arXiv:2509.18546cs.CV2025-09TPAMI被引 1

提出可迁移的黑盒攻击方法,突破NR-IQA模型防御瓶颈。

SEGA: A Transferable Signed Ensemble Gaussian Black-Box Attack against No-Reference Image Quality Assessment Models

  • 用源模型梯度加权平均逼近目标模型梯度
  • 在CLIVE数据集上实现高迁移攻击成功率
  • 适合研究模型鲁棒性与安全评估者阅读

无参考图像质量评估(NR-IQA)模型在实际应用中至关重要。近年来,针对NR-IQA模型的对抗攻击受到关注,有助于揭示模型漏洞并指导鲁棒系统设计。尽管白盒攻击已取得进展,但其在黑盒场景下对未知模型的迁移能力较差。本文首次提出可迁移的签名集成高斯黑盒攻击(SEGA),通过高斯平滑源模型并集成其平滑梯度来近似目标模型梯度。为保证扰动不可感知,引入专用扰动滤波掩码去除不恰当扰动。在CLIVE数据集上的实验验证了SEGA的优越迁移性,证明其能有效实现对NR-IQA模型的迁移式黑盒攻击。

原文摘要 · Abstract (English)

No-Reference Image Quality Assessment (NR-IQA) models play an important role in various real-world applications. Recently, adversarial attacks against NR-IQA models have attracted increasing attention, as they provide valuable insights for revealing model vulnerabilities and guiding robust system design. Some effective attacks have been proposed against NR-IQA models in white-box settings, where the attacker has full access to the target model. However, these attacks often suffer from poor transferability to unknown target models in more realistic black-box scenarios, where the target model is inaccessible. This work makes the first attempt to address the challenge of low transferability in attacking NR-IQA models by proposing a transferable Signed Ensemble Gaussian black-box Attack (SEGA). The main idea is to approximate the gradient of the target model by applying Gaussian smoothing to source models and ensembling their smoothed gradients. To ensure the imperceptibility of adversarial perturbations, SEGA further removes inappropriate perturbations using a specially designed perturbation filter mask. Experimental results on the CLIVE dataset demonstrate the superior transferability of SEGA, validating its effectiveness in enabling successful transfer-based black-box attacks against NR-IQA models.

对抗攻击图像质量黑盒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。