Improving transferable adversarial attack for vision transformers via global attention and local drop

被引:3
|
作者
Li, Tuo [1 ]
Han, Yahong [1 ]
机构
[1] Tianjin Univ, Coll Intelligence & Comp, Tianjin, Peoples R China
关键词
Adversarial examples; Vision transformer; Transferability; Self-attention;
D O I
10.1007/s00530-023-01157-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Vision Transformers (ViTs) have been a new paradigm in several computer vision tasks, yet they are susceptible to adversarial examples. Recent studies show it is difficult to transfer adversarial examples generated by ViTs to other models. Existing methods have poor transferability because they do not target the specific structural characteristics (e.g., self-attention and patch-embedding) of ViTs. To address this problem and further boost transferability, we propose a method, namely Global Attention and Local Drop (GALD), to boost the transferability of adversarial examples from ViTs to other models, including ViTs and convolutional neural networks (CNNs). Specifically, our method contains two parts: Global Attention Guidance (GAG) and Drop Patch (DP). The GAG improves the attention representation in shallow layers by adding global guidance attention to every layer except the final layer of ViTs. Therefore, the perturbations could focus on the object regions. DP randomly drops some patches in every iteration to diversify the input patterns and mitigate overfitting of adversarial examples to the surrogate model. Experiments show that adversarial examples generated by our method own the best transferability to black-box models with unknown structures. Code is available at Link.
引用
收藏
页码:3467 / 3480
页数:14
相关论文
共 50 条
  • [1] Improving transferable adversarial attack for vision transformers via global attention and local drop
    Tuo Li
    Yahong Han
    Multimedia Systems, 2023, 29 : 3467 - 3480
  • [2] Transferable Adversarial Attack for Both Vision Transformers and Convolutional Networks via Momentum Integrated Gradients
    Ma, Wenshuo
    Li, Yidong
    Jia, Xiaofeng
    Xu, Wei
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4607 - 4616
  • [3] Towards Transferable Adversarial Attacks on Vision Transformers
    Wei, Zhipeng
    Chen, Jingjing
    Goldblum, Micah
    Wu, Zuxuan
    Goldstein, Tom
    Jiang, Yu-Gang
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 2668 - 2676
  • [4] Improving transferable adversarial attack via feature-momentum
    He, Xianglong
    Li, Yuezun
    Qu, Haipeng
    Dong, Junyu
    COMPUTERS & SECURITY, 2023, 128
  • [5] Generating Transferable Adversarial Examples against Vision Transformers
    Wang, Yuxuan
    Wang, Jiakai
    Yin, Zinxin
    Gong, Ruihao
    Wang, Jingyi
    Liu, Aishan
    Liu, Xianglong
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2022, 2022, : 5181 - 5190
  • [6] TIA: Token Importance Transferable Attack on Vision Transformers
    Fu, Tingchao
    Li, Fanxiao
    Zhang, Jinhong
    Zhu, Liang
    Wang, Yuanyu
    Zhou, Wei
    INFORMATION SECURITY AND CRYPTOLOGY, INSCRYPT 2023, PT II, 2024, 14527 : 91 - 107
  • [7] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424
  • [8] Towards transferable adversarial attacks on vision transformers for image classification
    Guo, Xu
    Chen, Peng
    Lu, Zhihui
    Chai, Hongfeng
    Du, Xin
    Wu, Xudong
    JOURNAL OF SYSTEMS ARCHITECTURE, 2024, 152
  • [9] A Feature Map Adversarial Attack Against Vision Transformers
    Altoub, Majed
    Mehmood, Rashid
    AlQurashi, Fahad
    Alqahtany, Saad
    Alsulami, Bassma
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (10) : 962 - 968
  • [10] Intermediate-Layer Transferable Adversarial Attack With DNN Attention
    Yang, Shanshan
    Yang, Yu
    Zhou, Linna
    Zhan, Rui
    Man, Yufei
    IEEE ACCESS, 2022, 10 : 95451 - 95461