Passer à la navigation principale Passer à la recherche Passer au contenu principal

Vision transformers: The threat of realistic adversarial patches

  • Vrije Universiteit Brussel
  • Open University of the Netherlands
  • NLDA
  • Fraunhofer IOSB
  • Interuniversitair Micro-Electronica Centrum vzw

Résultats de recherche: Chapitre dans un livre, un rapport, des actes de conférencesContribution à une conférenceRevue par des pairs

Résumé

The increasing reliance on machine learning systems has made their security a critical concern. Evasion attacks enable adversaries to manipulate the decision-making processes of AI systems, potentially causing security breaches or misclassification of targets. Vision Transformers (ViTs) have gained significant traction in modern machine learning due to increased 1) performance compared to Convolutional Neural Networks (CNNs) and 2) robustness against adversarial perturbations. However, ViTs remain vulnerable to evasion attacks, particularly to adversarial patches, unique patterns designed to manipulate AI classification systems. These vulnerabilities are investigated by designing realistic adversarial patches to cause misclassification in person vs. non-person classification tasks using the Creases Transformation (CT) technique, which adds subtle geometric distortions similar to those occurring naturally when wearing clothing. This study investigates the transferability of adversarial attack techniques used in CNNs when applied to ViT classification models. Experimental evaluation across four fine-tuned ViT models on a binary person classification task reveals significant vulnerability variations: attack success rates ranged from 40.04% (google/vit-base-patch16-224-in21k) to 99.97% (facebook/dino-vitb16), with google/vit-base-patch16-224 achieving 66.40% and facebook/dinov3-vitb16 reaching 65.17%. These results confirm the cross-architectural transferability of adversarial patches from CNNs to ViTs, with pre-training dataset scale and methodology strongly influencing model resilience to adversarial attacks.

langue originaleAnglais
titreArtificial Intelligence for Security and Defence Applications III
rédacteurs en chefHugo J. Kuijf, Radhakrishna Prabhu, Yitzhak Yitzhaky
EditeurSociety of Photo-Optical Instrumentation Engineers
ISBN (Electronique)9781510692978
Les DOIs
étatPublié - 28 oct. 2025
Evénement3rd Artificial Intelligence for Security and Defence Applications - Madrid, Espagne
Durée: 16 sept. 202518 sept. 2025

Série de publications

NomProceedings of SPIE - The International Society for Optical Engineering
Volume13679
ISSN (imprimé)0277-786X
ISSN (Electronique)1996-756X

Une conférence

Une conférence3rd Artificial Intelligence for Security and Defence Applications
Pays/TerritoireEspagne
La villeMadrid
période16/09/2518/09/25

Empreinte digitale

Examiner les sujets de recherche de « Vision transformers: The threat of realistic adversarial patches ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation