Mind the box: $l_1$-APGD for sparse adversarial attacks on image classifiers

Open in new window