{"id":"https://openalex.org/W4304092585","doi":"https://doi.org/10.1145/3503161.3547989","title":"Generating Transferable Adversarial Examples against Vision Transformers","display_name":"Generating Transferable Adversarial Examples against Vision Transformers","publication_year":2022,"publication_date":"2022-10-10","ids":{"openalex":"https://openalex.org/W4304092585","doi":"https://doi.org/10.1145/3503161.3547989"},"language":"en","primary_location":{"id":"doi:10.1145/3503161.3547989","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3503161.3547989","pdf_url":null,"source":{"id":"https://openalex.org/S4363608757","display_name":"Proceedings of the 30th ACM International Conference on Multimedia","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5103854502","display_name":"Yuxuan Wang","orcid":"https://orcid.org/0000-0001-8269-3354"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuxuan Wang","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031116553","display_name":"Jiakai Wang","orcid":"https://orcid.org/0000-0001-5884-3412"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiakai Wang","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, Beijing, China","Zhongguancun Laboratory, State Key Lab of Software Development Environment, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]},{"raw_affiliation_string":"Zhongguancun Laboratory, State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103163232","display_name":"Zixin Yin","orcid":"https://orcid.org/0000-0002-2129-9182"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zixin Yin","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048414655","display_name":"Ruihao Gong","orcid":"https://orcid.org/0000-0002-6024-7086"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ruihao Gong","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, SenseTime, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, SenseTime, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084694747","display_name":"Jingyi Wang","orcid":"https://orcid.org/0000-0002-6009-1288"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jingyi Wang","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, Beijing, China","Zhongguancun Laboratory, State Key Lab of Software Development Environment, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]},{"raw_affiliation_string":"Zhongguancun Laboratory, State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014870180","display_name":"Aishan Liu","orcid":"https://orcid.org/0000-0002-4224-1318"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Aishan Liu","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5024067284","display_name":"Xianglong Liu","orcid":"https://orcid.org/0000-0002-7618-3275"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xianglong Liu","raw_affiliation_strings":["State Key Lab of Software Development Environment, Beihang University, Zhongguancun Laboratory, Beijing, China"],"affiliations":[{"raw_affiliation_string":"State Key Lab of Software Development Environment, Beihang University, Zhongguancun Laboratory, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5103854502"],"corresponding_institution_ids":["https://openalex.org/I82880672"],"apc_list":null,"apc_paid":null,"fwci":2.4946,"has_fulltext":false,"cited_by_count":24,"citation_normalized_percentile":{"value":0.91246499,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"5181","last_page":"5190"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9458000063896179,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9196000099182129,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8729424476623535},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7913057804107666},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.750118613243103},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.673208475112915},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.6037328839302063},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5293546319007874},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.48715850710868835},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4135291874408722},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.10122182965278625}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8729424476623535},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7913057804107666},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.750118613243103},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.673208475112915},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.6037328839302063},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5293546319007874},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.48715850710868835},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4135291874408722},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.10122182965278625},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C165801399","wikidata":"https://www.wikidata.org/wiki/Q25428","display_name":"Voltage","level":2,"score":0.0},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3503161.3547989","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3503161.3547989","pdf_url":null,"source":{"id":"https://openalex.org/S4363608757","display_name":"Proceedings of the 30th ACM International Conference on Multimedia","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G8074231069","display_name":null,"funder_award_id":"62022009 and 61872021","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":38,"referenced_works":["https://openalex.org/W2117539524","https://openalex.org/W2187089797","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2560674852","https://openalex.org/W2603766943","https://openalex.org/W2765424254","https://openalex.org/W2905423756","https://openalex.org/W2963446712","https://openalex.org/W3009454144","https://openalex.org/W3024215945","https://openalex.org/W3034665604","https://openalex.org/W3035467948","https://openalex.org/W3092738584","https://openalex.org/W3098144627","https://openalex.org/W3103557498","https://openalex.org/W3104771364","https://openalex.org/W3107530881","https://openalex.org/W3108324072","https://openalex.org/W3121523901","https://openalex.org/W3138516171","https://openalex.org/W3143373604","https://openalex.org/W3159235206","https://openalex.org/W3171288715","https://openalex.org/W3174032462","https://openalex.org/W3176477939","https://openalex.org/W3185095134","https://openalex.org/W3203460211","https://openalex.org/W3203497300","https://openalex.org/W3213646008","https://openalex.org/W3215515227","https://openalex.org/W4214540501","https://openalex.org/W4214612132","https://openalex.org/W4214893857","https://openalex.org/W4226142617","https://openalex.org/W6784508965","https://openalex.org/W6922057760","https://openalex.org/W6931259419"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W2997056298","https://openalex.org/W2950864148","https://openalex.org/W2570685808"],"abstract_inverted_index":{"Vision":[0],"transformers":[1,171],"(ViTs)":[2],"are":[3,32,121],"prevailing":[4],"among":[5,35,150,159],"several":[6],"visual":[7],"recognition":[8],"tasks,":[9],"therefore":[10,98],"drawing":[11],"intensive":[12],"interest":[13],"in":[14,112],"generating":[15],"adversarial":[16,43,74],"examples":[17,75],"against":[18],"them.":[19],"Different":[20],"from":[21,46],"CNNs,":[22],"ViTs":[23],"enjoy":[24],"unique":[25,145],"architectures,":[26],"e.g.,":[27],"self-attention":[28],"and":[29,81,107],"image-embedding,":[30],"which":[31,133],"commonly-shared":[33],"features":[34,149],"various":[36,169],"types":[37],"of":[38,55,103],"transformer-based":[39,151],"models.":[40],"However,":[41],"existing":[42],"methods":[44],"suffer":[45],"weak":[47],"transferable":[48,73,139],"attacking":[49,118,140,157],"ability":[50],"due":[51],"to":[52,71,124],"the":[53,61,78,83,89,101,104,109,116,126,144],"overlook":[54],"these":[56],"architectural":[57,148],"features.":[58],"To":[59],"address":[60],"problem,":[62],"we":[63,86,114,153],"propose":[64],"an":[65],"Architecture-oriented":[66],"Transferable":[67],"Attacking":[68],"(ATA)":[69],"framework":[70],"generate":[72],"by":[76,179],"activating":[77,100],"uncertain":[79],"attention":[80,105],"perturbing":[82],"sensitive":[84,130],"embedding.Specifically,":[85],"first":[87],"locate":[88],"patch-wise":[90],"attentional":[91],"regions":[92],"that":[93,120,173],"mostly":[94],"affect":[95],"model":[96,110],"perception,":[97],"intensively":[99],"uncertainty":[102],"mechanism":[106],"confusing":[108,143],"decisions":[111],"turn.Furthermore,":[113],"search":[115],"pixel-wise":[117],"positions":[119],"more":[122],"likely":[123],"derange":[125],"embedded":[127],"tokens":[128],"using":[129,168],"embedding":[131],"perturbation,":[132],"could":[134],"serve":[135],"as":[136],"a":[137],"strong":[138,156],"pattern.By":[141],"jointly":[142],"yet":[146],"widely-used":[147],"models,":[152],"can":[154],"activate":[155],"transferability":[158],"diverse":[160],"ViTs.":[161],"Extensive":[162],"experiments":[163],"on":[164],"large-scale":[165],"dataset":[166],"ImageNet":[167],"popular":[170],"demonstrate":[172],"our":[174],"ATA":[175],"outperforms":[176],"other":[177],"baselines":[178],"large":[180],"margins":[181],"(at":[182],"least":[183],"+15%":[184],"Attack":[185],"Success":[186],"Rate).":[187],"Our":[188],"code":[189],"is":[190],"available":[191],"at":[192],"https://github.com/nlsde-safety-team/ATA":[193]},"counts_by_year":[{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":12},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
