The Double-Edged Sword of Data-Driven Super-Resolution: Adversarial Super-Resolution Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Duba-Sullivan, Haley, Young, Steven R., Reid, Emma J.
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914312192262144
author Duba-Sullivan, Haley
Young, Steven R.
Reid, Emma J.
author_facet Duba-Sullivan, Haley
Young, Steven R.
Reid, Emma J.
contents Data-driven super-resolution (SR) methods are often integrated into imaging pipelines as preprocessing steps to improve downstream tasks such as classification and detection. However, these SR models introduce a previously unexplored attack surface into imaging pipelines. In this paper, we present AdvSR, a framework demonstrating that adversarial behavior can be embedded directly into SR model weights during training, requiring no access to inputs at inference time. Unlike prior attacks that perturb inputs or rely on backdoor triggers, AdvSR operates entirely at the model level. By jointly optimizing for reconstruction quality and targeted adversarial outcomes, AdvSR produces models that appear benign under standard image quality metrics while inducing downstream misclassification. We evaluate AdvSR on three SR architectures (SRCNN, EDSR, SwinIR) paired with a YOLOv11 classifier and demonstrate that AdvSR models can achieve high attack success rates with minimal quality degradation. These findings highlight a new model-level threat for imaging pipelines, with implications for how practitioners source and validate models in safety-critical applications.
format Preprint
id arxiv_https___arxiv_org_abs_2602_07251
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle The Double-Edged Sword of Data-Driven Super-Resolution: Adversarial Super-Resolution Models
Duba-Sullivan, Haley
Young, Steven R.
Reid, Emma J.
Computer Vision and Pattern Recognition
Artificial Intelligence
Data-driven super-resolution (SR) methods are often integrated into imaging pipelines as preprocessing steps to improve downstream tasks such as classification and detection. However, these SR models introduce a previously unexplored attack surface into imaging pipelines. In this paper, we present AdvSR, a framework demonstrating that adversarial behavior can be embedded directly into SR model weights during training, requiring no access to inputs at inference time. Unlike prior attacks that perturb inputs or rely on backdoor triggers, AdvSR operates entirely at the model level. By jointly optimizing for reconstruction quality and targeted adversarial outcomes, AdvSR produces models that appear benign under standard image quality metrics while inducing downstream misclassification. We evaluate AdvSR on three SR architectures (SRCNN, EDSR, SwinIR) paired with a YOLOv11 classifier and demonstrate that AdvSR models can achieve high attack success rates with minimal quality degradation. These findings highlight a new model-level threat for imaging pipelines, with implications for how practitioners source and validate models in safety-critical applications.
title The Double-Edged Sword of Data-Driven Super-Resolution: Adversarial Super-Resolution Models
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2602.07251