Theoretically Principled Trade-off for Stateful Defenses against Query-Based Black-Box Attacks

Open in new window