arXiv:2504.10804cs.CV2025-04NeurIPS被引 5

利用ViT计算冗余提升对抗样本迁移能力

Harnessing the Computation Redundancy in ViTs to Boost Adversarial Transferability

  • 发现ViT中数据与模型层面的冗余可增强攻击效果
  • 在ImageNet-1k上显著提升对抗样本迁移性与泛化性
  • 适合研究对抗攻击与模型鲁棒性的研究人员

视觉变换器(ViTs)在众多应用中表现优异,包括许多安全关键任务。然而其独特架构特性为对抗鲁棒性带来了新挑战与新机遇。我们观察到,针对ViTs生成的对抗样本比针对CNNs生成的具有更高的迁移性,表明ViTs存在有利于迁移攻击的结构特征。本文研究了ViTs中计算冗余的作用及其对对抗迁移性的影响。不同于以往为提高效率而减少计算的研究,我们提出利用这一冗余来提升对抗样本的质量与迁移能力。通过详细分析,我们识别出两种可利用的冗余形式:数据级和模型级。基于此,我们设计了一套技术,包括注意力稀疏度调控、注意力头重排、干净令牌正则化、伪MoE多样性增强以及测试时对抗训练。在ImageNet-1k数据集上的大量实验验证了该方法的有效性,结果显示我们的方法在多种模型架构上显著优于现有基线,在迁移性和泛化性方面均有提升。

原文摘要 · Abstract (English)

Vision Transformers (ViTs) have demonstrated impressive performance across a range of applications, including many safety-critical tasks. However, their unique architectural properties raise new challenges and opportunities in adversarial robustness. In particular, we observe that adversarial examples crafted on ViTs exhibit higher transferability compared to those crafted on CNNs, suggesting that ViTs contain structural characteristics favorable for transferable attacks. In this work, we investigate the role of computational redundancy in ViTs and its impact on adversarial transferability. Unlike prior studies that aim to reduce computation for efficiency, we propose to exploit this redundancy to improve the quality and transferability of adversarial examples. Through a detailed analysis, we identify two forms of redundancy, including the data-level and model-level, that can be harnessed to amplify attack effectiveness. Building on this insight, we design a suite of techniques, including attention sparsity manipulation, attention head permutation, clean token regularization, ghost MoE diversification, and test-time adversarial training. Extensive experiments on the ImageNet-1k dataset validate the effectiveness of our approach, showing that our methods significantly outperform existing baselines in both transferability and generality across diverse model architectures.

对抗攻击ViT迁移性冗余利用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。