Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Towards Adversarial Attack on Vision-Language Pre-training Models

About

While vision-language pre-training model (VLP) has shown revolutionary improvements on various vision-language (V+L) tasks, the studies regarding its adversarial robustness remain largely unexplored. This paper studied the adversarial attack on popular VLP models and V+L tasks. First, we analyzed the performance of adversarial attacks under different settings. By examining the influence of different perturbed objects and attack targets, we concluded some key observations as guidance on both designing strong multimodal adversarial attack and constructing robust VLP models. Second, we proposed a novel multimodal attack method on the VLP models called Collaborative Multimodal Adversarial Attack (Co-Attack), which collectively carries out the attacks on the image modality and the text modality. Experimental results demonstrated that the proposed method achieves improved attack performances on different V+L downstream tasks and VLP models. The analysis observations and novel attack method hopefully provide new understanding into the adversarial robustness of VLP models, so as to contribute their safe and reliable deployment in more real-world scenarios. Code is available at https://github.com/adversarial-for-goodness/Co-Attack.

Jiaming Zhang, Qi Yi, Jitao Sang• 2022

Related benchmarks

TaskDatasetResultRank
Text-to-Video RetrievalDiDeMo (test)
R@14.48
407
Image RetrievalFlickr30k (test)
R@198.12
357
Text RetrievalFlickr30k (test)
R@1 (ASR)97.08
340
Text-to-Video RetrievalMSR-VTT (test)
R@117.69
271
Text RetrievalFlickr30k (test)
R@196.72
251
Image RetrievalMS-COCO
R@198.8
174
Image RetrievalFlickr30K
R@183.86
170
Image RetrievalMSCOCO (test)
R@1 Attack Success Rate98.31
144
Text RetrievalMSCOCO (test)
Attack Success Rate @197.64
144
Text RetrievalMSCOCO
Recall@197.98
142
Showing 10 of 25 rows

Other info

Follow for update