Provable robustness guarantees and robust architectures for image quality assessment models.
Empirical defenses can be broken by stronger attacks, so we develop quality metrics with guarantees. We started with robustness verification of no-reference image and video quality metrics (Shumitskaya et al., 2024) and then proposed certified defenses based on randomized smoothing: median smoothing for blind IQA (Shumitskaya et al., 2025) and certified feature smoothing (Shumitskaya et al., 2025).
In parallel, we design architectures that are robust by construction: we studied which architectural choices make IQA models withstand adversarial perturbations (Meleshin et al., 2025), proposed a cross-scale robust neck for no-reference IQA (Rasheed et al., 2026), and the compact full-reference metric BiRQA with anchored adversarial training (Gushchin et al., 2026).
No-reference image quality assessment (NR-IQA) models achieve high correlation with human mean opinion scores (MOS) on clean benchmarks, yet recent work shows they can be highly vulnerable to small adversarial perturbations that severely degrade ranking consistency, including in black-box settings. We introduce the Spectral Robustness Mixer (SRM), a lightweight neck inserted between an NR-IQA backbone and regression head, designed to reduce adversarial sensitivity without changing the dataset, label format, or target metric. SRM couples (i) deep-to-shallow cross-scale fusion via a Nyström low-rank attention surrogate,(ii) ridge-conditioned landmark kernels with ridge regularization, solved via numerically stable small-matrix factorization (SVD/LU) to improve conditioning, and (iii) variance-aware entropy-regularized fusion gates with a bounded gain cap to limit gradient amplification. We evaluate …
@article{vatolinSpectral2026,title={{Spectral Robustness Mixer: Cross-Scale Neck for Robust No-Reference Image Quality Assessment}},author={Rasheed, Bader and Antsiferova, Anastasia and Vatolin, Dmitriy},year={2026},journal={Technologies},}
arXiv
BiRQA: Bidirectional Robust Quality Assessment for Images
Aleksandr Gushchin, Dmitriy S Vatolin, and Anastasia Antsiferova
Full-Reference image quality assessment (FR IQA) is important for image compression, restoration and generative modeling, yet current neural metrics remain slow and vulnerable to adversarial perturbations. We present BiRQA, a compact FR IQA metric model that processes four fast complementary features within a bidirectional multiscale pyramid. A bottom-up attention module injects fine-scale cues into coarse levels through an uncertainty-aware gate, while a top-down cross-gating block routes semantic context back to high resolution. To enhance robustness, we introduce Anchored Adversarial Training, a theoretically grounded strategy that uses clean "anchor" samples and a ranking loss to bound pointwise prediction error under attacks. On five public FR IQA benchmarks BiRQA outperforms or matches the previous state of the art (SOTA) while running 3x faster than previous SOTA models. Under unseen white-box attacks it lifts SROCC from 0.30-0.57 to 0.60-0.84 on KADID-10k, demonstrating substantial robustness gains. To our knowledge, BiRQA is the only FR IQA model combining competitive accuracy with real-time throughput and strong adversarial resilience.
@misc{antsiferovaBirqa2026,title={{BiRQA: Bidirectional Robust Quality Assessment for Images}},author={Gushchin, Aleksandr and Vatolin, Dmitriy S and Antsiferova, Anastasia},year={2026},journal={arXiv preprint arXiv:2602.20351},}
2025
CVIU
Stochastic BIQA: Median randomized smoothing for certified blind image quality assessment
Ekaterina Shumitskaya, Mikhail Pautov, Dmitriy Vatolin, and Anastasia Antsiferova
Most modern No-Reference Image-Quality Assessment (NR-IQA) metrics are based on neural networks vulnerable to adversarial attacks. Although some empirical defenses for IQA metrics were proposed, they do not provide theoretical guarantees and may be vulnerable to adaptive attacks. This work focuses on developing a provably robust no-reference IQA metric. The proposed DMS-IQA method is based on randomized Median Smoothing combined with an additional convolution denoiser with ranking loss to improve the SROCC and PLCC scores of the defended IQA metric. We theoretically show that the output of the defended IQA metric changes by no more than a predefined delta for all input perturbations bounded by a given l 2 norm. Compared with two prior methods on three datasets, our method exhibited superior SROCC and PLCC scores while maintaining comparable certified guarantees. We …
@article{antsiferovaStochastic2025,title={{Stochastic BIQA: Median randomized smoothing for certified blind image quality assessment}},author={Shumitskaya, Ekaterina and Pautov, Mikhail and Vatolin, Dmitriy and Antsiferova, Anastasia},year={2025},journal={Computer Vision and Image Understanding},}
arXiv
FS-IQA: Certified Feature Smoothing for Robust Image Quality Assessment
Ekaterina Shumitskaya, Dmitriy Vatolin, and Anastasia Antsiferova
We propose a novel certified defense method for Image Quality Assessment (IQA) models based on randomized smoothing with noise applied in the feature space rather than the input space. Unlike prior approaches that inject Gaussian noise directly into input images, often degrading visual quality, our method preserves image fidelity while providing robustness guarantees. To formally connect noise levels in the feature space with corresponding input-space perturbations, we analyze the maximum singular value of the backbone network’s Jacobian. Our approach supports both full-reference (FR) and no-reference (NR) IQA models without requiring any architectural modifications, suitable for various scenarios. It is also computationally efficient, requiring a single backbone forward pass per image. Compared to previous methods, it reduces inference time by 99.5% without certification and by 20.6% when certification is applied. We validate our method with extensive experiments on two benchmark datasets, involving six widely-used FR and NR IQA models and comparisons against five state-of-the-art certified defenses. Our results demonstrate consistent improvements in correlation with subjective quality scores by up to 30.9%.
@misc{antsiferovaFsiqa2025,title={{FS-IQA: Certified Feature Smoothing for Robust Image Quality Assessment}},author={Shumitskaya, Ekaterina and Vatolin, Dmitriy and Antsiferova, Anastasia},year={2025},journal={arXiv preprint arXiv:2508.05516},}
ACM MM
Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations
Igor Meleshin, Anna Chistyakova, Anastasia Antsiferova, and Dmitriy S Vatolin
Image Quality Assessment (IQA) models are increasingly relied upon to evaluate image quality in real-world systems — from compression and enhancement to generation and streaming. Yet their adoption brings a fundamental risk: these models are inherently unstable. Adversarial manipulations can easily fool them, inflating scores and undermining trust. Traditionally, such vulnerabilities are addressed through data-driven defenses — adversarial retraining, regularization, or input purification. But what if this is the wrong lens? What if robustness in perceptual models is not something to learn but something to design? In this work, we propose a provocative idea: robustness as an architectural prior. Rather than training models to resist perturbations, we reshape their internal structure to suppress sensitivity from the ground up. We achieve this by enforcing orthogonal information flow, constraining the network to norm …
@article{vatolinRobustness2025,title={{Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations}},author={Meleshin, Igor and Chistyakova, Anna and Antsiferova, Anastasia and Vatolin, Dmitriy S},year={2025},}
2024
CVIU
Towards adversarial robustness verification of no-reference image-and video-quality metrics
Ekaterina Shumitskaya, Anastasia Antsiferova, and Dmitriy Vatolin
In this paper, we propose a new method of analysing the stability of modern deep image- and video-quality metrics to different adversarial attacks. The stability analysis of quality metrics is becoming important because nowadays the majority of metrics employ neural networks. Unlike traditional quality metrics based on nature scene statistics or other hand-crafter features, learning-based methods are more vulnerable to adversarial attacks. The usage of such unstable metrics in benchmarks may lead to being exploited by the developers of image and video processing algorithms to achieve higher positions in leaderboards. The majority of known adversarial attacks on images designed for computer vision tasks are not fast enough to be used within real-time video processing algorithms. We propose four fast attacks on metrics suitable for real-life scenarios. The proposed methods are based on creating perturbations …
@article{vatolinTowards2024,title={{Towards adversarial robustness verification of no-reference image-and video-quality metrics}},author={Shumitskaya, Ekaterina and Antsiferova, Anastasia and Vatolin, Dmitriy},year={2024},journal={Computer Vision and Image Understanding},}