perceptual-advex
perceptual-advex copied to clipboard
What is the defense model being attacked in Figure 3 & 7
It seems that the defense model is a PAT-adversarially trained model.
When attacking a normally trained model (clean model), the perturbation will be very similar to l2 attack ? (especially LPA attack).