{"id":"https://openalex.org/W4415536197","doi":"https://doi.org/10.1145/3746027.3758182","title":"Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations","display_name":"Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations","publication_year":2025,"publication_date":"2025-10-25","ids":{"openalex":"https://openalex.org/W4415536197","doi":"https://doi.org/10.1145/3746027.3758182"},"language":null,"primary_location":{"id":"doi:10.1145/3746027.3758182","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3746027.3758182","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5120131165","display_name":"Igor Meleshin","orcid":null},"institutions":[{"id":"https://openalex.org/I19880235","display_name":"Lomonosov Moscow State University","ror":"https://ror.org/010pmpe69","country_code":"RU","type":"education","lineage":["https://openalex.org/I19880235"]}],"countries":["RU"],"is_corresponding":true,"raw_author_name":"Igor Meleshin","raw_affiliation_strings":["Lomonosov Moscow State University, Moscow, Russian Federation"],"raw_orcid":"https://orcid.org/0009-0009-1541-3418","affiliations":[{"raw_affiliation_string":"Lomonosov Moscow State University, Moscow, Russian Federation","institution_ids":["https://openalex.org/I19880235"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103245934","display_name":"Anna Chistyakova","orcid":"https://orcid.org/0000-0003-4896-4418"},"institutions":[{"id":"https://openalex.org/I4210100255","display_name":"Beijing Academy of Artificial Intelligence","ror":"https://ror.org/016a74861","country_code":"CN","type":"other","lineage":["https://openalex.org/I4210100255"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Anna Chistyakova","raw_affiliation_strings":["ISP RAS Research Center for Trusted Artificial Intelligence, Moscow, Russian Federation"],"raw_orcid":"https://orcid.org/0000-0003-4896-4418","affiliations":[{"raw_affiliation_string":"ISP RAS Research Center for Trusted Artificial Intelligence, Moscow, Russian Federation","institution_ids":["https://openalex.org/I4210100255"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086393377","display_name":"Anastasia Antsiferova","orcid":"https://orcid.org/0000-0002-1272-5135"},"institutions":[{"id":"https://openalex.org/I4210164862","display_name":"Artificial Intelligence in Medicine (Canada)","ror":"https://ror.org/05p590m36","country_code":"CA","type":"company","lineage":["https://openalex.org/I4210164862"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Anastasia Antsiferova","raw_affiliation_strings":["ISP RAS Research Center for Trusted Artificial Intelligence, Moscow, Russian Federation and MSU Institute for Artificial Intelligence, Moscow, Russian Federation"],"raw_orcid":"https://orcid.org/0000-0002-1272-5135","affiliations":[{"raw_affiliation_string":"ISP RAS Research Center for Trusted Artificial Intelligence, Moscow, Russian Federation and MSU Institute for Artificial Intelligence, Moscow, Russian Federation","institution_ids":["https://openalex.org/I4210164862"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5020940244","display_name":"Dmitriy Vatolin","orcid":"https://orcid.org/0000-0002-8893-9340"},"institutions":[{"id":"https://openalex.org/I19880235","display_name":"Lomonosov Moscow State University","ror":"https://ror.org/010pmpe69","country_code":"RU","type":"education","lineage":["https://openalex.org/I19880235"]}],"countries":["RU"],"is_corresponding":false,"raw_author_name":"Dmitriy S. Vatolin","raw_affiliation_strings":["MSU Institute for Artificial Intelligence, Moscow, Russian Federation and Lomonosov Moscow State University, Moscow, Russian Federation"],"raw_orcid":"https://orcid.org/0000-0002-8893-9340","affiliations":[{"raw_affiliation_string":"MSU Institute for Artificial Intelligence, Moscow, Russian Federation and Lomonosov Moscow State University, Moscow, Russian Federation","institution_ids":["https://openalex.org/I19880235"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5120131165"],"corresponding_institution_ids":["https://openalex.org/I19880235"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.15573304,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"12538","last_page":"12546"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9969000220298767,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8962000012397766},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.847599983215332},{"id":"https://openalex.org/keywords/perception","display_name":"Perception","score":0.41290000081062317},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.3847000002861023},{"id":"https://openalex.org/keywords/quality","display_name":"Quality (philosophy)","score":0.33469998836517334},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3027999997138977}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8962000012397766},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.847599983215332},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6603999733924866},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5547999739646912},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.41290000081062317},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.3847000002861023},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.38029998540878296},{"id":"https://openalex.org/C2779530757","wikidata":"https://www.wikidata.org/wiki/Q1207505","display_name":"Quality (philosophy)","level":2,"score":0.33469998836517334},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3027999997138977},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.28839999437332153},{"id":"https://openalex.org/C78548338","wikidata":"https://www.wikidata.org/wiki/Q2493","display_name":"Data compression","level":2,"score":0.26980000734329224},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.26600000262260437},{"id":"https://openalex.org/C55020928","wikidata":"https://www.wikidata.org/wiki/Q3813865","display_name":"Image quality","level":3,"score":0.25440001487731934},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.25440001487731934},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.2531999945640564}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3746027.3758182","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3746027.3758182","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W2133665775","https://openalex.org/W2543927648","https://openalex.org/W2905544033","https://openalex.org/W2962785568","https://openalex.org/W2962834855","https://openalex.org/W3002992380","https://openalex.org/W3007122219","https://openalex.org/W3047945973","https://openalex.org/W3194280054","https://openalex.org/W3208785972","https://openalex.org/W4297330561","https://openalex.org/W4312626912","https://openalex.org/W4320060435","https://openalex.org/W4402727691","https://openalex.org/W4404074579"],"related_works":[],"abstract_inverted_index":{"Image":[0],"Quality":[1],"Assessment":[2],"(IQA)":[3],"models":[4,33,76,102],"are":[5,34,51],"increasingly":[6],"relied":[7],"upon":[8],"to":[9,21,80,84,103,111,129,160,176],"evaluate":[10],"image":[11],"quality":[12],"in":[13,74,169],"real-world":[14],"systems":[15],"---":[16,56,132],"from":[17,114,171],"compression":[18],"and":[19,23,45,133,140],"enhancement":[20],"generation":[22],"streaming.":[24],"Yet":[25],"their":[26,108],"adoption":[27],"brings":[28],"a":[29,91,145,167],"fundamental":[30],"risk:":[31],"these":[32],"inherently":[35],"unstable.":[36],"Adversarial":[37],"manipulations":[38],"can":[39],"easily":[40],"fool":[41],"them,":[42],"inflating":[43],"scores":[44],"undermining":[46],"trust.":[47],"Traditionally,":[48],"such":[49],"vulnerabilities":[50],"addressed":[52],"through":[53,138,174,179],"data-driven":[54],"defenses":[55],"adversarial":[57,151,155],"retraining,":[58],"regularization,":[59],"or":[60,157],"input":[61],"purification.":[62],"But":[63],"what":[64],"if":[65,72],"this":[66,87,120],"is":[67,77,144],"the":[68,115,127,136,161],"wrong":[69],"lens?":[70],"What":[71],"robustness":[73,94,173],"perceptual":[75],"not":[78],"something":[79,83],"learn":[81],"but":[82],"design?":[85],"In":[86],"work,":[88],"we":[89,106],"propose":[90],"provocative":[92],"idea:":[93],"as":[95],"an":[96],"architectural":[97],"prior.":[98],"Rather":[99],"than":[100],"training":[101,156],"resist":[104],"perturbations,":[105],"reshape":[107],"internal":[109],"structure":[110],"suppress":[112],"sensitivity":[113],"ground":[116],"up.":[117],"We":[118],"achieve":[119],"by":[121],"enforcing":[122],"orthogonal":[123],"information":[124],"flow,":[125],"constraining":[126],"network":[128],"norm-preserving":[130],"operations":[131],"further":[134],"stabilizing":[135],"system":[137],"pruning":[139],"fine-tuning.":[141],"The":[142],"result":[143],"robust":[146],"IQA":[147],"architecture":[148],"that":[149],"withstands":[150],"attacks":[152],"without":[153],"requiring":[154],"significant":[158],"changes":[159],"original":[162],"model.":[163],"This":[164],"approach":[165],"suggests":[166],"shift":[168],"perspective:":[170],"optimizing":[172],"data":[175],"engineering":[177],"it":[178],"design.":[180]},"counts_by_year":[],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-25T00:00:00"}
