{"id":"https://openalex.org/W7125917050","doi":"https://doi.org/10.1109/smc58881.2025.11342643","title":"ViTProbe: Defending Vision Transformers against Adversarial Patch Attacks through Single-Layer Inspection","display_name":"ViTProbe: Defending Vision Transformers against Adversarial Patch Attacks through Single-Layer Inspection","publication_year":2025,"publication_date":"2025-10-05","ids":{"openalex":"https://openalex.org/W7125917050","doi":"https://doi.org/10.1109/smc58881.2025.11342643"},"language":null,"primary_location":{"id":"doi:10.1109/smc58881.2025.11342643","is_oa":false,"landing_page_url":"https://doi.org/10.1109/smc58881.2025.11342643","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5124121894","display_name":"Fanjin Xu","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Fanjin Xu","raw_affiliation_strings":["National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"],"affiliations":[{"raw_affiliation_string":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071450288","display_name":"Qiuran Li","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qiuran Li","raw_affiliation_strings":["National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"],"affiliations":[{"raw_affiliation_string":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124130168","display_name":"Kaiyan Wen","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kaiyan Wen","raw_affiliation_strings":["National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"],"affiliations":[{"raw_affiliation_string":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5121057889","display_name":"Yaohua Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yaohua Wang","raw_affiliation_strings":["National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"],"affiliations":[{"raw_affiliation_string":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073","institution_ids":["https://openalex.org/I170215575"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5124121894"],"corresponding_institution_ids":["https://openalex.org/I170215575"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.83865597,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1791","last_page":"1798"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.991599977016449,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.991599977016449,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.00279999990016222,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.0006000000284984708,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9375},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.4300000071525574},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.365200012922287},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.2815999984741211},{"id":"https://openalex.org/keywords/camouflage","display_name":"Camouflage","score":0.23430000245571136}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9375},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6711000204086304},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.46720001101493835},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.44359999895095825},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.4300000071525574},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.365200012922287},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.2815999984741211},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.25360000133514404},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.23430000245571136},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.2290000021457672}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/smc58881.2025.11342643","is_oa":false,"landing_page_url":"https://doi.org/10.1109/smc58881.2025.11342643","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.8140060901641846}],"awards":[],"funders":[{"id":"https://openalex.org/F4320330944","display_name":"Nature","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":12,"referenced_works":["https://openalex.org/W2108598243","https://openalex.org/W3096609285","https://openalex.org/W3150962209","https://openalex.org/W3174350209","https://openalex.org/W3217804443","https://openalex.org/W4214612132","https://openalex.org/W4214893857","https://openalex.org/W4312755170","https://openalex.org/W4321151009","https://openalex.org/W4385245566","https://openalex.org/W4386066003","https://openalex.org/W4399422274"],"related_works":[],"abstract_inverted_index":{"Vision":[0],"Transformer":[1],"(ViT)":[2],"has":[3],"achieved":[4],"remarkable":[5],"performance":[6,183],"in":[7,134],"image":[8],"classification":[9,168],"but":[10],"remains":[11],"susceptible":[12],"to":[13,34,46,174,185,195],"natural":[14,35],"corruptions":[15,36],"and":[16,37,79,126],"adversarial":[17,40,81,103,113,140,171],"attacks.":[18,48],"These":[19],"attacks":[20,56,161,173],"fabricate":[21],"either":[22],"global":[23,38],"image-wide":[24,39],"or":[25,60],"localized":[26],"patch-based":[27,47],"perturbations.":[28],"Although":[29],"ViT":[30,53],"demonstrates":[31],"inherent":[32],"resilience":[33],"attacks,":[41],"it":[42],"is":[43,91,105],"still":[44],"vulnerable":[45],"Current":[49],"defense":[50,75,187],"methods":[51],"for":[52,154],"against":[54,158],"such":[55],"typically":[57],"involve":[58],"re-inference":[59],"layer-by-layer":[61],"analysis,":[62],"incurring":[63],"substantial":[64],"computational":[65,191],"costs.":[66],"To":[67],"address":[68],"this":[69,109],"issue,":[70],"we":[71],"introduce":[72],"ViTProbe,":[73],"a":[74,84],"mechanism":[76],"that":[77,93,163],"identifies":[78],"removes":[80],"patches":[82,114,141],"within":[83],"single":[85],"layer":[86],"of":[87,97,121,130,176],"the":[88,94,117,122,127,131,135,146,152,167,177],"model.":[89],"It":[90],"observed":[92],"relative":[95],"length":[96],"attention":[98,123],"score":[99,124],"associated":[100],"with":[101],"an":[102],"patch":[104,172],"extremely":[106],"low.":[107],"Leveraging":[108],"insight,":[110],"ViTProbe":[111,164],"detects":[112],"by":[115,193],"assessing":[116],"ratio":[118],"between":[119],"components":[120,129],"matrix":[125,133],"corresponding":[128],"input":[132],"model\u2019s":[136],"specific":[137],"layer.":[138],"Potential":[139],"are":[142],"discarded":[143],"before":[144],"forwarding":[145],"chosen":[147],"layer\u2019s":[148],"output,":[149],"thereby":[150],"eliminating":[151],"need":[153],"re-inference.":[155],"Comprehensive":[156],"evaluations":[157],"three":[159],"patched-based":[160],"demonstrate":[162],"can":[165],"recover":[166],"accuracy":[169,179],"under":[170],"94.17%":[175],"clean":[178],"on":[180],"average,":[181],"achieving":[182],"comparable":[184],"state-of-the-art":[186],"while":[188],"significantly":[189],"reducing":[190],"costs":[192],"up":[194],"95.67%.":[196]},"counts_by_year":[],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2026-01-29T00:00:00"}
