Patch-Fool: Are Vision Transformers Always Robust Against Adversarial Perturbations?

Vision transformers (ViTs) have recently set off a new wave in neural\narchitecture design thanks to their record-breaking performance in various\nvision tasks. In parallel, to fulfill the goal of deploying ViTs into\nreal-world vision applications, their robustness against potential malicious\nattacks has gained increasing attention. In particular, recent works show that\nViTs are more robust against adversarial attacks as compared with convolutional\nneural networks (CNNs), and conjecture that this is because ViTs focus more on\ncapturing global interactions among different input/feature patches, leading to\ntheir improved robustness to local perturbations imposed by adversarial\nattacks. In this work, we ask an intriguing question: "Under what kinds of\nperturbations do ViTs become more vulnerable learners compared to CNNs?" Driven\nby this question, we first conduct a comprehensive experiment regarding the\nrobustness of both ViTs and CNNs under various existing adversarial attacks to\nunderstand the underlying reason favoring their robustness. Based on the drawn\ninsights, we then propose a dedicated attack framework, dubbed Patch-Fool, that\nfools the self-attention mechanism by attacking its basic component (i.e., a\nsingle patch) with a series of attention-aware optimization techniques.\nInterestingly, our Patch-Fool framework shows for the first time that ViTs are\nnot necessarily more robust than CNNs against adversarial perturbations. In\nparticular, we find that ViTs are more vulnerable learners compared with CNNs\nagainst our Patch-Fool attack which is consistent across extensive experiments,\nand the observations from Sparse/Mild Patch-Fool, two variants of Patch-Fool,\nindicate an intriguing insight that the perturbation density and strength on\neach patch seem to be the key factors that influence the robustness ranking\nbetween ViTs and CNNs.\n

Paper

References (81)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC