跳到主要导航 跳到搜索 跳到主要内容

PE-Attack: On the Universal Positional Embedding Vulnerability in Transformer-Based Models

  • Beihang University

科研成果: 期刊稿件文章同行评审

摘要

The Transformer model has gained significant recognition for its remarkable computational capabilities and versatility, positioning itself as a fundamental component in numerous practical applications. However, the robustness of the Transformer model, specifically its stability and reliability under various types of adversarial attacks, is of utmost importance for its practical applicability. Furthermore, it offers valuable insights for the design of more efficient and secure models. In contrast with conventional investigations into adversarial robustness, our study focuses on the analysis of Positional Embeddings (PEs), a crucial component that sets the Transformer model apart from previous model architectures. Theoretical analysis of PEs has been limited due to previous predominantly empirical design, which includes features such as sinusoidal or linear patterns, learned or fixed characteristics, and absolute or relative measurements. Our investigation delves deep into potential vulnerabilities within PEs. Initially, we develop a set of input infection techniques that can be universally applied to exploit vulnerabilities present in the Transformer architecture and its variants. In addition, we propose a novel adversarial attack that manipulates the model by providing it with incorrect positional information, enabling an evasion attack. Significantly, in contrast to previous attacks that were limited to a single task, our conducted experiments involving time-series analysis, natural language processing, and computer vision indicate that the susceptibility of PEs could be universal and transferable. This finding serves as a significant warning for future Transformer-based model design, urging researchers to consider potential security risks inherent in the model's structure.

源语言英语
页(从-至)9359-9373
页数15
期刊IEEE Transactions on Information Forensics and Security
19
DOI
出版状态已出版 - 2024

指纹

探究 'PE-Attack: On the Universal Positional Embedding Vulnerability in Transformer-Based Models' 的科研主题。它们共同构成独一无二的指纹。

引用此