Boosting Transferability in Vision-Language Attacks via Diversification Along the Intersection Region of Adversarial Trajectory

Page view(s)
12
Checked on Aug 10, 2025
Boosting Transferability in Vision-Language Attacks via Diversification Along the Intersection Region of Adversarial Trajectory
Title:
Boosting Transferability in Vision-Language Attacks via Diversification Along the Intersection Region of Adversarial Trajectory
Journal Title:
Computer Vision – European Conference on Computer Vision 2024
Keywords:
Publication Date:
29 September 2024
Citation:
Gao, S., Jia, X., Ren, X., Tsang, I., & Guo, Q. (2024). Boosting Transferability in Vision-Language Attacks via Diversification Along the Intersection Region of Adversarial Trajectory. In Computer Vision – ECCV 2024 (pp. 442–460). Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-72998-0_25
Abstract:
Vision-language pre-training (VLP) models exhibit remarkable capabilities in comprehending both images and text, yet they remain susceptible to multimodal adversarial examples (AEs). Strengthening attacks and uncovering vulnerabilities, especially common issues in VLP models (e.g., high transferable AEs), can advance reliable and practical VLP models. A recent work (i.e., Set-level guidance attack) indicates that augmenting image-text pairs to increase AE diversity along the optimization path enhances the transferability of adversarial examples significantly. However, this approach predominantly emphasizes diversity around the online adversarial examples (i.e., AEs in the optimization period), leading to the risk of overfitting the victim model and affecting the transferability. In this study, we posit that the diversity of adversarial examples towards the clean input and online AEs are both pivotal for enhancing transferability across VLP models. Consequently, we propose using diversification along the intersection region of adversarial trajectory to expand the diversity of AEs. To fully leverage the interaction between modalities, we introduce text-guided adversarial example selection during optimization. Furthermore, to further mitigate the potential overfitting, we direct the adversarial text deviating from the last intersection region along the optimization path, rather than adversarial images as in existing methods. Extensive experiments affirm the effectiveness of our method in improving transferability across various VLP models and downstream vision-and-language tasks. Code is available at https://github.com/SensenGao/VLPTransferAttack.
License type:
Publisher Copyright
Funding Info:
This research / project is supported by the National Research Foundation, Singapore and Infocomm Media Development Authority - Trust Tech Funding Initiative
Grant Reference no. : DTC-RGC-04

This research / project is supported by the National Research Foundation, Singapore, and DSO National Laboratories - AI Singapore Programme
Grant Reference no. : AISG2-GC-2023-008

This research / project is supported by the Agency for Science, Technology and Research (A*STAR) - Career Development Fund (CDF)
Grant Reference no. : C233312028
Description:
This is a post-peer-review, pre-copyedit version of an article published in Computer Vision – ECCV 2024. The final authenticated version is available online at: http://dx.doi.org/10.1007/978-3-031-72998-0_25
ISSN:
9783031729980
ISBN:
9783031729973
Files uploaded:

File Size Format Action
20240928-eccv-gaosensen.pdf 7.19 MB PDF Open