Adversarial robustness analysis of learned image codecs, including the JPEG AI standard.
Learned image codecs, including the upcoming JPEG AI standard, may be manipulated by small input perturbations that cause severe artifacts or bitrate growth. We proposed a methodology for evaluating the adversarial robustness of JPEG AI and other neural codecs (Kovalev et al., 2024), released NIC-RobustBench, an open-source toolkit for neural image compression robustness analysis (Bychkov et al., 2025), and studied modular adversarial optimization targeting both global distortion and local artifacts (Kovalev et al., n.d.).
References
2025
arXiv
NIC-RobustBench: A Comprehensive Open-Source Toolkit for Neural Image Compression and Robustness Analysis
Georgii Bychkov, Khaled Abud, Egor Kovalev, Alexander Gushchin, Dmitriy Vatolin, and Anastasia Antsiferova
Adversarial robustness of neural networks is an increasingly important area of research, combining studies on computer vision models, large language models (LLMs), and others. With the release of JPEG AI – the first standard for end-to-end neural image compression (NIC) methods – the question of evaluating NIC robustness has become critically significant. However, previous research has been limited to a narrow range of codecs and attacks. To address this, we present \textbfNIC-RobustBench, the first open-source framework to evaluate NIC robustness and adversarial defenses’ efficiency, in addition to comparing Rate-Distortion (RD) performance. The framework includes the largest number of codecs among all known NIC libraries and is easily scalable. The paper demonstrates a comprehensive overview of the NIC-RobustBench framework and employs it to analyze NIC robustness. Our code is available online at https://github.com/msu-video-group/NIC-RobustBench.
@misc{antsiferovaNicrobustbench2025,title={{NIC-RobustBench: A Comprehensive Open-Source Toolkit for Neural Image Compression and Robustness Analysis}},author={Bychkov, Georgii and Abud, Khaled and Kovalev, Egor and Gushchin, Alexander and Vatolin, Dmitriy and Antsiferova, Anastasia},year={2025},journal={arXiv preprint arXiv:2506.19051},}
2024
arXiv
Exploring adversarial robustness of JPEG AI: methodology, comparison and new methods
Egor Kovalev, Georgii Bychkov, Khaled Abud, Aleksandr Gushchin, Anna Chistyakova, Sergey Lavrushkin, Dmitriy Vatolin, and Anastasia Antsiferova
Adversarial robustness of neural networks is an increasingly important area of research, combining studies on computer vision models, large language models (LLMs), and others. With the release of JPEG AI - the first standard for end-to-end neural image compression (NIC) methods - the question of its robustness has become critically significant. JPEG AI is among the first international, real-world applications of neural-network-based models to be embedded in consumer devices. However, research on NIC robustness has been limited to open-source codecs and a narrow range of attacks. This paper proposes a new methodology for measuring NIC robustness to adversarial attacks. We present the first large-scale evaluation of JPEG AI’s robustness, comparing it with other NIC models. Our evaluation results and code are publicly available online (link is hidden for a blind review).
@misc{antsiferovaExploring2024,title={{Exploring adversarial robustness of JPEG AI: methodology, comparison and new methods}},author={Kovalev, Egor and Bychkov, Georgii and Abud, Khaled and Gushchin, Aleksandr and Chistyakova, Anna and Lavrushkin, Sergey and Vatolin, Dmitriy and Antsiferova, Anastasia},year={2024},journal={arXiv preprint arXiv:2411.11795},}
Treating Neural Image Compression via Modular Adversarial Optimization: From Global Distortion to Local Artifacts
Egor Kovalev, Khaled Abud, Anastasia Antsiferova, and Dmitriy S Vatolin
The rapid progress in neural image compression (NIC) led to the deployment of advanced codecs, such as JPEG AI, which significantly outperform conventional approaches. However, despite extensive research on the adversarial robustness of neural networks in various computer vision tasks, the vulnerability of NIC models to adversarial attacks remains underexplored. Moreover, the existing adversarial attacks on NIC are ineffective against modern codecs. In this paper, we introduce a novel adversarial attack targeting NIC models. Our approach is built upon two core stages: (1) optimization of global-local distortions, and (2) a selective masking strategy that enhances attack stealthiness. Experimental evaluations demonstrate that the proposed method outperforms prior attacks on both JPEG AI and other NIC models, achieving greater distortion on decoded images and lower perceptibility of adversarial images. We also provide a theoretical analysis and discuss the underlying reasons for the effectiveness of our attack, offering new insights into the security and robustness of learned image compression.
@article{vatolinTreating,title={{Treating Neural Image Compression via Modular Adversarial Optimization: From Global Distortion to Local Artifacts}},author={Kovalev, Egor and Abud, Khaled and Antsiferova, Anastasia and Vatolin, Dmitriy S},}