• Home
  • Search
  • Robust Token Gradient and Frequency-Aware Transferable Adversarial Attacks on Vision Transformers
  • https://doi.org/10.1109/tifs.2025.3620638Copy DOI Icon

Robust Token Gradient and Frequency-Aware Transferable Adversarial Attacks on Vision Transformers

  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Vision Transformers (ViTs) have achieved remarkable performance in computer vision tasks but are vulnerable to adversarial attacks. Recent studies have demonstrated the feasibility of crafting transferable adversarial examples based on ViT models. However, the adversarial examples generated by ViTs exhibit poor generalization, primarily due to structural differences between models and the tendency to overfit, which significantly hinders cross-architecture transferability. In this paper, we propose a novel framework to improve the generalization and transferability of adversarial attacks across diverse models, focusing on two key strategies: Token Gradient Divergence (TGD) and Multi-level Frequency-aware Attack (MFA). TGD, as a gradient regularization method, addresses the structural gradient issue of surrogate models, which is one of the causes of overfitting. By increasing the gradient divergence between tokens and eliminating the influence of the class token gradient, TGD enhances the transferability of adversarial examples across models. Meanwhile, MFA employs an implicit ensemble approach to enhance attack generalization. Through multiple spectral augmentations, it increases input diversity and simulates ensemble learning. By targeting critical frequency regions across models, MFA enhances adversarial example adaptability to different architectures, significantly boosting cross-architecture transferability. Extensive experiments on both ViTs and CNNs demonstrate that TGD-MFA significantly outperforms state-of-the-art transfer-based attacks, achieving substantial improvements in adversarial transferability and robustness.

Similar Papers
  • Research Article
  • Citations5

Crafting Transferable Adversarial Examples Against Face Recognition via Gradient Eroding

  • Jan 01, 2024
  • IEEE Transactions on Artificial Intelligence
  • Huipeng Zhou +6
  • Video Transcripts

On the Transferability of Adversarial Attacks against Neural Text Classifier

  • Oct 15, 2021
  • Underline Science Inc.
  • Liping Yuan
  • Research Article
  • Citations11

Efficient Generation of Targeted and Transferable Adversarial Examples for Vision-Language Models via Diffusion Models

  • Jan 01, 2025
  • IEEE Transactions on Information Forensics and Security
  • Qi Guo +4
  • PDF
  • Research Article
  • Citations7

Adversarial attacks on cooperative multi-agent deep reinforcement learning: a dynamic group-based adversarial example transferability method

  • Jul 03, 2023
  • Complex & Intelligent Systems
  • Lixia Zan +2
  • Conference Article
  • Citations1

ADVRET: An Adversarial Robustness Evaluating and Testing Platform for Deep Learning Models

  • Dec 01, 2021
  • Fei Ren +4
  • Research Article
  • Citations9

Improving Ensemble Robustness by Collaboratively Promoting and Demoting Adversarial Robustness

  • May 18, 2021
  • Proceedings of the AAAI Conference on Artificial Intelligence
  • Anh Tuan Bui +6
  • Book Chapter
  • Citations3

Model Extraction and Adversarial Attacks on Neural Networks Using Switching Power Information

  • Jan 01, 2021
  • Tommy Li +1
  • Research Article
  • Citations1

Individual and Common Attack: Enhancing Transferability in VLP Models Through Modal Feature Exploitation.

  • Jan 01, 2026
  • IEEE transactions on image processing : a publication of the IEEE Signal Processing Society
  • Yaguan Qian +7
  • PDF
  • Research Article
  • Citations2

Efficient Adversarial Attack Based on Moment Estimation and Lookahead Gradient

  • Jun 24, 2024
  • Electronics
  • Dian Hong +6
  • Conference Article
  • Citations1

Temporal Consistency Constrained Transferable Adversarial Attacks with Background Mixup for Action Recognition

  • Sep 01, 2025
  • Ping Li +2
  • Research Article
  • Citations12

Transferable adversarial examples can efficiently fool topic models

  • May 02, 2022
  • Computers & Security
  • Zhen Wang +4
  • Research Article
  • Citations9

Global-Local Characteristic Excited Cross-Modal Attacks from Images to Videos

  • Jun 26, 2023
  • Proceedings of the AAAI Conference on Artificial Intelligence
  • Ruikui Wang +2
  • Conference Article
  • Citations7

Assessing transferability of adversarial examples against malware detection classifiers

  • Apr 30, 2019
  • Yixiang Wang +2
  • Research Article

Adversarial Example Generation Method Based on Wavelet Transform

  • Feb 10, 2026
  • Information
  • Meng Bi +5
  • PDF
  • Research Article
  • Citations34

Adversarial Attack for SAR Target Recognition Based on UNet-Generative Adversarial Network

  • Oct 29, 2021
  • Remote Sensing
  • Chuan Du +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.