{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T21:35:13Z","timestamp":1770845713426,"version":"3.50.1"},"reference-count":34,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,5]],"date-time":"2025-10-05T00:00:00Z","timestamp":1759622400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,5]],"date-time":"2025-10-05T00:00:00Z","timestamp":1759622400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100020487","name":"Nature","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100020487","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,5]]},"DOI":"10.1109\/smc58881.2025.11342643","type":"proceedings-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T20:54:44Z","timestamp":1769633684000},"page":"1791-1798","source":"Crossref","is-referenced-by-count":0,"title":["ViTProbe: Defending Vision Transformers against Adversarial Patch Attacks through Single-Layer Inspection"],"prefix":"10.1109","author":[{"given":"Fanjin","family":"Xu","sequence":"first","affiliation":[{"name":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"}]},{"given":"Qiuran","family":"Li","sequence":"additional","affiliation":[{"name":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"}]},{"given":"Kaiyan","family":"Wen","sequence":"additional","affiliation":[{"name":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"}]},{"given":"Yaohua","family":"Wang","sequence":"additional","affiliation":[{"name":"National University of Defense Technology,College of Computer Science and Technology,Changsha,China,410073"}]}],"member":"263","reference":[{"key":"ref1","article-title":"An image is worth 16x16 words: Transformers for image recognition at scale","author":"Alexey","year":"2020"},{"key":"ref2","article-title":"Toward transformer-based object detection","author":"Beal","year":"2020"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00717"},{"key":"ref4","article-title":"Training data-efficient image transformers & distillation through attention","volume-title":"International conference on machine learning","author":"Touvron"},{"key":"ref5","article-title":"Benchmarking neural network robustness to common corruptions and perturbations","author":"Hendrycks","year":"2019"},{"key":"ref6","article-title":"Reveal of vision transformers robustness against adversarial attacks","author":"Aldahdooh","year":"2021"},{"key":"ref7","article-title":"Can cnns be more robust than transformers?","author":"AWang","year":"2022"},{"key":"ref8","article-title":"Adversarial patch","author":"Brown","year":"2017"},{"key":"ref9","article-title":"Lavan: Localized and visible adversarial noise","volume-title":"International conference on machine learning","author":"Karmon"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/s00138-021-01194-6"},{"key":"ref11","article-title":"Adversarial token attacks on vision transformers","author":"Joshi","year":"2021"},{"key":"ref12","article-title":"Patch-fool: Are vision transformers always robust against adversarial perturbations?","author":"Fu","year":"2022"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01480"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02357"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19775-8_24"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02120-9"},{"key":"ref17","article-title":"Defending against adversarial patches with robust self-attention","volume-title":"ICML 2021 workshop on uncertainty and robustness in deep learning","volume":"1","author":"Mu"},{"key":"ref18","article-title":"Understanding and defending patched-based adversarial attacks for vision transformer","author":"Liu","year":"2023"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref20","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2105.07581"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref23","article-title":"Training data-efficient image transformers & distillation through attention","volume-title":"International conference on machine learning","author":"Touvron"},{"key":"ref24","first-page":"26831","article-title":"Are transformers more robust than cnns?","volume":"34","author":"Bai","year":"2021","journal-title":"Advances in neural information processing systems"},{"key":"ref25","article-title":"Adversarial patch attacks and defences in vision-based tasks: A survey","author":"Sharma","year":"2022"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW53098.2021.00342"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58452-8_13"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00676"},{"key":"ref29","first-page":"26831","article-title":"Are transformers more robust than cnns?","volume":"34","author":"Bai","year":"2021","journal-title":"Advances in neural information processing systems"},{"key":"ref30","article-title":"On the adversarial robustness of vision transformers","author":"Shao","year":"2021"},{"key":"ref31","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref32","article-title":"Reveal of vision transformers robustness against adversarial attacks","author":"Aldahdooh","year":"2021"},{"key":"ref33","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref34","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"}],"event":{"name":"2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","location":"Vienna, Austria","start":{"date-parts":[[2025,10,5]]},"end":{"date-parts":[[2025,10,8]]}},"container-title":["2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11342430\/11342431\/11342643.pdf?arnumber=11342643","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T20:51:29Z","timestamp":1770843089000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11342643\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,5]]},"references-count":34,"URL":"https:\/\/doi.org\/10.1109\/smc58881.2025.11342643","relation":{},"subject":[],"published":{"date-parts":[[2025,10,5]]}}}