Understanding and improving adversarial transferability of vision transformers and convolutional neural networks

被引:6
作者
Chen, Zhiyu [1 ]
Xu, Chi [1 ]
Lv, Huanhuan [2 ]
Liu, Shangdong [1 ]
Ji, Yimu [1 ]
机构
[1] Nanjing Univ Posts & Telecommun, Nanjing, Peoples R China
[2] Nanjing Univ, Nanjing, Peoples R China
基金
中国国家自然科学基金;
关键词
Vision transformer; Convolutional neural network; Adversarial example; Transferability; DEFENSE GAN;
D O I
10.1016/j.ins.2023.119474
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Convolutional neural networks (CNNs) and visual transformers (ViTs) are both known to be vulnerable to adversarial examples. Recent work has illustrated the existence of transferability between the two, but the experimental performance is generally mediocre. To enhance the transferability of adversarial examples between CNNs and ViTs, we propose a novel attack on the phenomenon that CNNs and ViTs differ significantly in their inductive bias, which not only attacks the same inductive bias between the two classes of models, but also suppresses the unique of ViTs. We evaluate the effectiveness of our approach through extensive experiments on stateof -the -art ViTs, CNNs, and robustly trained CNNs, and demonstrate significant improvements in transferability, both between ViTs and from ViTs to CNNs. The code for our project is available at https://github .com /chenxiaoyupetter /inductive -biase -attack.
引用
收藏
页数:14
相关论文
共 49 条
[1]   Visformer: The Vision-friendly Transformer [J].
Chen, Zhengsu ;
Xie, Lingxi ;
Niu, Jianwei ;
Liu, Xuefeng ;
Wei, Longhui ;
Tian, Qi .
2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, :569-578
[2]   ConViT: improving vision transformers with soft convolutional inductive biases [J].
d'Ascoli, Stephane ;
Touvron, Hugo ;
Leavitt, Matthew L. ;
Morcos, Ari S. ;
Biroli, Giulio ;
Sagun, Levent .
JOURNAL OF STATISTICAL MECHANICS-THEORY AND EXPERIMENT, 2022, 2022 (11)
[3]  
Deng Huiqi, 2021, arXiv
[4]   Efficient Decision-based Black-box Adversarial Attacks on Face Recognition [J].
Dong, Yinpeng ;
Su, Hang ;
Wu, Baoyuan ;
Li, Zhifeng ;
Liu, Wei ;
Zhang, Tong ;
Zhu, Jun .
2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, :7706-7714
[5]   Evading Defenses to Transferable Adversarial Examples by Translation-Invariant Attacks [J].
Dong, Yinpeng ;
Pang, Tianyu ;
Su, Hang ;
Zhu, Jun .
2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, :4307-4316
[6]   Boosting Adversarial Attacks with Momentum [J].
Dong, Yinpeng ;
Liao, Fangzhou ;
Pang, Tianyu ;
Su, Hang ;
Zhu, Jun ;
Hu, Xiaolin ;
Li, Jianguo .
2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, :9185-9193
[7]  
Dosovitskiy A., 2021, arXiv
[8]   RSD-GAN: Regularized Sobolev Defense GAN Against Speech-to-Text Adversarial Attacks [J].
Esmaeilpour, Mohammad ;
Chaalia, Nourhene ;
Cardinal, Patrick .
IEEE SIGNAL PROCESSING LETTERS, 2022, 29 :1998-2002
[9]   Cyclic Defense GAN Against Speech Adversarial Attacks [J].
Esmaeilpour, Mohammad ;
Cardinal, Patrick ;
Koerich, Alessandro Lameiras .
IEEE SIGNAL PROCESSING LETTERS, 2021, 28 :1769-1773
[10]  
Goodfellow I. J., 2015, EXPLAINING HARNESSIN