Enhancing the transferability of adversarial examples on vision transformers

被引:1
作者
Guan, Yujiao [1 ]
Yang, Haoyu [1 ]
Qu, Xiaotong [1 ]
Wang, Xiaodong [1 ]
机构
[1] Ocean Univ China, Coll Comp Sci & Technol, Qingdao, Peoples R China
关键词
vision transformer; adversarial examples; transferability; image classification; computer vision;
D O I
10.1117/1.JEI.33.2.023039
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The advancement of adversarial attack techniques, particularly against neural network architectures, is a crucial area of research in machine learning. Notably, the emergence of vision transformers (ViTs) as a dominant force in computer vision tasks has opened avenues for exploring their vulnerabilities. In this context, we introduce dual gradient optimization for adversarial transferability (DGO-AT), a comprehensive strategy designed to enhance the transferability of adversarial examples in ViTs. DGO-AT incorporates two innovative components: attention gradient smoothing (AGS) and multi-layer perceptron gradient random dropout (GRD-MLP). AGS targets the attention layers of ViTs to smooth gradients and reduce noise, focusing on global features for improved transferability. GRD-MLP, on the other hand, introduces stochasticity into MLP gradient updates, broadening the adversarial examples' applicability. The synergy of these strategies in DGO-AT addresses the unique structural aspects of ViTs, leading to more effective and transferable adversarial attacks. Our comprehensive evaluations of a variety of ViT and CNN models, using the ImageNet dataset, demonstrate that DGO-AT significantly enhances the effectiveness and transferability of attacks, thereby contributing to the ongoing discourse on the adversarial robustness of advanced neural network models. (c) 2024 SPIE and IS&T
引用
收藏
页数:16
相关论文
共 50 条
[21]   Improving transferability of adversarial examples by saliency distribution and data augmentation [J].
Dong, Yansong ;
Tang, Long ;
Tian, Cong ;
Yu, Bin ;
Duan, Zhenhua .
COMPUTERS & SECURITY, 2022, 120
[22]   Assessing Transferability of Adversarial Examples against Malware Detection Classifiers [J].
Wang, Yixiang ;
Liu, Jiqiang ;
Chang, Xiaolin .
CF '19 - PROCEEDINGS OF THE 16TH ACM INTERNATIONAL CONFERENCE ON COMPUTING FRONTIERS, 2019, :211-214
[23]   Improving the Transferability of Adversarial Examples by Feature Augmentation [J].
Wang, Donghua ;
Yao, Wen ;
Jiang, Tingsong ;
Zheng, Xiaohu ;
Wu, Junqi .
IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2025,
[24]   Enhancing the Transferability of Targeted Attacks with Adversarial Perturbation Transform [J].
Deng, Zhengjie ;
Xiao, Wen ;
Li, Xiyan ;
He, Shuqian ;
Wang, Yizhen .
ELECTRONICS, 2023, 12 (18)
[25]   Enhancing the Adversarial Transferability with Channel Decomposition [J].
Lin B. ;
Gao F. ;
Zeng W. ;
Chen J. ;
Zhang C. ;
Zhu Q. ;
Zhou Y. ;
Zheng D. ;
Qiu Q. ;
Yang S. .
Computer Systems Science and Engineering, 2023, 46 (03) :3075-3085
[26]   Enhancing the transferability of adversarial attacks with diversified input strategies [J].
Li Z. ;
Chen Y. ;
Yang B. ;
Li C. ;
Zhang S. ;
Li W. ;
Zhang H. .
Journal of Intelligent and Fuzzy Systems, 2024, 46 (04) :10359-10373
[27]   Enhancing adversarial transferability with local transformation [J].
Zhang, Yang ;
Hong, Jinbang ;
Bai, Qing ;
Liang, Haifeng ;
Zhu, Peican ;
Song, Qun .
COMPLEX & INTELLIGENT SYSTEMS, 2025, 11 (01)
[28]   Evaluating and enhancing the robustness of vision transformers against adversarial attacks in medical imaging [J].
Kanca, Elif ;
Ayas, Selen ;
Kablan, Elif Baykal ;
Ekinci, Murat .
MEDICAL & BIOLOGICAL ENGINEERING & COMPUTING, 2024, :673-690
[29]   Strengthening transferability of adversarial examples by adaptive inertia and amplitude spectrum dropout [J].
Li, Huanhuan ;
Yu, Wenbo ;
Huang, He .
NEURAL NETWORKS, 2023, 165 :925-937
[30]   Generation and Countermeasures of adversarial examples on vision: a survey [J].
Liu, Jiangfan ;
Li, Yishan ;
Guo, Yanming ;
Liu, Yu ;
Tang, Jun ;
Nie, Ying .
ARTIFICIAL INTELLIGENCE REVIEW, 2024, 57 (08)