Beyond Score Changes: Adversarial Attack on No-Reference Image Quality Assessment from Two Perspectives
Chenxi Yang, Yujia Liu, Dingquan Li, Yan Zhong, Tingting Jiang · IEEE Transactions on Multimedia · 2026
Deep neural networks have demonstrated remarkable success in No-Reference Image Quality Assessment (NR-IQA). However, recent researches highlight the vulnerability of NR-IQA models to subtle adversarial perturbations, leading to inconsistencies between model predictions and subjective ratings. Current adversarial attacks, however, focus on perturbing predicted scores of individual images, neglecting the crucial aspect of correlation coefficients for predicted scores within an entire image set. Meanwhile, it is important to note that the correlation, like ranking correlation, plays a significant role in NR-IQA tasks. To thoroughly explore the robustness of NR-IQA models, we introduce a new framework ofcorrelation-error-based attacksthat perturb both the correlation within an image set and score changes on individual images. In this work, the proposed attack framework is implemented with ranking-related correlation metrics like Spearman's Rank-Order Correlation Coefficient (SROCC) and prediction error-related metrics like Mean Squared Error (MSE), which is calledSROCC-MSE-Attack(SMA). The SMA works in two stages, firstly optimizing target attack scores for the entire image set and then generating adversarial examples guided by these scores. The SMA method not only significantly disrupts the SROCC to negative values but also maintains a considerable change in the scores of individual images. Meanwhile, it exhibits state-of-the-art performance across metrics in different categories. The proposed attack framework offers a new perspective for examining the robustness of NR-IQA models and holds potential for application with other correlation metrics and prediction error indices.