Towards Robust Vision Transformer
arXiv:2105.07926
Abstract
Recent advances on Vision Transformer (ViT) and its improved variants have shown that self-attention-based networks surpass traditional Convolutional Neural Networks (CNNs) in most vision tasks. However, existing ViTs focus on the standard accuracy and computation cost, lacking the investigation of the intrinsic influence on model robustness and generalization. In this work, we conduct systematic evaluation on components of ViTs in terms of their impact on robustness to adversarial examples, common corruptions and distribution shifts. We find some components can be harmful to robustness. By using and combining robust components as building blocks of ViTs, we propose Robust Vision Transformer (RVT), which is a new vision transformer and has superior performance with strong robustness. We further propose two new plug-and-play techniques called position-aware attention scaling and patch-wise augmentation to augment our RVT, which we abbreviate as RVT*. The experimental results on ImageNet and six robustness benchmarks show the advanced robustness and generalization ability of RVT compared with previous ViTs and state-of-the-art CNNs. Furthermore, RVT-S* also achieves Top-1 rank on multiple robustness leaderboards including ImageNet-C and ImageNet-Sketch. The code will be available at \url{https://github.com/alibaba/easyrobust}.
Accepted to CVPR 2022, https://github.com/alibaba/easyrobust
References in corpus (11)
- An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale
- Transformer in Transformer
- AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty
- Making Convolutional Networks Shift-Invariant Again
- LocalViT: Analyzing Locality in Vision Transformers
- CvT: Introducing Convolutions to Vision Transformers
- LeViT: a Vision Transformer in ConvNet's Clothing for Faster Inference
- Rethinking Spatial Dimensions of Vision Transformers
- Adversarially Robust Neural Architectures
- Do Wider Neural Networks Really Help Adversarial Robustness?
- An Effective Anti-Aliasing Approach for Residual Networks
Cited by in corpus (6)
- Exploring the Limits of Out-of-Distribution Detection
- Discrete Representations Strengthen Vision Transformer Robustness
- DBIA: Data-free Backdoor Injection Attack against Transformer Networks
- Pyramid Adversarial Training Improves ViT Performance
- TransMix: Attend to Mix for Vision Transformers
- Sparse MoEs meet Efficient Ensembles