Pith. sign in

REVIEW 1 cited by

DeSparsify: Adversarial Attack Against Token Sparsification Mechanisms in Vision Transformers

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.02554 v2 pith:AKFRZASK submitted 2024-02-04 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords attackmechanismssparsificationtokenvisiontransformersadversarialdesparsify
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Vision transformers have contributed greatly to advancements in the computer vision domain, demonstrating state-of-the-art performance in diverse tasks (e.g., image classification, object detection). However, their high computational requirements grow quadratically with the number of tokens used. Token sparsification mechanisms have been proposed to address this issue. These mechanisms employ an input-dependent strategy, in which uninformative tokens are discarded from the computation pipeline, improving the model's efficiency. However, their dynamism and average-case assumption makes them vulnerable to a new threat vector - carefully crafted adversarial examples capable of fooling the sparsification mechanism, resulting in worst-case performance. In this paper, we present DeSparsify, an attack targeting the availability of vision transformers that use token sparsification mechanisms. The attack aims to exhaust the operating system's resources, while maintaining its stealthiness. Our evaluation demonstrates the attack's effectiveness on three token sparsification mechanisms and examines the attack's transferability between them and its effect on the GPU resources. To mitigate the impact of the attack, we propose various countermeasures.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Preventing Adversarial AI Attacks Against Autonomous Situational Awareness: A Maritime Case Study

    cs.CR 2025-05 conditional novelty 6.0 of 10

    DFCR combines AIS, radar, and optical object detection with validation components to lower AI confidence on adversarial contacts, reporting up to 100% loss reduction on patch and spoofing attacks.

Pith tools