Scholay

学术搜索 · AI 审稿 · LaTeX 协作

Compression as an Adversarial Amplifier Through Decision Space Reduction

作者:Lewis Evans, Harkrishan Jandu, Zihan Ye, Yang Lu, Shreyank N Gowda · 发表于:arXiv (Cornell University) · 年份:2026 · DOI:10.48550/arxiv.2604.06954 · 研究领域:Adversarial Robustness in Machine Learning、Advanced Image Processing Techniques、Digital Media Forensic Detection

Image compression is a ubiquitous component of modern visual pipelines, routinely applied by social media platforms and resource-constrained systems prior to inference. Despite its prevalence, the impact of compression on adversarial robustness remains poorly understood. We study a previously unexplored adversarial setting in which attacks are applied directly in compressed representations, and show that compression can act as an adversarial amplifier for deep image classifiers. Under identical nominal perturbation budgets, compression-aware attacks are substantially more effective than their pixel-space counterparts. We attribute this effect to decision space reduction, whereby compression induces a non-invertible, information-losing transformation that contracts classification margins and increases sensitivity to perturbations. Extensive experiments across standard benchmarks and architectures support our analysis and reveal a critical vulnerability in compression-in-the-loop deployment settings. Code will be released.