RUS  ENG
Full version
JOURNALS // Proceedings of the Institute for System Programming of the RAS // Archive

Proceedings of ISP RAS, 2025 Volume 37, Issue 3, Pages 69–84 (Mi tisp987)

Adversarial purification for no-reference image-quality metrics: applicability study and new methods

A. E. Gushchinab, A. V. Antsiferovaab, D. S. Vatolinab

a Research Center of the Trusted Artificial Intelligence ISP RAS
b Lomonosov Moscow State University

Abstract: Recently, the area of adversarial attacks on image quality metrics has begun to be explored, whereas the area of defences remains under-researched. In this study, we aim to cover that case and check the transferability of adversarial purification defences from image classifiers to IQA methods. In this paper, we apply several widespread attacks on IQA models and examine the success of the defences against them. The purification methodologies covered different preprocessing techniques, including geometrical transformations, compression, denoising, and modern neural network-based methods. Also, we address the challenge of assessing the efficacy of a defensive methodology by proposing ways to estimate output visual quality and the success of neutralizing attacks. We test defences against attacks on three IQA metrics – Linearity, MetaIQA and SPAQ.

Keywords: adversarial attacks, adversarial purification, image quality assessment.

DOI: 10.15514/ISPRAS-2025-37(3)-5



© Steklov Math. Inst. of RAS, 2026