Research Article
FAPA: Transferable Adversarial Attacks Based on Foreground Attention
Table 1
Attack success rate of the typical algorithm in the ViT model (%).
| Method | PiT-B | CaiT-S-24 | Visformer-S | TNT-S | LeViT-256 | ConViT-B | Mean |
| FGSM | 19.80 | 20.43 | 19.37 | 22.78 | 18.80 | 25.58 | 21.12 | BIM | 22.17 | 22.63 | 22.70 | 32.13 | 20.45 | 35.30 | 25.89 | MI | 45.23 | 47.13 | 45.97 | 55.23 | 43.75 | 58.25 | 49.26 | DI | 45.13 | 43.07 | 47.77 | 55.18 | 43.25 | 49.35 | 47.29 | TI | 17.67 | 16.50 | 19.00 | 28.18 | 13.70 | 27.53 | 20.43 | SIM | 32.73 | 35.17 | 31.13 | 46.73 | 36.43 | 45.68 | 37.98 | SGM | 41.60 | 52.30 | 48.80 | 64.33 | 51.13 | 60.68 | 53.14 | IR | 22.70 | 24.00 | 23.43 | 33.43 | 21.30 | 36.38 | 26.87 | TAP | 24.73 | 33.40 | 32.20 | 39.78 | 30.03 | 42.20 | 33.72 | ATA | 1.13 | 0.97 | 2.67 | 3.37 | 2.02 | 3.72 | 2.31 | SE | 21.25 | 31.40 | 24.90 | 37.87 | 21.73 | 46.03 | 30.53 |
|
|