← Latest papers
💻 computer science

SCOOTER: A Human Evaluation Framework for Unrestricted Adversarial Examples

This paper introduces SCOOTER, an open-source, statistically powered framework and benchmark dataset designed to evaluate unrestricted adversarial examples through large-scale human studies, revealing that current attacks often fail to achieve human-perceived imperceptibility and highlighting the misalignment between automated vision systems and human perception.

Original authors: Dren Fazlija, Monty-Maximilian Zühlke, Johanna Schrader, Arkadij Orlov, Clara Stein, Iyiola E. Olatunji, Daniel Kudenko

Published 2026-05-15
📖 5 min read🧠 Deep dive

Original authors: Dren Fazlija, Monty-Maximilian Zühlke, Johanna Schrader, Arkadij Orlov, Clara Stein, Iyiola E. Olatunji, Daniel Kudenko

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: The "Magic Trick" That Isn't Magic

Imagine you have a computer that is really good at identifying animals in photos. It can tell a cat from a dog instantly. But what if someone could trick the computer into thinking a cat is a dog, without you (the human) noticing anything weird about the photo?

In the world of AI security, these tricked photos are called Adversarial Examples.

  • The Old Way (Restricted): Imagine someone adding a tiny, invisible layer of static noise to a photo. It's like adding a single grain of sand to a beach. The computer gets confused, but humans can't see the sand.
  • The New Way (Unrestricted): Imagine someone changing the color of the cat's fur from orange to blue, or swapping the dog's ears for bunny ears. These changes are big enough to be seen, but the attacker claims they are "natural" enough that a human wouldn't notice them as fake.

The problem is: How do we know if these "big changes" are actually invisible to humans?

The Problem: "Trust Me, It Looks Real"

For years, researchers have been creating these "Unrestricted" attacks. They claim, "Look, my AI tricked the computer, and a human would never know the difference!"

But until now, there was no reliable way to prove this.

  • Some researchers just asked a few friends, "Does this look fake?"
  • Others used computer programs to measure "image quality," but computers are bad at guessing what humans actually see.
  • It was like a magician claiming a trick is "invisible" because he didn't have a camera to prove otherwise.

The Solution: Enter "Scooter"

The authors built a new system called Scooter (Systemizing Confusion Over Observations To Evaluate Realness). Think of Scooter as a rigorous, scientific "Taste Test" for AI images.

Instead of asking one person, Scooter organizes a massive, structured experiment with hundreds of people to get a statistically solid answer. Here is how it works, step-by-step:

1. The "Vision Check" (Preliminary Checks)

Before anyone can judge the images, they have to prove they can actually see colors.

  • The Analogy: Imagine a wine tasting competition. You wouldn't let someone judge the wine if they were colorblind and couldn't tell red from green.
  • The Test: Participants take a colorblindness test (like the famous Ishihara plates with hidden numbers) and a "did you read the instructions?" test. If they fail, they are out. This ensures the judges are sharp.

2. The "Blind Taste Test" (The Main Study)

Participants are shown 106 images. They don't know which are real and which are "tricked" by the AI.

  • The Scale: Instead of just saying "Real" or "Fake," they rate the image on a scale from -2 (Definitely Fake) to +2 (Definitely Real).
  • The Trap: The researchers sneak in "fake" images that are obviously fake (like a picture with a giant red filter) to see if the participant is paying attention. If you say a bright red filter looks real, you are flagged as a bad judge.

3. The "Math Check" (Statistical Analysis)

This is the most important part. The researchers don't just look at the average score. They use a special math test called TOST (Two-One-Sided Tests).

  • The Analogy: Imagine you are trying to prove that two coins are identical. You don't just flip them and hope they land the same. You have to prove that the difference between them is so small that it doesn't matter.
  • The Result: If the "tricked" images are rated significantly lower than the real images, the math proves the attack failed to be invisible.

What They Found: The "Magic" Wasn't That Good

The authors tested six different "Unrestricted" attacks (three that change colors, and three that use advanced AI generators).

The Shocking Result:

  • Humans could easily spot the fakes.
  • In every single test, the "tricked" images were rated significantly lower than the real ones.
  • Even the most sophisticated attacks (the ones using advanced AI generators) were obvious to human eyes.
  • The Takeaway: The claim that "humans can't tell the difference" is false. These attacks are not imperceptible.

The "Robot Judge" Experiment

The researchers also asked a super-smart AI (GPT-4o) to look at the images and guess if they were real.

  • The Result: The AI was better than a human at spotting some tricks, but it still got confused by others.
  • The Lesson: Even the smartest AI models today struggle to perfectly mimic human perception. You can't just ask a computer to check if an image looks real; you need real humans.

The "Scoreboard" (Objective Metrics)

The paper also looked at how computer programs (like FID or TOPIQ) rate these images.

  • The Problem: The computer programs often gave high scores to the "tricked" images, saying, "Wow, this looks great!"
  • The Reality: Humans looked at those same images and said, "That looks weird."
  • The Conclusion: We cannot trust computer metrics to tell us if an image looks real to a human. We need human judges.

Summary

Scooter is a new, open-source toolkit that forces researchers to prove their "invisible" AI attacks are actually invisible by using real humans in a scientifically rigorous way.

The main discovery? The "invisible" attacks everyone was bragging about? They aren't invisible. Humans can see them, and the math proves it. The paper provides the tools (code, datasets, and guidelines) so that in the future, no one can claim an attack is "imperceptible" without showing the human data to back it up.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →