Transferable and Imperceptible Attacks
Across CNN- and Transformer-based target models, SEGA preserves the visual appearance of the source image while producing adversarial examples with stronger cross-model transfer.
No-reference image quality assessment models are vulnerable to adversarial examples, yet transfer-based black-box attacks remain difficult because different architectures learn dissimilar quality representations. SEGA improves transferable attacks through Gaussian-smoothed gradient estimation, source-model gradient ensembling, and a perturbation filter that suppresses visually conspicuous changes. Experiments across multiple NR-IQA models and datasets demonstrate strong transferability together with competitive perceptual quality.
Across CNN- and Transformer-based target models, SEGA preserves the visual appearance of the source image while producing adversarial examples with stronger cross-model transfer.
The two filtering masks remove perturbations in visually sensitive or semantically unhelpful regions. Ablations show how smoothing strength, sampling count, and ensemble size balance transferability and efficiency.
@article{liu2026sega,
title={{SEGA}: A Transferable Signed Ensemble Gaussian Black-Box Attack against No-Reference Image Quality Assessment Models},
author={Liu, Yujia and Li, Dingquan and Li, Zhixuan and Huang, Tiejun},
journal={IEEE Transactions on Pattern Analysis and Machine Intelligence},
year={2026},
publisher={IEEE}
}