Mind the Box: l1 -APGD for Sparse Adversarial Attacks on Image Classifiers
Francesco Croce 1 Matthias Hein 1
Abstract exist a set of l1 -based attacks (Chen et al., 2018; Modas
et al., 2019; Brendel et al., 2019; Croce & Hein, 2020a;
We show that when taking into account also the Rony et al., 2020), in contrast to the l∞ - and l2 -case the
image domain [0, 1]d , established l1 -projected cla ...
附件列表