Appendix: Learning Black-Box Attackers with Transferable Priors and Query Feedback Jiancheng Y ang
–Neural Information Processing Systems
In Figure A1, we illustrate the gradients from Inception-V3 [15] and ResNet-152 [9]. These authors have contributed equally. Output: updated surrogate model S . The experiment setting and images are same as previous state-of-the-art [2]. Thereby, we also report the A VG.Q' including failures (in Table A1, A2, A3, A4, A5), where failure query numbers are considered as 10,000.
Neural Information Processing Systems
Aug-15-2025, 02:52:26 GMT