{"id":"https://openalex.org/W4402980106","doi":"https://doi.org/10.1109/icme57554.2024.10687455","title":"Enhancing Adversarial Transferability on Vision Transformer by Permutation-Invariant Attacks","display_name":"Enhancing Adversarial Transferability on Vision Transformer by Permutation-Invariant Attacks","publication_year":2024,"publication_date":"2024-07-15","ids":{"openalex":"https://openalex.org/W4402980106","doi":"https://doi.org/10.1109/icme57554.2024.10687455"},"language":"en","primary_location":{"id":"doi:10.1109/icme57554.2024.10687455","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme57554.2024.10687455","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101824758","display_name":"Haoyu Deng","orcid":"https://orcid.org/0000-0001-6637-0619"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Haoyu Deng","raw_affiliation_strings":["Shenzhen Campus of Sun Yat-sen University,School of Cyber Science and Technology,Shenzhen,China"],"affiliations":[{"raw_affiliation_string":"Shenzhen Campus of Sun Yat-sen University,School of Cyber Science and Technology,Shenzhen,China","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062946632","display_name":"Yanmei Fang","orcid":null},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yanmei Fang","raw_affiliation_strings":["Shenzhen Campus of Sun Yat-sen University,School of Cyber Science and Technology,Shenzhen,China"],"affiliations":[{"raw_affiliation_string":"Shenzhen Campus of Sun Yat-sen University,School of Cyber Science and Technology,Shenzhen,China","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102934173","display_name":"Fangjun Huang","orcid":"https://orcid.org/0000-0002-8219-6056"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Fangjun Huang","raw_affiliation_strings":["Shenzhen Campus of Sun Yat-sen University,School of Cyber Science and Technology,Shenzhen,China"],"affiliations":[{"raw_affiliation_string":"Shenzhen Campus of Sun Yat-sen University,School of Cyber Science and Technology,Shenzhen,China","institution_ids":["https://openalex.org/I157773358"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5101824758"],"corresponding_institution_ids":["https://openalex.org/I157773358"],"apc_list":null,"apc_paid":null,"fwci":1.0878,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.8158877,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9832000136375427,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9832000136375427,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11992","display_name":"CCD and CMOS Imaging Sensors","score":0.9740999937057495,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9686999917030334,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.7839280366897583},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6541999578475952},{"id":"https://openalex.org/keywords/invariant","display_name":"Invariant (physics)","score":0.617730438709259},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5959891080856323},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.5689994096755981},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4749346375465393},{"id":"https://openalex.org/keywords/permutation","display_name":"Permutation (music)","score":0.42865145206451416},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.41764742136001587},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3519178628921509},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.2278822362422943},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.20023539662361145},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.18343988060951233},{"id":"https://openalex.org/keywords/electrical-engineering","display_name":"Electrical engineering","score":0.09908109903335571},{"id":"https://openalex.org/keywords/art","display_name":"Art","score":0.06649452447891235}],"concepts":[{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.7839280366897583},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6541999578475952},{"id":"https://openalex.org/C190470478","wikidata":"https://www.wikidata.org/wiki/Q2370229","display_name":"Invariant (physics)","level":2,"score":0.617730438709259},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5959891080856323},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.5689994096755981},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4749346375465393},{"id":"https://openalex.org/C21308566","wikidata":"https://www.wikidata.org/wiki/Q7169365","display_name":"Permutation (music)","level":2,"score":0.42865145206451416},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.41764742136001587},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3519178628921509},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.2278822362422943},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.20023539662361145},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.18343988060951233},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.09908109903335571},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.06649452447891235},{"id":"https://openalex.org/C107038049","wikidata":"https://www.wikidata.org/wiki/Q35986","display_name":"Aesthetics","level":1,"score":0.0},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0},{"id":"https://openalex.org/C37914503","wikidata":"https://www.wikidata.org/wiki/Q156495","display_name":"Mathematical physics","level":1,"score":0.0},{"id":"https://openalex.org/C165801399","wikidata":"https://www.wikidata.org/wiki/Q25428","display_name":"Voltage","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icme57554.2024.10687455","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme57554.2024.10687455","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.4099999964237213,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W153185079","https://openalex.org/W2774644650","https://openalex.org/W2798302089","https://openalex.org/W2962847335","https://openalex.org/W2969542116","https://openalex.org/W3094502228","https://openalex.org/W3096609285","https://openalex.org/W3127807678","https://openalex.org/W3138516171","https://openalex.org/W3171288285","https://openalex.org/W3171516518","https://openalex.org/W3185095134","https://openalex.org/W3196621661","https://openalex.org/W4214893857","https://openalex.org/W4321151009","https://openalex.org/W4386072305","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6757555829","https://openalex.org/W6768366551","https://openalex.org/W6788135285","https://openalex.org/W6795475546","https://openalex.org/W6797399245","https://openalex.org/W6797592835"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W4392340763","https://openalex.org/W4283325551","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Vision":[0],"Transformers":[1],"(ViTs)":[2],"have":[3],"demonstrated":[4],"remarkable":[5],"performance":[6,138],"in":[7],"computer":[8],"vision.":[9],"However,":[10],"they":[11],"are":[12],"still":[13],"susceptible":[14],"to":[15,38,59,80,106,111],"adversarial":[16,25,42,76],"examples.":[17,43],"In":[18],"this":[19],"paper,":[20],"we":[21,45,71],"propose":[22],"a":[23,136],"novel":[24],"attack":[26,97,120],"method":[27],"tailored":[28],"for":[29,131],"ViTs,":[30],"by":[31],"leveraging":[32],"the":[33,47,56,67,74,81,94],"inherent":[34],"permutation-invariant":[35,95],"of":[36,51,140],"ViTs":[37,102,105,113],"generate":[39,60],"highly":[40],"transferable":[41],"Specifically,":[44],"split":[46],"image":[48,69],"into":[49],"patches":[50,58],"different":[52],"scales":[53],"and":[54,103,114,134],"permute":[55],"local":[57],"diverse":[61,112],"inputs.":[62],"By":[63],"optimizing":[64],"perturbations":[65],"on":[66,90,142],"permuted":[68],"set,":[70],"can":[72,115],"prevent":[73],"generated":[75],"examples":[77],"from":[78,104],"overfitting":[79],"surrogate":[82],"model,":[83],"thereby":[84],"enhancing":[85,123],"transferability.":[86,124],"Extensive":[87],"experiments":[88],"conducted":[89],"ImageNet":[91],"demonstrate":[92],"that":[93],"(PI)":[96],"significantly":[98],"improves":[99],"transferability":[100],"between":[101],"CNNs.":[107],"PI":[108],"is":[109],"applicable":[110],"seamlessly":[116],"integrate":[117],"with":[118],"existing":[119],"methods":[121,130],"further":[122],"Our":[125],"approach":[126],"surpasses":[127],"state-of-the-art":[128],"ensemble":[129],"input":[132],"transformation":[133],"achieves":[135],"notable":[137],"improvement":[139],"11.9%":[141],"average.":[143]},"counts_by_year":[{"year":2025,"cited_by_count":3}],"updated_date":"2025-12-23T23:11:35.936235","created_date":"2025-10-10T00:00:00"}
