When does gradient estimation improve black-box adversarial attacks?

HIGHLIGHTS

  • What: Knowing both expected rates of distortion, the authors provide the minimum number of estimation queries Q* (k) such that the expected distortion of CGBA is lower than SurFree for the same amount of queries. The authors compare the performance of GeoDA, which is based purely on the use of the normal vector n, SurFree, which does not use any gradient information and CGBA which combines the two approaches. The authors report the results for the MNIST dataset in Fig 5a. For CGBA, the authors report the average distortion for two different query schedules concerning the estimation . . .

     

    Logo ScioWire Beta black

    If you want to have access to all the content you need to log in!

    Thanks :)

    If you don't have an account, you can create one here.

     

Scroll to Top

Add A Knowledge Base Question !

+ = Verify Human or Spambot ?