Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Compression as an Adversarial Amplifier Through Decision Space Reduction

About

Image compression is a ubiquitous component of modern visual pipelines, routinely applied by social media platforms and resource-constrained systems prior to inference. Despite its prevalence, the impact of compression on adversarial robustness remains poorly understood. We study a previously unexplored adversarial setting in which attacks are applied directly in compressed representations, and show that compression can act as an adversarial amplifier for deep image classifiers. Under identical nominal perturbation budgets, compression-aware attacks are substantially more effective than their pixel-space counterparts. We attribute this effect to decision space reduction, whereby compression induces a non-invertible, information-losing transformation that contracts classification margins and increases sensitivity to perturbations. Extensive experiments across standard benchmarks and architectures support our analysis and reveal a critical vulnerability in compression-in-the-loop deployment settings. Code will be released.

Lewis Evans, Harkrishan Jandu, Zihan Ye, Yang Lu, Shreyank N Gowda• 2026

Related benchmarks

TaskDatasetResultRank
Image ClassificationImageNet 1.0 (val)
Accuracy33.63
48
Image ClassificationCIFAR-100
Accuracy16.66
36
Image ClassificationCIFAR-10 (test)
Accuracy18.11
36
Showing 3 of 3 rows

Other info

Follow for update