Return
Detection Token: Detecting adversarial examples for Vision Transformers with one additional token
DOI:10.1016/j.hcc.2025.100353.png)
Abstract
En 中文
As the latest architecture, Vision Transformer (ViT) is vulnerable to adversarial attacks, which can cause errors in downstream tasks of the model. Previous defense methods against adversarial attacks tend to introduce significant inference latency or require additional training, resulting in increased defense costs. In this paper, we design a lightweight adversarial example detection framework for ViT, called Detection Token. By adding a pre-trained token called a detection token to the input token sequence, this token automatically collects adversarial information during the inference process and outputs linearly separable detection results along with the model output. Our method introduces only one additional token, requires minimal training overhead (converging within 2 ∼3 loops), and achieves high classification accuracy with minimal impact on normal tasks. Experiments on ImageNet demonstrate the effectiveness of our method, achieving an AUC score of 0.99 on three strong attacks (FGSM, PGD, BIM) on three representative ViTs, while the loss for normal tasks is less than 1%.
Keywords:
Security and privacy: Social aspects of security and privacy
Software and application security
Computing methodologies: Computer vision
Vision Transformer
AI security
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
H
IF:
3
Papers:
239
Citations:
407

