Generating Transferable Adversarial Examples against Vision Transformers
Yuxuan Wang, Jiakai Wang, Zixin Yin, Ruihao Gong, Jingyi Wang, Aishan Liu, Xianglong Liu
摘要
Vision transformers (ViTs) are prevailing among several visual recognition tasks, therefore drawing intensive interest in generating adversarial examples against them. Different from CNNs, ViTs enjoy unique architectures, e.g., self-attention and image-embedding, which are commonly-shared features among various types of transformer-based models. However, existing adversarial methods suffer from weak transferable attacking ability due to the overlook of these architectural features. To address the problem, we propose an Architecture-oriented Transferable Attacking (ATA) framework to generate transferable adversarial examples by activating the uncertain attention and perturbing the sensitive embedding.Specifically, we first locate the patch-wise attentional regions that mostly affect model perception, therefore intensively activating the uncertainty of the attention mechanism and confusing the model decisions in turn.Furthermore, we search the pixel-wise attacking positions that are more likely to derange the embedded tokens using sensitive embedding perturbation, which could serve as a strong transferable attacking pattern.By jointly confusing the unique yet widely-used architectural features among transformer-based models, we can activate strong attacking transferability among diverse ViTs. Extensive experiments on large-scale dataset ImageNet using various popular transformers demonstrate that our ATA outperforms other baselines by large margins (at least +15% Attack Success Rate). Our code is available at https://github.com/nlsde-safety-team/ATA
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper10
- BiBench: Benchmarking and Analyzing Network BinarizationHaotong Qin, Mingyuan Zhang, Yifu Ding, Aoyu Li 等ICML 2023 · 被引用 53 次
- Boosting Adversarial Transferability across Model Genus by Deformation-Constrained WarpingQinliang Lin, Cheng Luo, Zenghao Niu, Xilin He 等AAAI 2024 · 被引用 36 次
- Vulnerabilities in Video Quality Assessment Models: The Challenge of Adversarial AttacksAoxiang Zhang, Yu Ran, Weixuan Tang, Yuan-Gen WangNeurIPS 2023 · 被引用 19 次
- AGS: Affordable and Generalizable Substitute Training for Transferable Adversarial AttackRuikui Wang, Yuanfang Guo, Yunhong WangAAAI 2024 · 被引用 17 次
- NAPGuard: Towards Detecting Naturalistic Adversarial PatchesSiyang Wu, Jiakai Wang, Jiejie Zhao, Yazhe Wang 等CVPR 2024 · 被引用 11 次
相关 Paper
- Towards Transferable Adversarial Attacks on Vision TransformersZhipeng Wei, Jingjing Chen, Micah Goldblum, Zuxuan Wu 等AAAI 2022 · 被引用 156 次
- On Improving Adversarial Transferability of Vision TransformersMuzammal Naseer, Kanchana Ranasinghe, Salman Khan, Fahad Shahbaz Khan 等ICLR 2022 · 被引用 111 次
- Boosting the Transferability of Adversarial Attack on Vision Transformer with Adaptive Token TuningDi Ming, Peng Ren, Yunlong Wang, Xin FengNeurIPS 2024 · 被引用 24 次
- Give Me Your Attention: Dot-Product Attention Considered Harmful for Adversarial Patch RobustnessGiulio Lovisotto, Nicole Finnie, Mauricio Munoz, Chaithanya Kumar Mummadi 等CVPR 2022 · 被引用 33 次
- ViT-EnsembleAttack: Augmenting Ensemble Models for Stronger Adversarial Transferability in Vision TransformersHanwen Cao, Haobo Lu, Xiaosen Wang, Kun HeICCV 2025 · 被引用 5 次
