perceptual-advex icon indicating copy to clipboard operation
perceptual-advex copied to clipboard

What is the defense model being attacked in Figure 3 & 7

Open Equationliu opened this issue 3 years ago • 0 comments

It seems that the defense model is a PAT-adversarially trained model.

When attacking a normally trained model (clean model), the perturbation will be very similar to l2 attack ? (especially LPA attack).

Equationliu avatar Aug 27 '21 06:08 Equationliu