Research Article

FAPA: Transferable Adversarial Attacks Based on Foreground Attention

Table 1

Attack success rate of the typical algorithm in the ViT model (%).

MethodPiT-BCaiT-S-24Visformer-STNT-SLeViT-256ConViT-BMean

FGSM19.8020.4319.3722.7818.8025.5821.12
BIM22.1722.6322.7032.1320.4535.3025.89
MI45.2347.1345.9755.2343.7558.2549.26
DI45.1343.0747.7755.1843.2549.3547.29
TI17.6716.5019.0028.1813.7027.5320.43
SIM32.7335.1731.1346.7336.4345.6837.98
SGM41.6052.3048.8064.3351.1360.6853.14
IR22.7024.0023.4333.4321.3036.3826.87
TAP24.7333.4032.2039.7830.0342.2033.72
ATA1.130.972.673.372.023.722.31
SE21.2531.4024.9037.8721.7346.0330.53