Towards transferable adversarial attacks on vision transformers for image classification

被引:1
|
作者
Guo, Xu [1 ]
Chen, Peng [1 ]
Lu, Zhihui [1 ,2 ]
Chai, Hongfeng [1 ,3 ]
Du, Xin [1 ]
Wu, Xudong [1 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
[2] Shanghai Blockchain Engn Res Ctr, Shanghai 200433, Peoples R China
[3] Fudan Univ, Inst Financial Technol, Shanghai 200433, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial example; Transfer attack; Surrogate model; Vision transformer; Fintech regulation; Image classification;
D O I
10.1016/j.sysarc.2024.103155
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The deployment of high-performance Vision Transformer (ViT) models has garnered attention from both industry and academia. However, their vulnerability to adversarial examples highlights security risks for scenarios such as intelligent surveillance, autonomous driving, and fintech regulation. As a black-box attack technique, transfer attacks leverage a surrogate model to generate transferable adversarial examples to attack a target victim model, which mainly focuses on a forward (input diversification) and a backward (gradient modification) approach. However, both approaches are currently implemented straightforwardly and limit the transferability of surrogate models. In this paper, we propose a Forward-Backward Transferable Adversarial Attack framework (FBTA) that can generate highly transferable adversarial examples against different models by fully leveraging ViT's distinctive intermediate layer structures. In the forward inference process of FBTA, we propose a Dropout-based Transferable Attack (DTA) approach to diversify the intermediate states of ViT models, simulating an ensemble learning effect; in the backward process, a Backpropagation Gradient Clipping (BGC) method is designed to refine the gradients within intermediate layers of ViT models intricately. Extensive experiments on state-of-the-art ViTs and robust CNNs demonstrate that our FBTA framework achieves an average performance improvement of 2.79% compared to state-of-the-art transfer-based attacks, offering insights for the comprehension and defense against transfer attacks.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks
    Haoran Lyu
    Yajie Wang
    Yu-an Tan
    Huipeng Zhou
    Yuhang Zhao
    Quanxin Zhang
    Cybersecurity, 7
  • [22] Maxwell's Demon in MLP-Mixer: towards transferable adversarial attacks
    Lyu, Haoran
    Wang, Yajie
    Tan, Yu-an
    Zhou, Huipeng
    Zhao, Yuhang
    Zhang, Quanxin
    CYBERSECURITY, 2024, 7 (01)
  • [23] Evaluating and enhancing the robustness of vision transformers against adversarial attacks in medical imaging
    Kanca, Elif
    Ayas, Selen
    Kablan, Elif Baykal
    Ekinci, Murat
    MEDICAL & BIOLOGICAL ENGINEERING & COMPUTING, 2024, : 673 - 690
  • [24] Transferable Adversarial Attack for Both Vision Transformers and Convolutional Networks via Momentum Integrated Gradients
    Ma, Wenshuo
    Li, Yidong
    Jia, Xiaofeng
    Xu, Wei
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4607 - 4616
  • [25] A Study of Adversarial Attacks on Malaria Cell Image Classification
    Pervin, Tasnim
    Huq, Aminul
    2021 IEEE INTERNATIONAL WOMEN IN ENGINEERING (WIE) CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (WIECON-ECE), 2022, : 79 - 82
  • [26] Vision Transformers for Breast Cancer Histology Image Classification
    Baroni, Giulia L.
    Rasotto, Laura
    Roitero, Kevin
    Siraj, Ameer Hamza
    Della Mea, Vincenzo
    IMAGE ANALYSIS AND PROCESSING - ICIAP 2023 WORKSHOPS, PT II, 2024, 14366 : 15 - 26
  • [27] Image forgery classification and localization through vision transformers
    Pawar, Digambar
    Gowda, Raghavendra
    Chandra, Krishna
    INTERNATIONAL JOURNAL OF MULTIMEDIA INFORMATION RETRIEVAL, 2025, 14 (01)
  • [28] Exploring Vision Transformers for Polarimetric SAR Image Classification
    Dong, Hongwei
    Zhang, Lamei
    Zou, Bin
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60
  • [29] ADAPTIVE WARPING NETWORK FOR TRANSFERABLE ADVERSARIAL ATTACKS
    Son, Minji
    Kwon, Myung-Joon
    Kim, Hee-Seon
    Byun, Junyoung
    Cho, Seungju
    Kim, Changick
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 3056 - 3060
  • [30] Towards efficient diagnostics: refining vision transformers for medical image multi-label classification
    Cayce, Garrett I.
    Hand, Benjamin M.
    Kurz, Aidan G.
    Bailey, Colleen P.
    ANOMALY DETECTION AND IMAGING WITH X-RAYS, ADIX IX, 2024, 13043