Papers › Backdoor Attacks against No-Reference Image Quality Assessment Models via a Scalable Trigger

Backdoor Attacks against No-Reference Image Quality Assessment Models via a Scalable Trigger

10 Dec 2024arXiv:2412.07277archive 2025-07-28

Yi Yu, Song Xia, Xun Lin, Wenhan Yang, Shijian Lu, Yap-Peng Tan, Alex Kot

No-Reference Image Quality Assessment (NR-IQA), responsible for assessing the quality of a single input image without using any reference, plays a critical role in evaluating and optimizing computer vision systems, e.g., low-light enhancement. Recent research indicates that NR-IQA models are susceptible to adversarial attacks, which can significantly alter predicted scores with visually imperceptible perturbations. Despite revealing vulnerabilities, these attack methods have limitations, including high computational demands, untargeted manipulation, limited practical utility in white-box scenarios, and reduced effectiveness in black-box scenarios. To address these challenges, we shift our focus to another significant threat and present a novel poisoning-based backdoor attack against NR-IQA (BAIQA), allowing the attacker to manipulate the IQA model's output to any desired target value by simply adjusting a scaling coefficient α for the trigger. We propose to inject the trigger in the discrete cosine transform (DCT) domain to improve the local invariance of the trigger for countering trigger diminishment in NR-IQA models due to widely adopted data augmentations. Furthermore, the universal adversarial perturbations (UAP) in the DCT space are designed as the trigger, to increase IQA model susceptibility to manipulation and improve attack effectiveness. In addition to the heuristic method for poison-label BAIQA (P-BAIQA), we explore the design of clean-label BAIQA (C-BAIQA), focusing on α sampling and image data refinement, driven by theoretical insights we reveal. Extensive experiments on diverse datasets and various NR-IQA models demonstrate the effectiveness of our attacks. Code can be found at https://github.com/yuyi-sd/BAIQA.

PaperPDFCodeCode Syntology ran

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

For agents, Syntology's MCP tool lists every function and class Syntology harvested from this paper and whether it ran (how to connect): get_harvested_code_for_paper(arxiv_id="2412.07277")

Code

Syntology Ran 3 of 12 code samples harvested from 1 repository linked to this paper; 9 have no recorded run. Of those that ran: 1 ran · honoured contract; 2 ran · fixture could not drive it.

By repository: official repository: 12 samples from 1 repository, 3 ran. The run record, sample by sample. “Ran” means executed on a synthesized input, not that the code is correct or reproduces the paper.

yuyi-sd/baiqa officialmentioned in papermentioned on GitHubpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

12 samples harvested; 3 ran; 1 honoured the contract we drafted; 9 have no recorded run. Read from Syntology's graph 2026-09-24; that is when this build read the record, not when the samples ran.

1ran · honoured contract
2ran · fixture could not drive it
9unverified

Licence: 12 of the 12 samples are pointer only, meaning Syntology does not serve that copy's text. This page shows no code text for any sample; each one links to its file in the repository.

Harvested from yuyi-sd/baiqa. “Ran” means the sample executed on a synthesized input. It does not mean the output is correct, and nothing here reproduces the paper's results. “Honoured” and “violated” refer to a contract Syntology drafted from the code itself; “our draft was wrong” and “fixture could not drive it” are failures of Syntology's instrument, not of the code.

Each sample ends with its code_sha256, Syntology's identity for that exact code. An agent fetches the stored sample with Syntology's MCP tool get_code(code_sha256="…") (how to connect); click an identity to copy that call.

Repository labels, per sample. official repository: The archive marks this repository official for the paper. named in the paper: The archive records that the paper mentions this repository; it is not marked official. community (archive-listed): In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper. found in paper text by Syntology: Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted. community: Not in the archive's code links for this paper; a community repository Syntology harvested. Samples from a repository marked official are listed first. Licence labels name the repository's licence as recorded at harvest. “Pointer only” means Syntology does not serve that copy's text, for one of four reasons: no licence file was found; the licence was not identified; the licence is recorded as permissive but that copy's record is not marked cleared; or the licence is outside the permissive list Syntology serves text under (MIT, Apache-2.0, BSD and similar). Some licences outside that list permit redistribution, such as WTFPL, and GPL-3.0 under its conditions; they are simply not on the list. Hover a licence label for the reason. File links open the file on GitHub at the default branch, which may have changed since the harvest.

window_partition yuyi-sd/baiqa/DBCNN.py official repository ran · fixture could not drive it fingerprinted no licence file found · pointer only · 144d10b49baeb8a6 · report
dct yuyi-sd/baiqa/network.py official repository ran · fixture could not drive it fingerprinted no licence file found · pointer only · a480f97ef83e404c · report
pil_loader yuyi-sd/baiqa/PGD_demo.py official repository ran · honoured contract no licence file found · pointer only · f321f54723433661 · report
IQA_untarget_UAP_DCT yuyi-sd/baiqa/UAP_DCT_demo.py official repository unverified no licence file found · pointer only · 5ade060cc526db4a · report
PGD_IQA_target yuyi-sd/baiqa/PGD_demo.py official repository unverified no licence file found · pointer only · 0bc77414a30afac5 · report
SPSP yuyi-sd/baiqa/DBCNN.py official repository unverified no licence file found · pointer only · 8543d8c6b629c8da · report
dct1 yuyi-sd/baiqa/network.py official repository unverified no licence file found · pointer only · c3f2ecb9e39faba4 · report
find_nearest yuyi-sd/baiqa/HyperIQASolver_multi_v6.py official repository unverified no licence file found · pointer only · a82dce4b3a95f2b1 · report
idct1 yuyi-sd/baiqa/network.py official repository unverified no licence file found · pointer only · e2f1e6b54f8342d0 · report
norm yuyi-sd/baiqa/PGD_demo.py official repository unverified no licence file found · pointer only · e19bee20080fc1b7 · report
norm_loss_with_normalization yuyi-sd/baiqa/DBCNN.py official repository unverified no licence file found · pointer only · 0abda7a5fadc62f8 · report
resnet50_backbone yuyi-sd/baiqa/models.py official repository unverified no licence file found · pointer only · b2cad251a2b63c16 · report

Tasks

Backdoor AttackImage Quality AssessmentNR-IQANo-Reference Image Quality Assessment

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Methods

Discrete Cosine TransformFocus

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections