max-andr/square-attack
Square Attack: a query-efficient black-box adversarial attack via random search [ECCV 2020]
PythonBSD-3-Clause
Issues
- 3
- 2
1.Hi, I would like to know what do you refer to as Rademacher distribution in A.4, and why
#12 opened by Kitzzaaa - 4
Bugs when running Linf attack on pt_inception
#11 opened by Daizy97 - 2
- 6
Can you provide the code of defensive model in your paper's section 5.2 for me?
#2 opened by machanic - 5
- 2
Results of MNIST and CIFAR10
#8 opened by bdseal - 1
- 2
The Linf version
#6 opened by bymavis - 4
Why the perturbation with its value equals the maximum bound of Linf and L2 attack should be used in update?
#5 opened by machanic - 10
Why do you use two windows in L2 norm attack? I don't understand the mass moving (Fig.2)
#3 opened by machanic - 2
Why the loss type is margin_loss in untargeted attack, but cross_entropy loss in targeted attack.
#4 opened by machanic - 4
Where does this paper published on?
#1 opened by machanic