BlackboxAttacksviaSurrogateEnsembleSearch SupplementaryMaterial Summary
–Neural Information Processing Systems
Some previous papers (e.g., MIM [7])claimedthat ensemble with weighted logits (equation (4) in main text) outperforms ensemble with weighted probabilities and weighted combination of loss (equations(3)and(5)in main text). In our experiments, shown in Figure 6b, we observe that weighted combination of surrogate loss functions provide similar or even higher fooling rate compared to weighted probabilities or logits.
Neural Information Processing Systems
Feb-7-2026, 21:53:03 GMT