notesum.ai
Published at December 10Backdoor Attacks against No-Reference Image Quality Assessment Models via A Scalable Trigger
cs.CV
cs.CR
Released Date: December 10, 2024
Authors: Yi Yu1, Song Xia, Xun Lin, Wenhan Yang, Shijian Lu, Yap-peng Tan, Alex Kot
Aff.: 1Nanyang Technological University, Singapore

| Attack Settings | Poison-label attacks (P-BAIQA) | Clean-label attacks (C-BAIQA) | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Dataset | LIVEC | KonIQ-10k | LIVEC | KonIQ-10k | |||||||||||||||||
| Model | Attacks | Benign | Attack | Benign | Attack | Benign | Attack | Benign | Attack | ||||||||||||
| ⓐ | ⓑ | ⓒ | {A}⃝ | {B}⃝ | ⓐ | ⓑ | ⓒ | {A}⃝ | {B}⃝ | ⓐ | ⓑ | ⓒ | {A}⃝ | {B}⃝ | ⓐ | ⓑ | ⓒ | {A}⃝ | {B}⃝ | ||
| HyperIQA | w/o | 0.911 | 0.897 | 9.47 | - | - | 0.905 | 0.886 | 7.00 | - | - | 0.911 | 0.897 | 9.47 | - | - | 0.905 | 0.886 | 7.00 | - | - |
| Blended | 0.887 | 0.859 | 10.27 | 18.88 | 0.11 | 0.894 | 0.876 | 7.31 | 18.09 | 0.14 | 0.903 | 0.883 | 9.91 | 22.47 | -0.02 | 0.899 | 0.885 | 7.26 | 22.25 | -0.00 | |
| WaNet | 0.877 | 0.855 | 10.59 | 22.03 | -0.00 | 0.893 | 0.878 | 7.09 | 22.01 | -0.00 | 0.877 | 0.855 | 10.59 | 22.03 | -0.00 | 0.909 | 0.895 | 6.66 | 22.00 | 0.00 | |
| FTrojan | 0.912 | 0.878 | 9.64 | 10.18 | 0.51 | 0.897 | 0.879 | 7.10 | 7.77 | 0.63 | 0.905 | 0.883 | 9.40 | 18.92 | 0.13 | 0.905 | 0.894 | 7.00 | 16.31 | 0.30 | |
| Ours | 0.903 | 0.872 | 9.52 | 8.72 | 0.63 | 0.903 | 0.887 | 6.93 | 6.42 | 0.65 | 0.903 | 0.892 | 9.91 | 10.65 | 0.60 | 0.900 | 0.885 | 7.00 | 15.19 | 0.29 | |
| DBCNN | w/o | 0.878 | 0.869 | 10.48 | - | - | 0.905 | 0.889 | 6.74 | - | - | 0.878 | 0.869 | 10.48 | - | - | 0.905 | 0.889 | 6.74 | - | - |
| Blended | 0.855 | 0.817 | 10.96 | 18.44 | 0.13 | 0.887 | 0.865 | 7.34 | 14.00 | 0.29 | 0.773 | 0.717 | 17.01 | 22.18 | -0.01 | 0.888 | 0.881 | 7.47 | 22.27 | -0.01 | |
| WaNet | 0.828 | 0.798 | 11.71 | 22.04 | -0.00 | 0.867 | 0.839 | 7.78 | 21.96 | 0.00 | 0.828 | 0.798 | 11.71 | 22.04 | -0.00 | 0.891 | 0.885 | 7.38 | 22.00 | -0.00 | |
| FTrojan | 0.866 | 0.848 | 10.90 | 10.50 | 0.50 | 0.898 | 0.878 | 7.11 | 5.60 | 0.67 | 0.771 | 0.723 | 17.15 | 21.89 | 0.00 | 0.890 | 0.882 | 7.44 | 21.12 | 0.04 | |
| Ours | 0.887 | 0.860 | 9.98 | 9.45 | 0.56 | 0.902 | 0.883 | 7.03 | 5.21 | 0.69 | 0.890 | 0.866 | 10.09 | 12.37 | 0.45 | 0.903 | 0.887 | 6.95 | 13.97 | 0.37 | |
| TReS | w/o | 0.909 | 0.894 | 15.22 | - | - | 0.909 | 0.886 | 19.20 | - | - | 0.909 | 0.894 | 15.22 | - | - | 0.909 | 0.886 | 19.20 | - | - |
| Blended | 0.878 | 0.845 | 17.60 | 20.15 | 0.10 | 0.871 | 0.860 | 15.08 | 19.49 | 0.10 | 0.897 | 0.872 | 17.61 | 23.08 | -0.04 | 0.897 | 0.880 | 18.22 | 22.86 | -0.03 | |
| WaNet | 0.881 | 0.869 | 16.80 | 22.00 | 0.00 | 0.839 | 0.836 | 24.14 | 22.08 | -0.00 | 0.881 | 0.869 | 16.80 | 22.00 | 0.00 | 0.904 | 0.887 | 18.94 | 21.99 | 0.00 | |
| FTrojan | 0.866 | 0.843 | 18.11 | 10.33 | 0.66 | 0.891 | 0.877 | 20.76 | 9.81 | 0.81 | 0.895 | 0.882 | 17.94 | 19.60 | 0.10 | 0.886 | 0.872 | 17.24 | 16.96 | 0.22 | |
| Ours | 0.877 | 0.855 | 17.31 | 10.22 | 0.73 | 0.892 | 0.875 | 22.24 | 9.01 | 0.93 | 0.895 | 0.871 | 16.15 | 13.75 | 0.42 | 0.887 | 0.862 | 16.99 | 14.60 | 0.35 | |