When I test the Geoa3 in the entire mn40 test set, the attack sucess rate is low, why?
cuge1995 opened this issue · 2 comments
cuge1995 commented
When I test the Geoa3 in the entire mn40 test set, the attack sucess rate is low, why?
cuge1995 commented
Untargeted attack for Pointnet and DGCNN, the classification after attack is 73.58 and 71.23%, respectively.
Yuxin-Wen commented
The attack success rate shold also be 100% without SOR defense. However, unlike 2D image attack, we did not find or claim that a more complex architecture is easier to be misled; on the contrary, such architecture is always more robust, so the 500 iterations and 10 binary search should be completely conducted (it might be time-comsuing, and that's why we conduct our experiments on the randomly selected samples).