Inference Time Evidences of Adversarial Attacks for Forensic on Transformers

01/31/2023
by   Hugo Lemarchant, et al.
0

Vision Transformers (ViTs) are becoming a very popular paradigm for vision tasks as they achieve state-of-the-art performance on image classification. However, although early works implied that this network structure had increased robustness against adversarial attacks, some works argue ViTs are still vulnerable. This paper presents our first attempt toward detecting adversarial attacks during inference time using the network's input and outputs as well as latent features. We design four quantifications (or derivatives) of input, output, and latent vectors of ViT-based models that provide a signature of the inference, which could be beneficial for the attack detection, and empirically study their behavior over clean samples and adversarial samples. The results demonstrate that the quantifications from input (images) and output (posterior probabilities) are promising for distinguishing clean and adversarial samples, while latent vectors offer less discriminative power, though they give some insights on how adversarial perturbations work.

READ FULL TEXT

page 8

page 14

research
07/01/2021

Using Anomaly Feature Vectors for Detecting, Classifying and Warning of Outlier Adversarial Examples

We present DeClaW, a system for detecting, classifying, and warning of a...
research
10/01/2022

Adversarial Attacks on Transformers-Based Malware Detectors

Signature-based malware detectors have proven to be insufficient as even...
research
03/16/2022

Patch-Fool: Are Vision Transformers Always Robust Against Adversarial Perturbations?

Vision transformers (ViTs) have recently set off a new wave in neural ar...
research
10/07/2022

Game-Theoretic Understanding of Misclassification

This paper analyzes various types of image misclassification from a game...
research
07/25/2023

On the unreasonable vulnerability of transformers for image restoration – and an easy fix

Following their success in visual recognition tasks, Vision Transformers...
research
06/18/2021

Less is More: Feature Selection for Adversarial Robustness with Compressive Counter-Adversarial Attacks

A common observation regarding adversarial attacks is that they mostly g...
research
08/04/2022

Self-Ensembling Vision Transformer (SEViT) for Robust Medical Image Classification

Vision Transformers (ViT) are competing to replace Convolutional Neural ...

Please sign up or login with your details

Forgot password? Click here to reset