{"id":"https://openalex.org/W4375869363","doi":"https://doi.org/10.1109/icassp49357.2023.10096862","title":"Defending Against Universal Patch Attacks by Restricting Token Attention in Vision Transformers","display_name":"Defending Against Universal Patch Attacks by Restricting Token Attention in Vision Transformers","publication_year":2023,"publication_date":"2023-05-05","ids":{"openalex":"https://openalex.org/W4375869363","doi":"https://doi.org/10.1109/icassp49357.2023.10096862"},"language":"en","primary_location":{"id":"doi:10.1109/icassp49357.2023.10096862","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49357.2023.10096862","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2023 - 2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100647868","display_name":"Hongwei Yu","orcid":"https://orcid.org/0009-0009-8292-8964"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Hongwei Yu","raw_affiliation_strings":["University of Science and Technology Beijing,Beijing,China","University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology Beijing,Beijing,China","institution_ids":["https://openalex.org/I92403157"]},{"raw_affiliation_string":"University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100668653","display_name":"Jiansheng Chen","orcid":"https://orcid.org/0000-0002-2040-7938"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiansheng Chen","raw_affiliation_strings":["University of Science and Technology Beijing,Beijing,China","University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology Beijing,Beijing,China","institution_ids":["https://openalex.org/I92403157"]},{"raw_affiliation_string":"University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006236325","display_name":"Huimin Ma","orcid":"https://orcid.org/0000-0001-5383-5667"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huimin Ma","raw_affiliation_strings":["University of Science and Technology Beijing,Beijing,China","University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology Beijing,Beijing,China","institution_ids":["https://openalex.org/I92403157"]},{"raw_affiliation_string":"University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022741226","display_name":"Yu Cheng","orcid":"https://orcid.org/0000-0001-6717-5727"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Cheng Yu","raw_affiliation_strings":["Tsinghua University,Beijing,China","Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University,Beijing,China","institution_ids":["https://openalex.org/I99065089"]},{"raw_affiliation_string":"Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5032553368","display_name":"Xinlong Ding","orcid":"https://orcid.org/0000-0003-4853-5832"},"institutions":[{"id":"https://openalex.org/I92403157","display_name":"University of Science and Technology Beijing","ror":"https://ror.org/02egmk993","country_code":"CN","type":"education","lineage":["https://openalex.org/I92403157"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinlong Ding","raw_affiliation_strings":["University of Science and Technology Beijing,Beijing,China","University of Science and Technology Beijing, Beijing, China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology Beijing,Beijing,China","institution_ids":["https://openalex.org/I92403157"]},{"raw_affiliation_string":"University of Science and Technology Beijing, Beijing, China","institution_ids":["https://openalex.org/I92403157"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5100647868"],"corresponding_institution_ids":["https://openalex.org/I92403157"],"apc_list":null,"apc_paid":null,"fwci":0.1748,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.52432455,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"5"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9932000041007996,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.6899634599685669},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5387611389160156},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5332462787628174},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.47407522797584534},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.3439018428325653},{"id":"https://openalex.org/keywords/electrical-engineering","display_name":"Electrical engineering","score":0.1726851761341095},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.13323655724525452},{"id":"https://openalex.org/keywords/voltage","display_name":"Voltage","score":0.05441486835479736}],"concepts":[{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.6899634599685669},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5387611389160156},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5332462787628174},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.47407522797584534},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.3439018428325653},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.1726851761341095},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.13323655724525452},{"id":"https://openalex.org/C165801399","wikidata":"https://www.wikidata.org/wiki/Q25428","display_name":"Voltage","level":2,"score":0.05441486835479736}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp49357.2023.10096862","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49357.2023.10096862","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2023 - 2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W1932198206","https://openalex.org/W2535873859","https://openalex.org/W2618530766","https://openalex.org/W2783237807","https://openalex.org/W2902867332","https://openalex.org/W2942810103","https://openalex.org/W2963302614","https://openalex.org/W2964175514","https://openalex.org/W3017485054","https://openalex.org/W3035422918","https://openalex.org/W3094502228","https://openalex.org/W3097573595","https://openalex.org/W3099573537","https://openalex.org/W3145185940","https://openalex.org/W3194222974","https://openalex.org/W3202052293","https://openalex.org/W3205945722","https://openalex.org/W4224923640","https://openalex.org/W4224933361","https://openalex.org/W4312755170","https://openalex.org/W4385245566","https://openalex.org/W4394668313","https://openalex.org/W6739901393","https://openalex.org/W6747706139","https://openalex.org/W6751839145","https://openalex.org/W6761472960","https://openalex.org/W6766301176","https://openalex.org/W6784333009","https://openalex.org/W6864693536"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W4388335561","https://openalex.org/W2970530566","https://openalex.org/W4288261899","https://openalex.org/W4307309205","https://openalex.org/W2967478618","https://openalex.org/W4385009901","https://openalex.org/W4385572700","https://openalex.org/W4304700937"],"abstract_inverted_index":{"Previous":[0],"works":[1],"reveal":[2,23],"that":[3,27,90],"similar":[4],"to":[5,13],"CNNs,":[6],"vision":[7],"transformers":[8],"(ViT)":[9],"are":[10],"also":[11],"vulnerable":[12],"universal":[14,100],"adversarial":[15],"patch":[16,84,101],"attacks.":[17],"In":[18],"this":[19],"paper,":[20],"we":[21,68],"empirically":[22],"and":[24,34],"mathematically":[25],"explain":[26],"the":[28,32,35,38,43,54,62,74,80,83],"shallow":[29,56],"tokens":[30],"in":[31],"transformer":[33],"attention":[36,63,75],"of":[37,82],"network":[39],"can":[40,60,93],"largely":[41],"influence":[42,81],"classification":[44,106],"result.":[45],"Adversarial":[46],"patches":[47],"usually":[48],"produce":[49],"large":[50],"feature":[51],"norm":[52],"for":[53,108],"corresponding":[55],"token":[57],"vectors":[58],"which":[59,77],"attract":[61],"anomalously.":[64],"Inspired":[65],"by":[66],"this,":[67],"propose":[69],"a":[70],"restriction":[71],"operation":[72],"on":[73,87],"matrix,":[76],"effectively":[78,94],"reduces":[79],"region.":[85],"Experiments":[86],"ImageNet":[88],"validate":[89],"our":[91],"proposal":[92],"improve":[95],"ViT\u2019s":[96],"robustness":[97],"towards":[98],"white-box":[99],"attacks":[102],"while":[103],"maintaining":[104],"satisfactory":[105],"accuracy":[107],"clean":[109],"samples.":[110]},"counts_by_year":[{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
