Enhancing Transferable Adversarial Attacks on Vision Transformers through Gradient Normalization Scaling and High-Frequency Adaptation
Zhiyu Zhu, Xinyi Wang, Zhibo Jin, Jiayu Zhang, Huaming Chen
Abstract
Vision Transformers (ViTs) have been widely used in various domains. Similar to Convolutional Neural Networks (CNNs), ViTs are prone to the impacts of adversarial samples, raising security concerns in real-world applications. As one of the most effective black-box attack methods, transferable attacks can generate adversarial samples on surrogate models to directly attack the target model without accessing the parameters. However, due to the distinct internal structures of ViTs and CNNs, adversarial samples constructed by traditional transferable attack methods may not be applicable to ViTs. Therefore, it is imperative to propose more effective transferability attack methods to unveil latent vulnerabilities in ViTs. Existing methods have found that applying gradient regularization to extreme gradients across different functional regions in the transformer structure can enhance sample transferability. However, in practice, substantial gradient disparities exist even within the same functional region across different layers. Furthermore, we find that mild gradients therein are the main culprits behind reduced transferability. In this paper, we introduce a novel Gradient Normalization Scaling method for fine-grained gradient editing to enhance the transferability of adversarial attacks on ViTs. More importantly, we highlight that ViTs, unlike traditional CNNs, exhibit distinct attention regions in the frequency domain. Leveraging this insight, we delve into exploring the frequency domain to further enhance the algorithm's transferability. Through extensive experimentation on various ViT variants and traditional CNN models, we substantiate that the new approach achieves state-of-the-art performance, with an average performance improvement of 33.54% and 42.05% on ViT and CNN models, respectively. Our code is available at: https://github.com/LMBTough/GNS-HFA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 145f2552-6e60-41c0-a601-a8cfae3a4084Cited by top-tier papers4
- MIP against Agent: Malicious Image Patches Hijacking Multimodal OS AgentsLukas Aichberger, Alasdair Paren, Guohao Li, Philip H. S. Torr et al.NeurIPS 2025 · 12 citations
- Harnessing the Computation Redundancy in ViTs to Boost Adversarial TransferabilityJiani Liu, Zhiyuan Wang, Zeliang Zhang, Chao Huang et al.NeurIPS 2025 · 7 citations
- Improving Adversarial Transferability on Vision Transformers via Forward Propagation RefinementYuchen Ren, Zhengyu Zhao, Chenhao Lin, Bo Yang et al.CVPR 2025
- Boosting Adversarial Transferability via Ensemble Non-AttentionYipeng Zou, Qin Liu, Jie Wu, Yu Peng et al.AAAI 2026
Builds on18
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Training data-efficient image transformers & distillation through attentionHugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa et al.ICML 2021 · 8,974 citations
- Transformer in TransformerKai Han, An Xiao, Enhua Wu, Jianyuan Guo et al.NeurIPS 2021 · 2,148 citations
- CrossViT: Cross-Attention Multi-Scale Vision Transformer for Image ClassificationChun-Fu (Richard) Chen, Quanfu Fan, Rameswar PandaICCV 2021 · 2,072 citations
- Going deeper with Image TransformersHugo Touvron, Matthieu Cord, Alexandre Sablayrolles, Gabriel Synnaeve et al.ICCV 2021 · 1,279 citations
Related papers
- Transferable Adversarial Attacks on Vision Transformers with Token Gradient RegularizationJianping Zhang, Yizhan Huang, Weibin Wu, Michael R. LyuCVPR 2023
- Boosting the Transferability of Adversarial Attack on Vision Transformer with Adaptive Token TuningDi Ming, Peng Ren, Yunlong Wang, Xin FengNeurIPS 2024 · 24 citations
- On Improving Adversarial Transferability of Vision TransformersMuzammal Naseer, Kanchana Ranasinghe, Salman Khan, Fahad Shahbaz Khan et al.ICLR 2022 · 111 citations
- Improving the Adversarial Transferability of Vision Transformers with Virtual Dense ConnectionJianping Zhang, Yizhan Huang, Zhuoer Xu, Weibin Wu et al.AAAI 2024 · 22 citations
- Attacking Transformers with Feature Diversity Adversarial PerturbationChenxing Gao, Hang Zhou, Junqing Yu, Yuteng Ye et al.AAAI 2024 · 9 citations
