Enhancing the transferability of adversarial examples on vision transformers

被引:0
|
作者
Guan, Yujiao [1 ]
Yang, Haoyu [1 ]
Qu, Xiaotong [1 ]
Wang, Xiaodong [1 ]
机构
[1] Ocean Univ China, Coll Comp Sci & Technol, Qingdao, Peoples R China
关键词
vision transformer; adversarial examples; transferability; image classification; computer vision;
D O I
10.1117/1.JEI.33.2.023039
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The advancement of adversarial attack techniques, particularly against neural network architectures, is a crucial area of research in machine learning. Notably, the emergence of vision transformers (ViTs) as a dominant force in computer vision tasks has opened avenues for exploring their vulnerabilities. In this context, we introduce dual gradient optimization for adversarial transferability (DGO-AT), a comprehensive strategy designed to enhance the transferability of adversarial examples in ViTs. DGO-AT incorporates two innovative components: attention gradient smoothing (AGS) and multi-layer perceptron gradient random dropout (GRD-MLP). AGS targets the attention layers of ViTs to smooth gradients and reduce noise, focusing on global features for improved transferability. GRD-MLP, on the other hand, introduces stochasticity into MLP gradient updates, broadening the adversarial examples' applicability. The synergy of these strategies in DGO-AT addresses the unique structural aspects of ViTs, leading to more effective and transferable adversarial attacks. Our comprehensive evaluations of a variety of ViT and CNN models, using the ImageNet dataset, demonstrate that DGO-AT significantly enhances the effectiveness and transferability of attacks, thereby contributing to the ongoing discourse on the adversarial robustness of advanced neural network models. (c) 2024 SPIE and IS&T
引用
收藏
页数:16
相关论文
共 50 条
  • [1] ENHANCING THE ADVERSARIAL TRANSFERABILITY OF VISION TRANSFORMERS THROUGH PERTURBATION INVARIANCE
    Zeng Boheng
    2022 19TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2022,
  • [2] On the Robustness of Vision Transformers to Adversarial Examples
    Mahmood, Kaleel
    Mahmood, Rigel
    van Dijk, Marten
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7818 - 7827
  • [3] Enhancing the Transferability of Adversarial Examples with Feature Transformation
    Xu, Hao-Qi
    Hu, Cong
    Yin, He-Feng
    MATHEMATICS, 2022, 10 (16)
  • [4] Enhancing Transferability of Adversarial Examples with Spatial Momentum
    Wang, Guoqiu
    Yan, Huanqian
    Wei, Xingxing
    PATTERN RECOGNITION AND COMPUTER VISION, PT I, PRCV 2022, 2022, 13534 : 593 - 604
  • [5] Improving the Adversarial Transferability of Vision Transformers with Virtual Dense Connection
    Zhang, Jianping
    Huang, Yizhan
    Xu, Zhuoer
    Wu, Weibin
    Lyu, Michael R.
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 7, 2024, : 7133 - 7141
  • [6] Generating Transferable Adversarial Examples against Vision Transformers
    Wang, Yuxuan
    Wang, Jiakai
    Yin, Zinxin
    Gong, Ruihao
    Wang, Jingyi
    Liu, Aishan
    Liu, Xianglong
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2022, 2022, : 5181 - 5190
  • [7] Enhancing adversarial transferability with partial blocks on vision transformer
    Han, Yanyang
    Liu, Ju
    Liu, Xiaoxi
    Jiang, Xiao
    Gu, Lingchen
    Gao, Xuesong
    Chen, Weiqiang
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (22): : 20249 - 20262
  • [8] Enhancing adversarial transferability with partial blocks on vision transformer
    Yanyang Han
    Ju Liu
    Xiaoxi Liu
    Xiao Jiang
    Lingchen Gu
    Xuesong Gao
    Weiqiang Chen
    Neural Computing and Applications, 2022, 34 : 20249 - 20262
  • [9] Enhancing Transferability of Adversarial Examples by Successively Attacking Multiple Models
    Zhang, Xiaolin
    Zhang, Wenwen
    Liu, Lixin
    Wang, Yongping
    Gao, Lu
    Zhang, Shuai
    International Journal of Network Security, 2023, 25 (02) : 306 - 316
  • [10] Understanding and improving adversarial transferability of vision transformers and convolutional neural networks
    Chen, Zhiyu
    Xu, Chi
    Lv, Huanhuan
    Liu, Shangdong
    Ji, Yimu
    INFORMATION SCIENCES, 2023, 648