跳到主要导航 跳到搜索 跳到主要内容

Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks

  • Haoran Lyu
  • , Yajie Wang
  • , Yu An Tan
  • , Huipeng Zhou
  • , Yuhang Zhao
  • , Quanxin Zhang*
  • *此作品的通讯作者
  • Beijing Institute of Technology

科研成果: 期刊稿件文章同行评审

摘要

Models based on MLP-Mixer architecture are becoming popular, but they still suffer from adversarial examples. Although it has been shown that MLP-Mixer is more robust to adversarial attacks compared to convolutional neural networks (CNNs), there has been no research on adversarial attacks tailored to its architecture. In this paper, we fill this gap. We propose a dedicated attack framework called Maxwell’s demon Attack (MA). Specifically, we break the channel-mixing and token-mixing mechanisms of the MLP-Mixer by perturbing inputs of each Mixer layer to achieve high transferability. We demonstrate that disrupting the MLP-Mixer’s capture of the main information of images by masking its inputs can generate adversarial examples with cross-architectural transferability. Extensive evaluations show the effectiveness and superior performance of MA. Perturbations generated based on masked inputs obtain a higher success rate of black-box attacks than existing transfer attacks. Moreover, our approach can be easily combined with existing methods to improve the transferability both within MLP-Mixer based models and to models with different architectures. We achieve up to 55.9% attack performance improvement. Our work exploits the true generalization potential of the MLP-Mixer adversarial space and helps make it more robust for future deployments.

源语言英语
文章编号6
期刊Cybersecurity
7
1
DOI
出版状态已出版 - 12月 2024

指纹

探究 'Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks' 的科研主题。它们共同构成独一无二的指纹。

引用此