{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T21:27:25Z","timestamp":1772659645081,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","funder":[{"name":"Ministry of Economic Development of the Russian Federation","award":["000000C313925P4G0002"],"award-info":[{"award-number":["000000C313925P4G0002"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,27]]},"DOI":"10.1145\/3746027.3758182","type":"proceedings-article","created":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T05:44:48Z","timestamp":1761371088000},"page":"12538-12546","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-1541-3418","authenticated-orcid":false,"given":"Igor","family":"Meleshin","sequence":"first","affiliation":[{"name":"Lomonosov Moscow State University, Moscow, Russian Federation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4896-4418","authenticated-orcid":false,"given":"Anna","family":"Chistyakova","sequence":"additional","affiliation":[{"name":"ISP RAS Research Center for Trusted Artificial Intelligence, Moscow, Russian Federation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1272-5135","authenticated-orcid":false,"given":"Anastasia","family":"Antsiferova","sequence":"additional","affiliation":[{"name":"ISP RAS Research Center for Trusted Artificial Intelligence, Moscow, Russian Federation and MSU Institute for Artificial Intelligence, Moscow, Russian Federation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8893-9340","authenticated-orcid":false,"given":"Dmitriy S.","family":"Vatolin","sequence":"additional","affiliation":[{"name":"MSU Institute for Artificial Intelligence, Moscow, Russian Federation and Lomonosov Moscow State University, Moscow, Russian Federation"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Koushik Biswas Meghana Karri and Ula\u015f Ba\u011fc\u0131. 2023. A Non-monotonic Smooth Activation Function. arXiv:2310.10126 [cs.LG] https:\/\/arxiv.org\/abs\/2310.10126"},{"key":"e_1_3_2_1_2_1","volume-title":"Thomas Massena, and Mathieu Serrurier.","author":"Boissin Thibaut","year":"2025","unstructured":"Thibaut Boissin, Franck Mamalet, Thomas Fel, Agustin Martin Picard, Thomas Massena, and Mathieu Serrurier. 2025. An Adaptive Orthogonal Convolution Scheme for Efficient and Flexible CNN Architectures. arXiv preprint arXiv:2501.07930 (2025)."},{"key":"e_1_3_2_1_3_1","unstructured":"Nicholas Carlini and David Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. arXiv:1608.04644 [cs.CR] https:\/\/arxiv.org\/abs\/1608.04644"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.3390\/technologies12110220"},{"key":"e_1_3_2_1_5_1","unstructured":"Djork-Arn\u00e9 Clevert Thomas Unterthiner and Sepp Hochreiter. 2016. Fast and Accurate Deep Network Learning by Exponential Linear Units (ELUs). arXiv:1511.07289 [cs.LG] https:\/\/arxiv.org\/abs\/1511.07289"},{"key":"e_1_3_2_1_6_1","volume-title":"NIPS 2017: Adversarial Learning Development Set. https:\/\/www.kaggle.com\/datasets\/google-brain\/nips-2017-adversarial-learning-development-set.","author":"Page Competition","year":"2017","unstructured":"Competition Page 2017. NIPS 2017: Adversarial Learning Development Set. https:\/\/www.kaggle.com\/datasets\/google-brain\/nips-2017-adversarial-learning-development-set."},{"key":"e_1_3_2_1_7_1","first-page":"13073","article-title":"Simulating a primary visual cortex at the front of CNNs improves robustness to image perturbations","volume":"33","author":"Dapello Joel","year":"2020","unstructured":"Joel Dapello, Tiago Marques, Martin Schrimpf, Franziska Geiger, David Cox, and James J DiCarlo. 2020. Simulating a primary visual cortex at the front of CNNs improves robustness to image perturbations. Advances in Neural Information Processing Systems 33 (2020), 13073--13087.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_8_1","volume-title":"Simoncelli","author":"Ding Keyan","year":"2020","unstructured":"Keyan Ding, Kede Ma, Shiqi Wang, and Eero P. Simoncelli. 2020. Image Quality Assessment: Unifying Structure and Texture Similarity. CoRR abs\/2004.07728 (2020). https:\/\/arxiv.org\/abs\/2004.07728"},{"key":"e_1_3_2_1_9_1","volume-title":"A guide to convolution arithmetic for deep learning. arXiv preprint arXiv:1603.07285","author":"Dumoulin Vincent","year":"2016","unstructured":"Vincent Dumoulin and Francesco Visin. 2016. A guide to convolution arithmetic for deep learning. arXiv preprint arXiv:1603.07285 (2016)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","unstructured":"Stefan Elfwing Eiji Uchibe and Kenji Doya. 2017. Sigmoid-Weighted Linear Units for Neural Network Function Approximation in Reinforcement Learning. arXiv:1702.03118 [cs.LG] https:\/\/arxiv.org\/abs\/1702.03118","DOI":"10.1016\/j.neunet.2017.12.012"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00404"},{"key":"e_1_3_2_1_12_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_13_1","unstructured":"Alexander Gushchin Khaled Abud Georgii Bychkov Ekaterina Shumitskaya Anna Chistyakova Sergey Lavrushkin Bader Rasheed Kirill Malyshev Dmitriy Vatolin and Anastasia Antsiferova. 2024. Guardians of Image Quality: Benchmarking Defenses Against Adversarial Attacks on Image Quality Metrics. arXiv:2408.01541 [cs.CV] https:\/\/arxiv.org\/abs\/2408.01541"},{"key":"e_1_3_2_1_14_1","unstructured":"Aleksandr Gushchin Anna Chistyakova Vladislav Minashkin Anastasia Antsiferova and Dmitriy Vatolin. 2024. Adversarial purification for no-reference image-quality metrics: applicability study and new methods. arXiv:2404.06957 [cs.CV] https:\/\/arxiv.org\/abs\/2404.06957"},{"key":"e_1_3_2_1_15_1","unstructured":"Dan Hendrycks and Kevin Gimpel. 2023. Gaussian Error Linear Units (GELUs). arXiv:1606.08415 [cs.LG] https:\/\/arxiv.org\/abs\/1606.08415"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.2967829"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Tong Jian Zifeng Wang Yanzhi Wang Jennifer Dy and Stratis Ioannidis. 2022. Pruning Adversarially Robust Neural Networks without Adversarial Examples. arXiv:2210.04311 [cs.LG] https:\/\/arxiv.org\/abs\/2210.04311","DOI":"10.1109\/ICDM54844.2022.00120"},{"key":"e_1_3_2_1_18_1","unstructured":"Artur Jordao Ricardo Kloss Fernando Yamada and William Robson Schwartz. 2019. Pruning Deep Neural Networks using Partial Least Squares. arXiv:1810.07610 [cs.CV] https:\/\/arxiv.org\/abs\/1810.07610"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2020.2975987"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00007"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3552469.3555715"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413804"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02414"},{"key":"e_1_3_2_1_24_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2019. Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv:1706.06083 [stat.ML] https:\/\/arxiv.org\/abs\/1706.06083"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_1_26_1","volume-title":"Duen Horng Chau, and Jason Martin","author":"Peng ShengYun","year":"2023","unstructured":"ShengYun Peng, Weilin Xu, Cory Cornelius, Kevin Li, Rahul Duggal, Duen Horng Chau, and Jason Martin. 2023. RobArch: Designing Robust Architectures against Adversarial Attacks. arXiv:2301.03110 [cs.CV]"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19803-8_21"},{"key":"e_1_3_2_1_28_1","unstructured":"Ekaterina Shumitskaya Anastasia Antsiferova and Dmitriy Vatolin. 2022. Universal Perturbation Attack on Differentiable No-Reference Image- and Video-Quality Metrics. arXiv:2211.00366 [cs.CV] https:\/\/arxiv.org\/abs\/2211.00366"},{"key":"e_1_3_2_1_29_1","unstructured":"Ekaterina Shumitskaya Anastasia Antsiferova and Dmitriy Vatolin. 2023. Fast Adversarial CNN-based Perturbation Attack on No-Reference Image- and Video-Quality Metrics. arXiv:2305.15544 [cs.CV] https:\/\/arxiv.org\/abs\/2305.15544"},{"key":"e_1_3_2_1_30_1","volume-title":"Orthogonalizing convolutional layers with the cayley transform. arXiv preprint arXiv:2104.07167","author":"Trockman Asher","year":"2021","unstructured":"Asher Trockman and J Zico Kolter. 2021. Orthogonalizing convolutional layers with the cayley transform. arXiv preprint arXiv:2104.07167 (2021)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"e_1_3_2_1_32_1","volume-title":"Spatially transformed adversarial examples. arXiv preprint arXiv:1801.02612","author":"Xiao Chaowei","year":"2018","unstructured":"Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song. 2018. Spatially transformed adversarial examples. arXiv preprint arXiv:1801.02612 (2018)."},{"key":"e_1_3_2_1_33_1","volume-title":"Le","author":"Xie Cihang","year":"2021","unstructured":"Cihang Xie, Mingxing Tan, Boqing Gong, Alan Yuille, and Quoc V. Le. 2021. Smooth Adversarial Training. arXiv:2006.14536 [cs.LG] https:\/\/arxiv.org\/abs\/2006.14536"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"e_1_3_2_1_35_1","unstructured":"Weixia Zhang Dingquan Li Xiongkuo Min Guangtao Zhai Guodong Guo Xiaokang Yang and Kede Ma. 2022. Perceptual Attacks of No-Reference Image Quality Models with Human-in-the-Loop. arXiv:2210.00933 [cs.CV] https:\/\/arxiv.org\/abs\/2210.00933"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2018.2886771"}],"event":{"name":"MM '25: The 33rd ACM International Conference on Multimedia","location":"Dublin Ireland","acronym":"MM '25","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 33rd ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3746027.3758182","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T19:15:53Z","timestamp":1765307753000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3746027.3758182"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,27]]},"references-count":36,"alternative-id":["10.1145\/3746027.3758182","10.1145\/3746027"],"URL":"https:\/\/doi.org\/10.1145\/3746027.3758182","relation":{},"subject":[],"published":{"date-parts":[[2025,10,27]]},"assertion":[{"value":"2025-10-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}