Pith. sign in

REVIEW 2 cited by

Backdoor Attacks on Vision Transformers

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2206.08477 v1 pith:6P4JYYMV submitted 2022-06-16 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords backdoorvitsattackscnnsimagestestvisionattacker
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Vision Transformers (ViT) have recently demonstrated exemplary performance on a variety of vision tasks and are being used as an alternative to CNNs. Their design is based on a self-attention mechanism that processes images as a sequence of patches, which is quite different compared to CNNs. Hence it is interesting to study if ViTs are vulnerable to backdoor attacks. Backdoor attacks happen when an attacker poisons a small part of the training data for malicious purposes. The model performance is good on clean test images, but the attacker can manipulate the decision of the model by showing the trigger at test time. To the best of our knowledge, we are the first to show that ViTs are vulnerable to backdoor attacks. We also find an intriguing difference between ViTs and CNNs - interpretation algorithms effectively highlight the trigger on test images for ViTs but not for CNNs. Based on this observation, we propose a test-time image blocking defense for ViTs which reduces the attack success rate by a large margin. Code is available here: https://github.com/UCDvision/backdoor_transformer.git

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. BadViM: Backdoor Attack against Vision Mamba

    cs.CR 2025-07 conditional novelty 6.0 of 10

    BadViM attacks Vision Mamba with a resonant frequency trigger plus hidden state alignment, reporting high attack success with little clean accuracy loss.

  2. An Effective and Resilient Backdoor Attack Framework against Deep Neural Networks and Vision Transformers

    cs.CV 2024-12 conditional novelty 5.0 of 10

    Attention-guided trigger placement with co-optimized training and alternating clean retraining achieves high backdoor attack success at low poison ratios on CNNs and vision transformers, while evading several publishe...

Pith tools