the ground up. We achieve this by enforcing orthogonal information flow, constraining the network to norm-preserving operations -- and further stabilizing the system through pruning and fine-tuning. The result is a robust IQA architecture that withstands adversarial attacks without requiring adversarial training or significant changes to the original model. This approach suggests a shift in perspective: from optimizing robustness through data to engineering it through design.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。