Skip to main content

Table 1 The fooling rate (%) on 1k ImageNet val

From: Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks

Attack

Mixer-B/16

Mixer-L/16

ResMLP-36

ViT-B/16

Deit-B

VGG-16

ResNet-50

MoNet-V2

Source Model: Mixer-B/16

PGD

100.0

35.2

18.5

9.6

7.6

5.4

2.6

6.7

PGD+MA

99.7 (− 0.3)

77.3 (+ 42.1)

33.7 (+ 15.2)

11.1 (+ 1.5)

13.8 (+ 6.2)

27.7 (+ 22.3)

14.6 (+ 12.0)

30.7 (+ 24.0)

PGD+SE

100.0

88.6

50.6

18.0

23.9

31.0

16.4

35.7

PGD+SE+MA

99.9 (− 0.1)

86.1 (− 2.5)

55.7 (+ 5.1)

27.8 (+ 9.8)

35.1 (+ 11.2)

58.8 (+ 27.8)

32.8 (+ 16.4)

56.2 (+ 20.5)

PGD+TR

100.0

86.9

59.4

23.6

30.2

55.1

22.8

48.6

PGD+TR+MA

99.8 (− 0.2)

92.3 (+ 5.4)

76.0 (+ 16.6)

52.6 (+ 29.0)

59.6 (+ 29.4)

78.6 (+ 23.5)

44.4 (+ 21.6)

71.5 (+ 22.9)

MIM

100.0

47.3

21.5

8.7

12.3

21.3

9.60

23.6

MIM+MA

100.0 (+ 0.0)

88.2 (+ 40.9)

52.2 (+ 30.7)

22.0 (+ 13.3)

38.7 (+ 26.4)

41.6 (+ 20.3)

22.6 (+ 13.0)

43.9 (+ 20.3)

MIM+SE

100.0

89.3

55.7

27.7

37.6

52.3

28.2

50.0

MIM+SE+MA

100.0 (+ 0.0)

91.3 (+ 2.0)

63.9 (+ 8.2)

32.6 (+ 4.9)

46.2 (+ 8.6)

62.5 (+ 10.2)

35.2 (+ 7.00)

61.7 (+ 11.7)

MIM+TR

100.0

86.0

60.7

33.1

38.5

63.4

31.1

59.6

MIM+TR+MA

100.0 (+ 0.0)

91.2 (+ 5.2)

73.3 (+ 12.6)

50.0 (+ 16.9)

53.3 (+ 14.8)

75.5 (+ 12.1)

42.5 (+ 11.4)

69.9 (+ 10.3)

DIM

100.0

58.7

26.1

7.1

7.7

8.9

6.1

13.9

DIM+MA

100.0 (+ 0.0)

92.6 (+ 33.9)

57.8 (+ 31.7)

16.7 (+ 9.6)

22.5 (+ 14.8)

31.4 (+ 22.5)

18.0 (+ 11.9)

36.6 (+ 22.7)

DIM+SE

100.0

97.0

77.9

33.8

45.1

50.4

33.6

56.2

DIM+SE+MA

100.0 (+ 0.0)

96.6 (− 0.4)

82.6 (+ 4.7)

43.1 (+ 9.3)

54.9 (+ 9.8)

69.8 (+ 19.4)

42.8 (+ 9.2)

69.1 (+ 12.9)

DIM+TR

100.0

95.4

83.1

40.9

55.7

69.7

41.3

67.3

DIM+TR+MA

100.0 (+ 0.0)

96.0 (+ 0.6)

86.9 (+ 3.8)

61.6 (+ 20.7)

70.9 (+ 15.2)

81.6 (+ 11.9)

54.5 (+ 13.2)

78.3 (+ 11.0)

TIM

100.0

35.3

9.2

2.8

2.3

5.6

2.5

6.8

TIM+MA

99.8 (− 0.2)

77.4 (+ 42.1)

33.8 (+ 24.6)

11.5 (+ 8.7)

15.2 (+ 12.9)

27.5 (+ 21.9)

13.8 (+ 11.3)

30.6 (+ 23.8)

TIM+SE

100.0

88.8

52.8

17.9

25.2

31.9

17.4

36.1

TIM+SE+MA

99.8 (− 0.2)

86.3 (− 2.5)

56.8 (+ 4.0)

27.9 (+ 10.0)

35.3 (+ 10.1)

60.0 (+ 28.1)

34.0 (+ 16.6)

56.4 (+ 20.3)

TIM+TR

100.0

87.2

59.8

23.9

29.8

54.1

22.6

48.8

TIM+TR+MA

99.8 (− 0.2)

93.2 (+ 6.0)

77.4 (+ 17.6)

53.2 (+ 29.3)

59.4 (+ 29.6)

80.3 (+ 26.2)

45.7 (+ 23.1)

71.6 (+ 22.8)

Source Model: Mixer-L/16

PGD

21.0

100.0

2.5

1.3

0.3

3.4

1.5

4.3

PGD+MA

38.7 (+ 17.7)

99.1 (− 0.9)

7.6 (+ 5.1)

2.1 (+ 0.8)

1.8 (+ 1.5)

10.8 (+ 7.4)

5.0 (+ 3.5)

12.6 (+ 8.3)

PGD+SE

88.2

100.0

38.5

14.5

16.0

28.2

14.3

27.9

PGD+SE+MA

83.4 (− 4.8)

99.6 (− 0.4)

47.1 (+ 8.6)

23.1 (+ 8.6)

26.0 (+ 10.0)

47.1 (+ 18.9)

24.2 (+ 9.9)

44.4 (+ 16.5)

PGD+TR

93.0

100.0

66.7

32.4

42.6

58.0

28.7

53.9

PGD+TR+MA

94.0 (+ 1.0)

99.8 (− 0.2)

79.1 (+ 12.4)

56.7 (+ 24.3)

60.3 (+ 17.7)

78.8 (+ 20.8)

47.7 (+ 19.0)

73.5 (+ 19.6)

MIM

31.9

100.0

8.5

4.9

2.8

16.9

7.0

16.4

MIM+MA

51.8 (+ 19.9)

99.4 (− 0.6)

13.6 (+ 5.1)

6.2 (+ 1.3)

5.9 (+ 3.1)

26.5 (+ 9.6)

12.4 (+ 5.4)

26.9 (+ 10.5)

MIM+SE

89.0

100.0

46.3

23.5

23.7

46.6

23.9

45.7

MIM+SE+MA

85.6 (− 3.4)

99.6 (− 0.4)

50.2 (+ 3.9)

26.9 (+ 3.4)

30.2 (+ 6.5)

56.1 (+ 9.5)

30.6 (+ 6.7)

51.2 (+ 10.5)

MIM+TR

91.9

100.0

70.2

42.7

47.4

67.7

36.3

64.1

MIM+TR+MA

94.4 (+ 2.5)

99.8 (− 0.2)

79.3 (+ 9.3)

59.1 (+ 16.4)

63.6 (+ 16.2)

81.8 (+ 14.1)

51.9 (+ 15.6)

77.5 (+ 13.4)

DIM

36.1

100.0

6.9

2.5

2.1

5.4

3.7

7.4

DIM+MA

92.0 (+ 55.9)

100.0 (+ 0.0)

44.9 (+ 38.0)

11.8 (+ 9.3)

15.1 (+ 13.0)

18.8 (+ 13.4)

11.4 (+ 7.7)

25.8 (+ 18.4)

DIM+SE

95.9

100.0

65.5

28.5

36.3

46.4

27.2

47.9

DIM+SE+MA

98.3 (+ 2.4)

100.0 (+ 0.0)

80.1 (+ 14.6)

40.6 (+ 12.1)

53.2 (+ 16.9)

62.9 (+ 16.5)

40.1 (+ 12.9)

62.4 (+ 14.5)

DIM+TR

96.1

100.0

82.0

46.9

60.4

71.0

41.9

69.1

DIM+TR+MA

97.9 (+ 1.8)

100.0 (+ 0.0)

89.0 (+ 7.0)

66.5 (+ 19.6)

74.0 (+ 13.6)

83.5 (+ 12.5)

57.8 (+ 15.9)

79.6 (+ 10.5)

TIM

21.4

100.0

2.9

1.2

0.4

3.3

2.0

4.4

TIM+MA

38.7 (+ 17.3)

98.8 (− 1.2)

7.8 (+ 4.9)

3.0 (+ 1.8)

1.6 (+ 1.2)

10.9 (+ 7.6)

4.9 (+ 2.9)

12.6 (+ 8.2)

TIM+SE

88.3

100.0

39.1

14.6

16.3

29.0

14.8

29.9

TIM+SE+MA

82.8 (− 5.5)

99.6 (− 0.4)

47.3 (+ 8.2)

23.2 (+ 8.6)

25.6 (+ 9.3)

47.9 (+ 18.9)

24.6 (+ 9.8)

44.6 (+ 14.7)

TIM+TR

92.3

100.0

67.8

34.1

42.7

58.2

28.9

54.0

TIM+TR+MA

93.7 (+ 1.4)

99.8 (− 0.2)

78.6 (+ 10.8)

58.2 (+ 24.1)

60.8 (+ 18.1)

79.0 (+ 20.8)

48.7 (+ 19.8)

74.9 (+ 20.9)

  1. The adversarial examples at \(\epsilon \le\) 16. The adversarial examples generated by our proposed MA method have a significantly higher fooling rate. We generated adversarial examples on Mixer-B/16 and Mixer-L/16, and conducted transferability experiments on networks of different architectures. Our MA method combined with existing adversarial attack methods can comprehensively improve the transferability of adversarial examples on MLP-based models, transformer-based models and CNN-based models