Skip to main content
Top
Published in:

15-02-2024 | Original Article

Dual stage black-box adversarial attack against vision transformer

Authors: Fan Wang, Mingwen Shao, Lingzhuang Meng, Fukang Liu

Published in: International Journal of Machine Learning and Cybernetics | Issue 8/2024

Log in

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

The article introduces a dual-stage black-box adversarial attack against Vision Transformers (ViTs), addressing the challenge of enhancing the transferability of adversarial examples. The proposed method optimizes perturbations in both decision space and feature space, utilizing a Semi Self-Integrated Module (SSIM) and a Random Perturbation Masking (RPM) module. The SSIM extracts classification information from deep transformer blocks, while the RPM alleviates overfitting by randomly masking noise patches. The approach demonstrates superior performance in attacking various ViTs and CNNs, outperforming state-of-the-art methods by up to 16.04% on average. The article also provides extensive experimental validation, highlighting the effectiveness of the dual-stage optimization strategy in improving adversarial transferability across different models.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Business + Economics & Engineering + Technology"

Online-Abonnement

Springer Professional "Business + Economics & Engineering + Technology" gives you access to:

  • more than 102.000 books
  • more than 537 journals

from the following subject areas:

  • Automotive
  • Construction + Real Estate
  • Business IT + Informatics
  • Electrical Engineering + Electronics
  • Energy + Sustainability
  • Finance + Banking
  • Management + Leadership
  • Marketing + Sales
  • Mechanical Engineering + Materials
  • Insurance + Risk


Secure your knowledge advantage now!

Springer Professional "Engineering + Technology"

Online-Abonnement

Springer Professional "Engineering + Technology" gives you access to:

  • more than 67.000 books
  • more than 390 journals

from the following specialised fileds:

  • Automotive
  • Business IT + Informatics
  • Construction + Real Estate
  • Electrical Engineering + Electronics
  • Energy + Sustainability
  • Mechanical Engineering + Materials





 

Secure your knowledge advantage now!

Springer Professional "Business + Economics"

Online-Abonnement

Springer Professional "Business + Economics" gives you access to:

  • more than 67.000 books
  • more than 340 journals

from the following specialised fileds:

  • Construction + Real Estate
  • Business IT + Informatics
  • Finance + Banking
  • Management + Leadership
  • Marketing + Sales
  • Insurance + Risk



Secure your knowledge advantage now!

Show more products
Literature
This content is only visible if you are logged in and have the appropriate permissions.
Metadata
Title
Dual stage black-box adversarial attack against vision transformer
Authors
Fan Wang
Mingwen Shao
Lingzhuang Meng
Fukang Liu
Publication date
15-02-2024
Publisher
Springer Berlin Heidelberg
Published in
International Journal of Machine Learning and Cybernetics / Issue 8/2024
Print ISSN: 1868-8071
Electronic ISSN: 1868-808X
DOI
https://doi.org/10.1007/s13042-024-02097-4