ViP: Unified Certified Detection and Recovery for Patch Attack with Vision Transformers

被引:3
|
作者
Li, Junbo [1 ]
Zhang, Huan [2 ]
Xie, Cihang [1 ]
机构
[1] Univ Calif Santa Cruz, Santa Cruz, CA 95064 USA
[2] Carnegie Mellon Univ, Pittsburgh, PA USA
来源
COMPUTER VISION, ECCV 2022, PT XXV | 2022年 / 13685卷
关键词
Certified defense; Patch attacks; Vision transformer;
D O I
10.1007/978-3-031-19806-9_33
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Patch attack, which introduces a perceptible but localized change to the input image, has gained significant momentum in recent years. In this paper, we present a unified framework to analyze certified patch defense tasks, including both certified detection and certified recovery, leveraging the recently emerged Vision Transformers (ViTs). In addition to the existing patch defense setting where only one patch is considered, we provide the very first study on developing certified detection against the dual patch attack, in which the attacker is allowed to adversarially manipulate pixels in two different regions. By building upon the latest progress in self-supervised ViTs with masked image modeling (i.e., masked autoencoder (MAE)), our method achieves state-of-the-art performance in both certified detection and certified recovery of adversarial patches. Regarding certified detection, we improve the performance by up to similar to 16% on ImageNet without training on a single adversarial patch, and for the first time, can also tackle the more challenging dual patch setting. Our method largely closes the gap between detection-based certified robustness and clean image accuracy. Regarding certified recovery, our approach improves certified accuracy by similar to 2% on ImageNet across all attack sizes, attaining the new state-of-the-art performance.
引用
收藏
页码:573 / 587
页数:15
相关论文
共 34 条
  • [31] Image-Based Lunar Hazard Detection in Low Illumination Simulated Conditions via Vision Transformers
    Ghilardi, Luca
    Furfaro, Roberto
    SENSORS, 2023, 23 (18)
  • [32] An intelligent ransomware attack detection and classification using dual vision transformer with Mantis Search Split Attention Network
    Ashwini, K.
    Nagasundara, K. B.
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 119
  • [33] Enhanced tuberculosis detection using Vision Transformers and explainable AI with a Grad-CAM approach on chest X-rays
    Vanitha, K.
    Mahesh, T. R.
    Kumar, V. Vinoth
    Guluwadi, Suresh
    BMC MEDICAL IMAGING, 2025, 25 (01):
  • [34] A Novel Diagnostic Framework with an Optimized Ensemble of Vision Transformers and Convolutional Neural Networks for Enhanced Alzheimer's Disease Detection in Medical Imaging
    Bortty, Joy Chakra
    Chakraborty, Gouri Shankar
    Noman, Inshad Rahman
    Batra, Salil
    Das, Joy
    Bishnu, Kanchon Kumar
    Tarafder, Md Tanvir Rahman
    Islam, Araf
    DIAGNOSTICS, 2025, 15 (06)