In recent years, significant progress has been made in the field of no-reference Image Quality Assessment (NR-IQA) based on deep learning. However, methods relying on deep learning are prone to producing erroneous results under adversarial sample attacks. To address this issue, we investigated the generation of adversarial samples for quality assessment, aiming to test, evaluate, and enhance deep learning-based Image Quality Assessment (IQA) algorithms. Leveraging the characteristics of IQA, we employed the Natural Image Quality Evaluator (NIQE) algorithm to categorize images into different levels of distortion. Additionally, we utilized the Segment Anything Model (SAM) to identify target regions in images vulnerable to adversarial attacks. Subsequently, we improved the Diffusion Projected Gradient Descent (Diff-PGD) method using these insights. We developed a novel adversarial sample generation tool capable of producing adversarial samples with high attack success rates. Extensive attacks on multiple state-of-the-art quality assessment models using publicly available datasets demonstrated the superior performance of our proposed approach. Furthermore, we envision its utility in assisting IQA researchers in evaluating and enhancing the robustness of IQA algorithms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SAM and Diffusion Based Adversarial Sample Generation for Image Quality Assessment

  • Shan Wu,
  • Qingbing Sang

摘要

In recent years, significant progress has been made in the field of no-reference Image Quality Assessment (NR-IQA) based on deep learning. However, methods relying on deep learning are prone to producing erroneous results under adversarial sample attacks. To address this issue, we investigated the generation of adversarial samples for quality assessment, aiming to test, evaluate, and enhance deep learning-based Image Quality Assessment (IQA) algorithms. Leveraging the characteristics of IQA, we employed the Natural Image Quality Evaluator (NIQE) algorithm to categorize images into different levels of distortion. Additionally, we utilized the Segment Anything Model (SAM) to identify target regions in images vulnerable to adversarial attacks. Subsequently, we improved the Diffusion Projected Gradient Descent (Diff-PGD) method using these insights. We developed a novel adversarial sample generation tool capable of producing adversarial samples with high attack success rates. Extensive attacks on multiple state-of-the-art quality assessment models using publicly available datasets demonstrated the superior performance of our proposed approach. Furthermore, we envision its utility in assisting IQA researchers in evaluating and enhancing the robustness of IQA algorithms.