DiffAttack icon indicating copy to clipboard operation
DiffAttack copied to clipboard

Some questions about the paper

Open qj1204 opened this issue 7 months ago • 12 comments

Hello, I am currently reproducing your paper. Regarding Figure 4, I have some questions that I would like to ask you:

  1. Is the dataset Imagene-compatible?
  2. Besides DiffAttack, which specific surrogate model is attacked by other methods to obtain adversarial samples (which one of Res-50, VGG-19, Mov-v2, Inc-v3, ConvNeXt, and Swin-B)?
  3. Are other methods using third-party adversarial attack libraries or running only source code? image

There is another question about table 1: The gray background represents a white box attack, but DiffAttack uses the adversarial samples generated by the diffusion model to attack the target model, which should be a black box attack. Why is DiffAttack also set to gray in Table 1? image

I would greatly appreciate it if you could reply to me.

qj1204 avatar Jul 02 '24 14:07 qj1204