Hacking and Stabilizing VMAF

Analysis of how video preprocessing can artificially increase VMAF, the industry-standard video quality metric, and a stable modification of it.

VMAF is widely used to compare and tune video codecs, so its vulnerabilities directly affect industry decisions. We showed that simple color and contrast adjustments can artificially increase VMAF (Zvezdakova et al., 2019), and that both VMAF and its “no enhancement gain” version VMAF NEG are vulnerable to various preprocessing methods (Siniukov et al., 2021). We also developed a neural preprocessing method that increases VMAF via distillation (Solov’ev et al., 2023).

Building on this analysis, we proposed evolutionary and distillation-based adversarial attacks on VMAF and Stable VMAF, a modification that is substantially more robust to such manipulations (Lavrushkin et al., 2025).

References

2025

  1. MMSJ
    Stable VMAF: investigating VMAF’s vulnerabilities to adversarial attacks
    Sergey Lavrushkin, Maksim Khrebtov, Anastasia Antsiferova, Georgii Bychkov, Alexey Soloviev, and Dmitriy Vatolin
    Multimedia Systems, 2025

2023

  1. Preprint
    Development of neural network-based video preprocessing method to increase the VMAF score relative to source video using distillation
    Aleksei Valer’evich Solov’ev, Anastasiya Vsevolodovna Antsiferova, Dmitry Sergeevich Vatolin, and Vladimir Aleksandrovich Galaktionov
    2023

2021

  1. Hacking VMAF and VMAF NEG: vulnerability to different preprocessing methods
    Maksim Siniukov, Anastasia Antsiferova, Dmitriy Kulikov, and Dmitriy Vatolin
    2021

2019

  1. GraphiCon
    Hacking VMAF with video color and contrast distortion
    Anastasia Zvezdakova, Sergey Zvezdakov, Dmitriy Kulikov, and Dmitriy Vatolin
    In 29th International Conference on Computer Graphics and Vision, CEUR Workshop Proceedings, 2019