A The algorithm for Moiré Attack (MA) Algorithm 1 Moiré Attack Input: clean image x; targeted label x; ground truth label y