PapersWithELO
← ICLR 2024 leaderboard

SlowFormer: Universal Adversarial Patch for Attack on Compute and Energy Efficiency of Inference Efficient Vision Transformers

Navaneet K L, Soroush Abbasi Koohpayegani, Essam Sleiman, Hamed Pirsiavash

general MLAdversarial attackEfficient TransformersEnergy AttackTransformersUniversal Adversarial Patch
15.90100
Fused
band ≈ ±13 pct pts (from σ = 0.26)
14.50100
Mimo
band ≈ ±19 pct pts (from σ = 0.37)
20.40100
DeepSeek
band ≈ ±18 pct pts (from σ = 0.36)

OpenReview ground truth

Rejected

TL;DR — We show that efficient transformers are not robust to Universal Adversarial Patch Energy Attack.

Abstract

Recently, there has been a lot of progress in reducing the computation of deep models at inference time. These methods can reduce both the computational needs and power usage of deep models. Some of these approaches adaptively scale the compute based on the input instance. We show that such models can be vulnerable to a universal adversarial patch attack, where the attacker optimizes for a patch that when pasted on any image, can increase the compute and power consumption of the model. We run experiments with three different efficient vision transformer methods showing that in some cases, the attacker can increase the computation to the maximum possible level by simply pasting a patch that occupies only 8\% of the image area. We also show that a standard adversarial training defense method can reduce some of the attack's success. We believe adaptive efficient methods will be necessary for the future to lower the power usage of deep models, so we hope our paper encourages the community to study the robustness of these methods and develop better defense methods for the proposed attack.

Author context

Most prolific author: 2 submissions (credibility 1.00).

No mass-submission penalty for this paper (authors within normal submission volume).

Aggregate statistics only — no individual author rankings.

Ranking trajectory

Percentile by tournament round — convergence indicates rating stability.

Battle history — 42 comparisons

Ranked above opponent in 43% of matchups.

Judge assessments

Mean overall score 0.0 ± 0.0 (n = 42)