Improving transferable adversarial attack for vision transformers via global attention and local drop

被引:3
|
作者
Li, Tuo [1 ]
Han, Yahong [1 ]
机构
[1] Tianjin Univ, Coll Intelligence & Comp, Tianjin, Peoples R China
关键词
Adversarial examples; Vision transformer; Transferability; Self-attention;
D O I
10.1007/s00530-023-01157-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Vision Transformers (ViTs) have been a new paradigm in several computer vision tasks, yet they are susceptible to adversarial examples. Recent studies show it is difficult to transfer adversarial examples generated by ViTs to other models. Existing methods have poor transferability because they do not target the specific structural characteristics (e.g., self-attention and patch-embedding) of ViTs. To address this problem and further boost transferability, we propose a method, namely Global Attention and Local Drop (GALD), to boost the transferability of adversarial examples from ViTs to other models, including ViTs and convolutional neural networks (CNNs). Specifically, our method contains two parts: Global Attention Guidance (GAG) and Drop Patch (DP). The GAG improves the attention representation in shallow layers by adding global guidance attention to every layer except the final layer of ViTs. Therefore, the perturbations could focus on the object regions. DP randomly drops some patches in every iteration to diversify the input patterns and mitigate overfitting of adversarial examples to the surrogate model. Experiments show that adversarial examples generated by our method own the best transferability to black-box models with unknown structures. Code is available at Link.
引用
收藏
页码:3467 / 3480
页数:14
相关论文
共 50 条
  • [41] Other tokens matter: Exploring global and local features of Vision Transformers for Object Re-Identification
    Wang, Yingquan
    Zhang, Pingping
    Wang, Dong
    Lu, Huchuan
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2024, 244
  • [42] Improving Transferability of Adversarial Samples via Critical Region-Oriented Feature-Level Attack
    Li, Zhiwei
    Ren, Min
    Li, Qi
    Jiang, Fangling
    Sun, Zhenan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6650 - 6664
  • [43] ALGM: Adaptive Local-then-Global Token Merging for Efficient Semantic Segmentation with Plain Vision Transformers
    Norouzi, Narges
    Orlova, Svetlana
    de Geus, Daan
    Dubbelman, Gijs
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2024, : 15773 - 15782
  • [44] Light-Weight Vision Transformer with Parallel Local and Global Self-Attention
    Ebert, Nikolas
    Reichardt, Laurenz
    Stricker, Didier
    Wasenmueller, Oliver
    2023 IEEE 26TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS, ITSC, 2023, : 452 - 459
  • [45] PLG-ViT: Vision Transformer with Parallel Local and Global Self-Attention
    Ebert, Nikolas
    Stricker, Didier
    Wasenmueller, Oliver
    SENSORS, 2023, 23 (07)
  • [46] Face Presentation Attack Detection in Ultraviolet Spectrum via Local and Global Features
    Siegmund, Dirk
    Kerckhoff, Florian
    Magdaleno, Javier Yeste
    Jansen, Nils
    Kirchbuchner, Florian
    Kuijper, Arjan
    2020 INTERNATIONAL CONFERENCE OF THE BIOMETRICS SPECIAL INTEREST GROUP (BIOSIG), 2020, P-306
  • [47] Attention Heat Map-Based Black-Box Local Adversarial Attack for Synthetic Aperture Radar Target Recognition
    Wan, Xuanshen
    Liu, Wei
    Niu, Chaoyang
    Lu, Wanjie
    PHOTOGRAMMETRIC ENGINEERING AND REMOTE SENSING, 2024, 90 (10): : 601 - 609
  • [48] Improving Object Detection Quality by Incorporating Global Contexts via Self-Attention
    Lee, Donghyeon
    Kim, Joonyoung
    Jung, Kyomin
    ELECTRONICS, 2021, 10 (01) : 1 - 15
  • [49] Footprints Elicit the Truth: Improving Global Positioning Accuracy via Local Mobility
    Wu, Chenshu
    Yang, Zheng
    Zhao, Yiyang
    Liu, Yunhao
    2013 PROCEEDINGS IEEE INFOCOM, 2013, : 490 - 494
  • [50] Material decomposition of spectral CT images via attention-based global convolutional generative adversarial network
    Xiaodong Guo
    Peng He
    Xiaojie Lv
    Xuezhi Ren
    Yonghui Li
    Yuanfeng Liu
    Xiaohua Lei
    Peng Feng
    Hongming Shan
    Nuclear Science and Techniques, 2023, 34