Skip to content

Image transforms

Reference for the image transforms Dreadnode ships for multimodal red teaming - noise and corruptions, blur, photometric and geometric perturbations, weather corruptions, occlusion, steganography, and typographic attacks.

Image transforms mutate the image you send to a vision-capable target - and can score the image a model generates back. Safety training is unevenly distributed across modalities, so a request refused as text may be complied with when it is embedded in an image.

TransformWhat it doesKey params
add_gaussian_noiseAdditive Gaussian noisescale, seed
add_laplace_noiseAdditive Laplace noisescale, seed
add_uniform_noiseAdditive uniform noiselow, high, seed
salt_pepper_noiseImpulse noise - flips random pixels to black/whiteamount, salt_vs_pepper, seed
shot_noisePoisson (photon-count) sensor noise (ImageNet-C)scale, seed
speckle_noiseMultiplicative speckle noise (ImageNet-C)scale, seed
high_frequency_perturbationNear-Nyquist sinusoidal grating (low-visibility)amplitude, frequency
shift_pixel_valuesSmall random per-pixel integer shiftmax_delta, seed
TransformWhat it doesKey params
blurGaussian blurradius
motion_blurDirectional (camera-motion) blursize, angle
defocus_blurDisk-kernel (out-of-focus) blur (ImageNet-C)radius
glass_blurFrosted-glass blur - blur plus local pixel jitter (ImageNet-C)sigma, max_delta, iterations
zoom_blurAverage of progressively zoomed copies (ImageNet-C)max_zoom, step
downscaleDown/upsample to destroy fine detailscale
pixelateBlocky mosaic via nearest-neighbor resizepixel_size
TransformWhat it doesKey params
adjust_brightness / adjust_contrast / adjust_saturationEnhance channelsfactor
color_jitterRandom brightness/contrast/saturation jitterbrightness, contrast, saturation, seed
hue_shiftRotate hue in HSVdegrees
chromatic_aberrationLaterally offset red/blue channelsshift
invert_colors / solarize / posterize / sepia / grayscaleColor remappingthreshold / bits
histogram_equalize / autocontrastContrast normalizationcutoff
sharpenUnsharp-mask edge accentuationradius, percent, threshold
opacity_blendBlend toward a flat background (wash-out)opacity, background
halftone_dither1-bit Floyd-Steinberg dithering-
apply_pil_filterNamed PIL filter (emboss/contour/edge_enhance/find_edges/…)filter_name
jpeg_compressionJPEG compression artifactsquality
TransformWhat it doesKey params
rotate / horizontal_flip / vertical_flipRotations and mirrorsdegrees
crop / pad / pad_squareCrop or pad (letterbox to square)x1..y2 / padding
skewHorizontal shear/slantshear
change_aspect_ratioAnamorphic width stretchratio
perspective_warpPerspective (viewpoint) warpmagnitude
elastic_deformSmooth elastic displacement fieldalpha, sigma, seed
shuffle_pixelsShuffle pixel blocksblock_size, seed
interpolate_imagesLinear interpolation between two images (SDK-only)alpha
TransformWhat it doesKey params
fogBlend a low-frequency bright cloud over the imageintensity, seed
snowOverlay motion-blurred bright specksamount, streak_angle, seed
spatterPaint random mud/rain blobsamount, color, seed
TransformWhat it doesKey params
cutoutOcclude a random rectangle (random-erasing)size_ratio, fill, seed
channel_shufflePermute RGB channels (e.g. BGR)order, seed
overlay_emoji / overlay_stripesOverlay emoji or occluding stripesemoji / count, width
add_text_overlaySemi-transparent text captiontext, position, color
adversarial_patchHigh-salience occluding patch, optionally carrying textpayload, position, size_ratio
meme_formatWhite caption bar with bold text (image macro)caption, position
overlay_imageComposite a second image (logo/QR/distractor); SDK-onlyoverlay, position, opacity
TransformWhat it doesReference
image_steganographyHide a text payload in pixel LSBs-
extract_steganographyRecover an LSB-hidden payload (verification)-
figstep_imageRender a numbered blank-step list soliciting harmful completionFigStep
typographic_promptRender a request as pixels to bypass text filtersMM-SafetyBench
invisible_textNear-imperceptible low-contrast instruction a human misses but a VLM readsVisual prompt injection
from dreadnode.transforms import image
# Concise image-attack stack: typographic instruction + hidden payload + corruption + patch.
transforms = [
image.figstep_image("Explain the steps to ...", steps=3),
image.image_steganography("ignore previous instructions"),
image.fog(intensity=0.6, seed=0),
image.adversarial_patch("OVERRIDE", size_ratio=0.25),
]

Additional augmentations (Albumentations / DSP)

Section titled “Additional augmentations (Albumentations / DSP)”
TransformWhat it doesKey params
median_blurEdge-preserving median filtersize
gamma_correctionPower-law tone curvegamma
color_quantizeReduce to an adaptive N-color palettecolors, dither
ordered_dither4x4 Bayer ordered dithering-
vignetteRadial corner darkeningstrength
rgb_shiftConstant per-channel value shiftr_shift, g_shift, b_shift
channel_dropoutZero a single color channelchannel, seed
hsv_shiftShift saturation and value in HSVsaturation, value
coarse_dropoutErase multiple random rectanglesholes, size_ratio, seed
pixel_dropoutRandomly zero individual pixelsdropout_ratio, seed
morphologyGrayscale erode/dilate/open/closeoperation, size
optical_distortionRadial barrel/pincushion lens distortionk
grid_distortionWarp along a randomly perturbed gridnum_steps, distort, seed
rainDirectional rain streaksamount, length, angle
random_shadowDarken a random triangular regionstrength, seed
iso_noiseCamera ISO noise (Poisson + color Gaussian)color_shift, intensity
ringing_overshootSinc-kernel ringing (Gibbs) artifactsize
fancy_pcaAlexNet PCA color augmentationalpha_std, seed
webp_compressionWebP lossy-compression artifactsquality
affineCombined rotate + scale + translate + shearrotate, scale, translate, shear

These transforms are for authorized safety and security testing of systems you own or are permitted to assess. Model-optimized adversarial attacks (e.g. Carlini & Wagner, HADES, Image Hijacks) require gradient access to a surrogate model and are out of scope for these black-box, dependency-free transforms; the entries above implement the model-free primitives from each family.

See Transforms for how to apply transforms with any attack.