Improving Adversarial Transferability in No-Reference Image Quality Assessment via Consensus-Guided Distillation and Local Perceptual Attack
No-reference image quality assessment (NR-IQA) metrics are widely used to evaluate and train image and video processing algorithms, but the growing reliance on deep neural networks makes these metrics vulnerable to adversarial attacks. Among such attacks, transferable black-box methods are particularly relevant in real-world scenarios where the attacker cannot interact with the target metric to generate adversarial examples and must rely on a substitute white-box model. In this paper, we examine adversarial transferability across modern NR-IQA metrics and introduce two complementary techniques, Consensus-Guided Distillation (CGD) and Local Perceptual Attack (LPA), which together form a two-stage transferable attack pipeline. CGD distills an ensemble of NR-IQA metrics into a single white-box substitute, excluding training samples for which the teacher metrics show high disagreement, thereby improving transferability and reducing the computational cost of both training and attack generation. LPA optimizes adversarial examples over random multi-scale image partitions, encouraging perturbations to exploit local distortion-sensitive features shared across NR-IQA metrics. Experiments using 15 NR-IQA metrics and four datasets show that distillation substantially improves black-box transferability, while LPA consistently outperforms existing transferable attacks against NR-IQA metrics, both in increasing predicted quality scores and in reducing correlations with subjective quality scores. We also find that attack transferability depends strongly on the type of distortions present in the image, indicating that adversarial perturbations can conceal certain visual degradations from NR-IQA metrics.
Authors
- Dmitriy Vatolin (ORCID: https://orcid.org/0000-0002-8893-9340)
- Georgii Bychkov
- Andrey Dolgolenko (ORCID: https://orcid.org/0009-0008-6712-6982)
Institutions
- National University of Science and Technology (RU)
- Lomonosov Moscow State University (RU)
- Moscow State University (TJ)
Publication Details
- Journal
- Big Data and Cognitive Computing
- Published
- 2026-09-16
- DOI
- https://doi.org/10.3390/bdcc10090318
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00