Skip to main content
Fig. 2 | Cybersecurity

Fig. 2

From: Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks

Fig. 2

Maxwell’s demon Attack (MA). \(I_i\) represents the input of the Mixer layer \(l_i\), \(M_i\) is the masking matrix generated for \(I_i\) based on the Bernoulli distribution, and \(\odot\) represents the element-wise product. After \(I_i\) and \(M_i\) are multiplied, some elements in \(I_i\) are discarded. By masking the part input of each Mixer layer, MA breaks the token-mixing and channel-mixing of MLP-Mixer, preventing adversarial examples from overfitting MLP-Mixer, which can greatly improve the transferability of its generated adversarial examples

Back to article page