Skip to main content

Table 7 The attack success rate (ASR, %) versus average queries (Avg.Q) of different transformers trained on the ImageNet dataset

From: DTA: distribution transform-based attack for query-limited scenario

Metric

Model

100

200

300

400

500

ASR

ViT-16

29.93

33.04

35.16

35.91

37.53

ViT-32

34.35

38.08

39.28

40.61

41.01

Swin-B

26.63

29.35

29.23

30.77

31.48

Avg.Q

ViT-16

15.59

2.89

40.50

49.03

60.91

ViT-32

13.79

24.58

34.24

41.51

43.57

Swin-B

17.00

29.83

36.35

48.08

56.22