{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:JGRKUWTMFZ3F6JFH7J7G7L5GQ6","short_pith_number":"pith:JGRKUWTM","schema_version":"1.0","canonical_sha256":"49a2aa5a6c2e765f24a7fa7e6fafa687a99c0ffcb04cc83f69a9152398ba5486","source":{"kind":"arxiv","id":"2106.04169","version":3},"attestation_state":"computed","paper":{"title":"On Improving Adversarial Transferability of Vision Transformers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CV","authors_text":"Fahad Shahbaz Khan, Fatih Porikli, Kanchana Ranasinghe, Muzammal Naseer, Salman Khan","submitted_at":"2021-06-08T08:20:38Z","abstract_excerpt":"Vision transformers (ViTs) process input images as sequences of patches via self-attention; a radically different architecture than convolutional neural networks (CNNs). This makes it interesting to study the adversarial feature space of ViT models and their transferability. In particular, we observe that adversarial patterns found via conventional adversarial attacks show very \\emph{low} black-box transferability even for large ViT models. We show that this phenomenon is only due to the sub-optimal attack procedures that do not leverage the true representation potential of ViTs. A deep ViT is"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2106.04169","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2021-06-08T08:20:38Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"85c9a04c3092e8f53b7da8d761c52d20581388cd70c3266626ac1ee5ecf1220a","abstract_canon_sha256":"5779b3e81323267bdff9e5f4969d5a2e61b9571613f433701db5f32ed0a3f065"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:01:41.838805Z","signature_b64":"fPNW6S2uvYgXrJj3qWQzas66rSCXaFJ2qvPX4PUsZpCFP9E2YcDJEUUJiBE5pc4/o5hjx0IPgqHiBuTl/k9rAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"49a2aa5a6c2e765f24a7fa7e6fafa687a99c0ffcb04cc83f69a9152398ba5486","last_reissued_at":"2026-07-05T04:01:41.838339Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:01:41.838339Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"On Improving Adversarial Transferability of Vision Transformers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CV","authors_text":"Fahad Shahbaz Khan, Fatih Porikli, Kanchana Ranasinghe, Muzammal Naseer, Salman Khan","submitted_at":"2021-06-08T08:20:38Z","abstract_excerpt":"Vision transformers (ViTs) process input images as sequences of patches via self-attention; a radically different architecture than convolutional neural networks (CNNs). This makes it interesting to study the adversarial feature space of ViT models and their transferability. In particular, we observe that adversarial patterns found via conventional adversarial attacks show very \\emph{low} black-box transferability even for large ViT models. We show that this phenomenon is only due to the sub-optimal attack procedures that do not leverage the true representation potential of ViTs. A deep ViT is"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2106.04169","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2106.04169/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2106.04169","created_at":"2026-07-05T04:01:41.838402+00:00"},{"alias_kind":"arxiv_version","alias_value":"2106.04169v3","created_at":"2026-07-05T04:01:41.838402+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2106.04169","created_at":"2026-07-05T04:01:41.838402+00:00"},{"alias_kind":"pith_short_12","alias_value":"JGRKUWTMFZ3F","created_at":"2026-07-05T04:01:41.838402+00:00"},{"alias_kind":"pith_short_16","alias_value":"JGRKUWTMFZ3F6JFH","created_at":"2026-07-05T04:01:41.838402+00:00"},{"alias_kind":"pith_short_8","alias_value":"JGRKUWTM","created_at":"2026-07-05T04:01:41.838402+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2502.05206","citing_title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10582","citing_title":"Guaranteed Jailbreaking Defense via Disrupt-and-Rectify Smoothing","ref_index":31,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6","json":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6.json","graph_json":"https://pith.science/api/pith-number/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/graph.json","events_json":"https://pith.science/api/pith-number/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/events.json","paper":"https://pith.science/paper/JGRKUWTM"},"agent_actions":{"view_html":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6","download_json":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6.json","view_paper":"https://pith.science/paper/JGRKUWTM","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2106.04169&json=true","fetch_graph":"https://pith.science/api/pith-number/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/graph.json","fetch_events":"https://pith.science/api/pith-number/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/action/storage_attestation","attest_author":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/action/author_attestation","sign_citation":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/action/citation_signature","submit_replication":"https://pith.science/pith/JGRKUWTMFZ3F6JFH7J7G7L5GQ6/action/replication_record"}},"created_at":"2026-07-05T04:01:41.838402+00:00","updated_at":"2026-07-05T04:01:41.838402+00:00"}