DiffAttack
DiffAttack copied to clipboard
Some questions about the paper
Hello, I am currently reproducing your paper. Regarding Figure 4, I have some questions that I would like to ask you:
- Is the dataset Imagene-compatible?
- Besides DiffAttack, which specific surrogate model is attacked by other methods to obtain adversarial samples (which one of Res-50, VGG-19, Mov-v2, Inc-v3, ConvNeXt, and Swin-B)?
- Are other methods using third-party adversarial attack libraries or running only source code?
There is another question about table 1:
The gray background represents a white box attack, but DiffAttack uses the adversarial samples generated by the diffusion model to attack the target model, which should be a black box attack. Why is DiffAttack also set to gray in Table 1?
I would greatly appreciate it if you could reply to me.