Defending Backdoor Attacks on Vision Transformer via Patch Processing
Khoa D. Doan, Yingjie Lao, Peng Yang, Ping Li
Abstract
1 Vision Transformers (ViTs) have a radically different architecture with significantly less inductive bias than Convolutional Neural Networks. Along with the improvement in performance, security and robustness of ViTs are also of great importance to study. In contrast to many recent works that exploit the robustness of ViTs against adversarial examples, this paper investigates a representative causative attack, i.e., backdoor. We first examine the vulnerability of ViTs against various backdoor attacks and find that ViTs are also quite vulnerable to existing attacks. However, we observe that the clean-data accuracy and backdoor attack success rate of ViTs respond distinctively to patch transformations before the positional encoding. Then, based on this finding, we propose an effective method for ViTs to defend both patch-based and blendingbased trigger backdoor attacks via patch processing. The performances are evaluated on several benchmark datasets, including CIFAR10, GTSRB, and TinyImageNet, which show the proposed novel defense is very successful in mitigating backdoor attacks for ViTs. To the best of our knowledge, this paper presents the first defensive strategy that utilizes a unique characteristic of ViTs against backdoor attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 452f9603-4d8b-43f8-a59e-d2dc2c0be9a3Cited by top-tier papers9
- Marksman Backdoor: Backdoor Attacks with Arbitrary Target ClassKhoa D. Doan, Yingjie Lao, Ping LiNeurIPS 2022 · 63 citations
- Attention-Imperceptible Backdoor Attacks on Vision TransformersZhishen Wang, Rui Wang, Lihua JingAAAI 2025 · 5 citations
- BAM-ICL: Causal Hijacking In-Context Learning with Budgeted Adversarial ManipulationRui Chu, Bingyin Zhao, Hanling Jiang, Shuchin Aeron et al.NeurIPS 2025 · 4 citations
- DF-LoGiT: Data-Free Logic-Gated Backdoor Attacks in Vision TransformersXiaozuo Shen, Yifei Cai, RUI NING, Chunsheng Xin et al.ICML 2026 · 2 citations
- You Are Catching My Attention: Are Vision Transformers Bad Learners under Backdoor Attacks?Zenghui Yuan, Pan Zhou, Kai Zou, Yu ChengCVPR 2023
Builds on26
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Training data-efficient image transformers & distillation through attentionHugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa et al.ICML 2021 · 8,974 citations
- Pyramid Vision Transformer: A Versatile Backbone for Dense Prediction without ConvolutionsWenhai Wang, Enze Xie, Xiang Li, Deng-Ping Fan et al.ICCV 2021 · 4,909 citations
- Tokens-to-Token ViT: Training Vision Transformers from Scratch on ImageNetLi Yuan, Yunpeng Chen, Tao Wang, Weihao Yu et al.ICCV 2021 · 2,462 citations
Related papers
- TrojViT: Trojan Insertion in Vision TransformersMengxin Zheng, Qian Lou, Lei JiangCVPR 2023
- When Adversarial Training Meets Vision Transformers: Recipes from Training to ArchitectureYichuan Mo, Dongxian Wu, Yifei Wang, Yiwen Guo et al.NeurIPS 2022 · 109 citations
- Beating Backdoor Attack at Its Own GameMin Liu, Alberto L. Sangiovanni-Vincentelli, Xiangyu YueICCV 2023 · 19 citations
- Understanding and Defending Patched-based Adversarial Attacks for Vision TransformerLiang Liu, Yanan Guo, Youtao Zhang, Jun YangICML 2023 · 7 citations
- Clean-Label Backdoor Attacks on Video Recognition ModelsShihao Zhao, Xingjun Ma, Xiang Zheng, James Bailey et al.CVPR 2020
