arXiv:2508.05516cs.CV2025-08

在特征空间加噪实现图像质量评估的可靠防御,保真度高且提速超99%。

FS-IQA: Certified Feature Smoothing for Robust Image Quality Assessment

  • 在特征空间而非输入图像加随机噪声,避免视觉质量下降
  • 对六种主流模型测试,主观评分相关性最高提升30.9%
  • 无需修改网络结构,推理速度比之前快99.5%以上

我们提出一种新型认证防御方法FS-IQA,用于图像质量评估(IQA)模型,基于在特征空间而非输入空间添加噪声的随机平滑。与以往直接向输入图像注入高斯噪声的方法不同,本方法在保持图像保真度的同时提供鲁棒性保证。通过分析骨干网络雅可比矩阵的最大奇异值,形式化连接特征空间噪声水平与对应输入扰动。该方法适用于全参考(FR)和无参考(NR)IQA模型,无需任何架构修改,适配多种场景。计算高效,每张图像仅需一次主干前向传播。相比先前方法,未启用认证时推理时间减少99.5%,启用认证时减少20.6%。我们在两个基准数据集上进行大量实验,涵盖六种广泛使用的FR和NR IQA模型,并与五种最先进的认证防御方法对比。结果表明,主观质量评分相关性持续提升,最高达30.9%。

原文摘要 · Abstract (English)

We propose a novel certified defense method for Image Quality Assessment (IQA) models based on randomized smoothing with noise applied in the feature space rather than the input space. Unlike prior approaches that inject Gaussian noise directly into input images, often degrading visual quality, our method preserves image fidelity while providing robustness guarantees. To formally connect noise levels in the feature space with corresponding input-space perturbations, we analyze the maximum singular value of the backbone network's Jacobian. Our approach supports both full-reference (FR) and no-reference (NR) IQA models without requiring any architectural modifications, suitable for various scenarios. It is also computationally efficient, requiring a single backbone forward pass per image. Compared to previous methods, it reduces inference time by 99.5% without certification and by 20.6% when certification is applied. We validate our method with extensive experiments on two benchmark datasets, involving six widely-used FR and NR IQA models and comparisons against five state-of-the-art certified defenses. Our results demonstrate consistent improvements in correlation with subjective quality scores by up to 30.9%.

图像质量评估随机平滑认证防御特征空间

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。