Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

A Feature Map Adversarial Attack Against Vision Transformers

Author 1: Majed Altoub Author 2: Rashid Mehmood Author 3: Fahad AlQurashi Author 4: Saad Alqahtany Author 5: Bassma Alsulami
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 15, No. 10 · Published 2024

DOI: https://doi.org/10.14569/IJACSA.2024.0151097

Abstract

Image classification is a domain where Deep Neural Networks (DNNs) have demonstrated remarkable achievements. Recently, Vision Transformers (ViTs) have shown potential in handling large-scale image classification challenges by efficiently scaling to higher resolutions and accommodating larger input sizes compared to traditional Convolutional Neural Networks (CNNs). However, in the context of adversarial attacks, ViTs are still considered vulnerable. Feature maps serve as the foundation for representing and extracting meaningful information from images. While CNNs excel at capturing local features and spatial relationships, ViTs are better at understanding global context and long-range dependencies. This paper proposes a feature map ViT-specific adversarial example attack called Feature Map ViT-specific Attack (FMViTA). The objective of the investigation is to generate adversarial perturbations in the spatial and frequency domains of the image representation that allow deeper distance measurement between perturbed and targeted images. The experiments focus on a ViT pre-trained model that is fine-tuned on the ImageNet dataset. The proposed attack demonstrates the vulnerability of ViTs to adversarial examples by showing that even allowing only 0.02 maximum perturbation magnitude to be added to the input samples gives 100% attack success rate.

Keywords

How to Cite this Article

Altoub, M., Mehmood, R., AlQurashi, F., Alqahtany, S., & Alsulami, B. (2024). A Feature Map Adversarial Attack Against Vision Transformers. International Journal of Advanced Computer Science and Applications, 15(10). https://doi.org/10.14569/IJACSA.2024.0151097

Altoub, Majed, et al.. "A Feature Map Adversarial Attack Against Vision Transformers." International Journal of Advanced Computer Science and Applications, vol. 15, no. 10, 2024, https://doi.org/10.14569/IJACSA.2024.0151097.

@article{Altoub2024,
  title     = {A Feature Map Adversarial Attack Against Vision Transformers},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {15},
  number    = {10},
  year      = {2024},
  publisher = {The Science and Information Organization},
  author    = {Majed Altoub and Rashid Mehmood and Fahad AlQurashi and Saad Alqahtany and Bassma Alsulami},
  doi       = {10.14569/IJACSA.2024.0151097},
  url       = {https://doi.org/10.14569/IJACSA.2024.0151097}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.