Abstract: Without access to the training data where a black-box victim model is deployed, training a surrogate model for black-box adversarial attack is still a struggle. In terms of data, we mainly ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results