Enhancing the transferability of adversarial examples on vision transformers

被引:1
作者
Guan, Yujiao [1 ]
Yang, Haoyu [1 ]
Qu, Xiaotong [1 ]
Wang, Xiaodong [1 ]
机构
[1] Ocean Univ China, Coll Comp Sci & Technol, Qingdao, Peoples R China
关键词
vision transformer; adversarial examples; transferability; image classification; computer vision;
D O I
10.1117/1.JEI.33.2.023039
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The advancement of adversarial attack techniques, particularly against neural network architectures, is a crucial area of research in machine learning. Notably, the emergence of vision transformers (ViTs) as a dominant force in computer vision tasks has opened avenues for exploring their vulnerabilities. In this context, we introduce dual gradient optimization for adversarial transferability (DGO-AT), a comprehensive strategy designed to enhance the transferability of adversarial examples in ViTs. DGO-AT incorporates two innovative components: attention gradient smoothing (AGS) and multi-layer perceptron gradient random dropout (GRD-MLP). AGS targets the attention layers of ViTs to smooth gradients and reduce noise, focusing on global features for improved transferability. GRD-MLP, on the other hand, introduces stochasticity into MLP gradient updates, broadening the adversarial examples' applicability. The synergy of these strategies in DGO-AT addresses the unique structural aspects of ViTs, leading to more effective and transferable adversarial attacks. Our comprehensive evaluations of a variety of ViT and CNN models, using the ImageNet dataset, demonstrate that DGO-AT significantly enhances the effectiveness and transferability of attacks, thereby contributing to the ongoing discourse on the adversarial robustness of advanced neural network models. (c) 2024 SPIE and IS&T
引用
收藏
页数:16
相关论文
共 50 条
[41]   Enhancing the Transferability of Adversarial Attacks via Multi-Feature Attention [J].
Zheng, Desheng ;
Ke, Wuping ;
Li, Xiaoyu ;
Duan, Yaoxin ;
Yin, Guangqiang ;
Min, Fan .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 :1462-1474
[42]   Boosting the transferability of adversarial examples via stochastic serial attack [J].
Hao, Lingguang ;
Hao, Kuangrong ;
Wei, Bing ;
Tang, Xue-song .
NEURAL NETWORKS, 2022, 150 :58-67
[43]   Towards transferable adversarial attacks on vision transformers for image classification [J].
Guo, Xu ;
Chen, Peng ;
Lu, Zhihui ;
Chai, Hongfeng ;
Du, Xin ;
Wu, Xudong .
JOURNAL OF SYSTEMS ARCHITECTURE, 2024, 152
[44]   Learnable Masked Tokens for Improved Transferability of Self-supervised Vision Transformers [J].
Hu, Hao ;
Baldassarre, Federico ;
Azizpour, Hossein .
MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2022, PT III, 2023, 13715 :409-426
[45]   Improving transferable adversarial attack for vision transformers via global attention and local drop [J].
Li, Tuo ;
Han, Yahong .
MULTIMEDIA SYSTEMS, 2023, 29 (06) :3467-3480
[46]   Improving transferable adversarial attack for vision transformers via global attention and local drop [J].
Tuo Li ;
Yahong Han .
Multimedia Systems, 2023, 29 :3467-3480
[47]   Towards Efficient Adversarial Training on Vision Transformers [J].
Wu, Boxi ;
Gu, Jindong ;
Li, Zhifeng ;
Cai, Deng ;
He, Xiaofei ;
Liu, Wei .
COMPUTER VISION, ECCV 2022, PT XIII, 2022, 13673 :307-325
[48]   Boosting the Transferability of Adversarial Examples with Gradient-Aligned Ensemble Attack for Speaker Recognition [J].
Li, Zhuhai ;
Zhang, Jie ;
Guo, Wu ;
Wu, Haochen .
INTERSPEECH 2024, 2024, :532-536
[49]   A Comprehensive Understanding of the Impact of Data Augmentation on the Transferability of 3D Adversarial Examples [J].
Qian, Fulan ;
Zou, Yuanjun ;
Xu, Mengyao ;
Zhang, Xuejun ;
Zhang, Chonghao ;
Xu, Chenchu ;
Chen, Hai .
ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2025, 19 (02)
[50]   ON THE TRANSFERABILITY OF ADVERSARIAL EXAMPLES AGAINST CNN-BASED IMAGE FORENSICS [J].
Barni, M. ;
Kallas, K. ;
Nowroozi, E. ;
Tondi, B. .
2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, :8286-8290