Technology
fdc42b6b0ee16a2f866281508ef56730-Supplemental.pdf
To estimate the impact of removing a parameter, these methods often use importance measures that were originally designed to prune neural networks. If this hypothesis is true, it has great potential to covert the inefficient training process on a large network to the scalable training process over a small one with comparable test accuracy. Most of existing LTH techniques provide empirical evidence to verify the LTH, although these methods raise very intriguing observations [71, 12, 1, 47, 69, 54, 5, 53, 26, 8, 7, 11]. However, multiple cycles of training and pruning over large neural networks are time-consuming. Tworecent worksanalyze the LTH transferability, i.e., the ticket discovered from one source task can be transferred to another targettask[44,43].
fdb55ce855129e05da8374059cc82728-Supplemental.pdf
A.1 Fullexperimentalresults In this section we provide the full experimental results that extend the results demonstrated in the Section 4.2. Table 8 demonstrates the evaluation on 16 robustly trained CIFAR10 models from RobustBench [28] that was summarized in the Table 2. We consider four configurations of the attack for each of the models. SA and AA correspond to the update size schedules proposed by Andriushchenko et al.[1]and Croce and Hein[2]respectively. "Uni" denotes sampling the color fortheupdateuniformly. A.2 Meta-trainingtheControllers The meta-training of controllers was described in Section 3 and Section 4.1.
Meta-LearningtheSearchDistributionofBlack-Box RandomSearchBasedAdversarialAttacks
A very promising direction in the field of black-box adversarial attacks are randomized search schemes for crafting adversarial examples [1, 23, 24]. Combining random search with specific update proposal distributions allows to achieve state-of-the-art black-box efficiency for different threat models such as` and `2 [1], `1 [25], `0, adversarial patches, and adversarial frames [24].